ExamGecko
Question list
Search
Search

Related questions

Question 162 - CISA discussion

Report
Export

An organization conducted an exercise to test the security awareness level of users by sending an email offering a cash reward 10 those who click on a link embedded in the body of the email. Which of the following metrics BEST indicates the effectiveness of awareness training?

A.
The number of users deleting the email without reporting because it is a phishing email
Answers
A.
The number of users deleting the email without reporting because it is a phishing email
B.
The number of users clicking on the link to learn more about the sender of the email
Answers
B.
The number of users clicking on the link to learn more about the sender of the email
C.
The number of users forwarding the email to their business unit managers
Answers
C.
The number of users forwarding the email to their business unit managers
D.
The number of users reporting receipt of the email to the information security team
Answers
D.
The number of users reporting receipt of the email to the information security team
Suggested answer: D

Explanation:

The metric that best indicates the effectiveness of awareness training is the number of users reporting receipt of the email to the information security team. This shows that the users are able to recognize and report a phishing email, which is a common social engineering technique used by attackers to trick users into revealing sensitive information or installing malicious software. The other metrics do not demonstrate a high level of security awareness, as they either ignore, follow, or forward the phishing email, which could expose the organization to potential risks.Reference:CISA Review Manual, 27th Edition, page 326

asked 18/09/2024
J.J. van Ingen
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first