Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 100 discussion

Actual exam question from ISC's CISSP
Question #: 100
Topic #: 1
[All CISSP Questions]

What is the PRIMARY purpose of creating and reporting metrics for a security awareness, training, and education program?

  • A. Measure the effect of the program on the organization's workforce.
  • B. Make all stakeholders aware of the program's progress.
  • C. Facilitate supervision of periodic training events.
  • D. Comply with legal regulations and document due diligence in security practices.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
deeden
3 months, 2 weeks ago
Selected Answer: A
This is the primary purpose of creating and reporting metrics for a security awareness, training, and education program. By measuring the program's effectiveness, organizations can: Demonstrate ROI: Justify the program's existence and secure continued funding. Identify areas for improvement: Pinpoint weaknesses in training content or delivery. Enhance security culture: Foster a culture of security awareness among employees. While the other options are important, they are secondary to the overall goal of measuring the program's impact on the workforce.
upvoted 1 times
...
8b48948
7 months, 1 week ago
I dont see how it is A - how would taking metrics measure the impact the training had already had.
upvoted 1 times
...
shmoeee
1 year ago
It's A, guaranteed
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: A
A. Measure the effect of the program on the organization's workforce. Creating and reporting metrics for a security awareness, training, and education program allows organizations to assess the effectiveness and impact of the program on their workforce By measuring the effect of the program, organizations can determine if their workforce is gaining knowledge, adopting desired behaviors, and applying security practices effectively.
upvoted 4 times
...
invincible96
1 year, 8 months ago
Selected Answer: A
The main point here is "Primary" which makes option A the right answer. Option D is not the primary purpose of creating and reporting metrics. While compliance with legal regulations and documenting due diligence are important, the primary purpose of metrics is to measure the effectiveness of the program in changing the behavior of the workforce.
upvoted 1 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
RVoigt
1 year, 8 months ago
Selected Answer: D
Remember its creating and reporting - only D works with creating ...
upvoted 3 times
[Removed]
1 year, 3 months ago
I read it as creating metrics and reporting metrics.
upvoted 1 times
...
...
meelaan
1 year, 11 months ago
Selected Answer: A
A sounds good
upvoted 2 times
...
Jamati
2 years ago
A sound correct
upvoted 2 times
...
franbarpro
2 years, 1 month ago
Yep "A" sounds like a PRIMARY reason
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...