Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 5Objective 1

Security Frameworks and Governance CISA Practice Questions (Page 2)

Part of the Protection of Information Assets domain, which accounts for 26% of the CISA exam.

24questions here
5free pages
4concepts
26%of the exam

Questions 6–10

  1. 6foundation · easy

    An organization conducts simulated phishing campaigns and tracks the click rate over time. What is the primary purpose of this activity?

    Select an answer first
  2. 7expert · hard

    A security manager implemented a security awareness program and is now under pressure to demonstrate its value to the board. The board is not interested in technical metrics like phishing click rates; they want to understand the program's impact on business risk. Which approach best communicates the program's value to the board?

    Select an answer first
  3. 8application · medium

    After implementing a new security awareness program, the CISO asks the security manager to prove that the program is actually reducing risk. Which metric would provide the most direct evidence of the program's effectiveness?

    Select an answer first
  4. 9application · medium

    A healthcare organization has experienced multiple phishing incidents where employees clicked on malicious links in emails. The security manager wants to implement a training program that directly addresses this specific risk. Which approach is most effective for this situation?

    Select an answer first
  5. 10foundation · easy

    What is the primary purpose of a security awareness training program?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.