nerdexam
Isaca

CISM · Question #954

Which of the following should be of MOST concern to an information security manager when evaluating the effectiveness of the organization's phishing simulation program?

The correct answer is D. An increase in click rates over time. An increasing click rate over time directly indicates that employees are becoming more susceptible to phishing attacks, meaning the simulation program is failing at its core purpose - reducing human risk. A well-functioning program should show declining click rates as employees…

Submitted by ravi_2018· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following should be of MOST concern to an information security manager when evaluating the effectiveness of the organization's phishing simulation program?

Options

  • AAn increase in the number of reported phishing attempts
  • BAn increase in phishing simulation software licensing costs
  • CAn increase in scrutiny from senior management
  • DAn increase in click rates over time

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    13% (6)
  • C
    8% (4)
  • D
    75% (36)

Explanation

An increasing click rate over time directly indicates that employees are becoming more susceptible to phishing attacks, meaning the simulation program is failing at its core purpose - reducing human risk. A well-functioning program should show declining click rates as employees learn to recognize and avoid phishing attempts.

Why the distractors are wrong:

  • A is actually a positive indicator - more reported phishing attempts means employees are aware and engaged, which is the desired behavior.
  • B is a budget/procurement concern, not a measure of program effectiveness; cost doesn't reflect whether employees are learning.
  • C is a governance dynamic that may actually improve the program; management attention often drives better resources and accountability.

Memory tip: Think of click rate as the program's "failure rate." Just as you'd be concerned if a safety training program saw more workplace accidents over time, a rising click rate means the phishing program is producing the opposite of its intended outcome - it's the clearest signal the training isn't working.

Topics

#Phishing Simulation#Security Awareness Training#Program Effectiveness#Security Metrics

Community Discussion

No community discussion yet for this question.

Full CISM Practice