CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 469


Which of the following findings should be of GREATEST concern for an IS auditor when auditing the effectiveness of a phishing simulation test administered for staff members?

Show Answer
Correct Answer: AC

The most concerning finding for an IS auditor when auditing the effectiveness of a phishing simulation test is that staff members who failed the test did not receive follow-up education. The primary objective of such simulations is to identify and educate vulnerable employees to enhance the organization's overall security posture. Without follow-up education, the vulnerabilities remain unaddressed, making the simulation less effective in improving security awareness and reducing the risk of successful phishing attacks.

Discussion

6 comments
Sign in to comment
DeeplaxmiOption: C
Oct 3, 2022

i feel C

David_HuOption: C
Jan 7, 2023

should be C

MohamedAbdelaalOption: C
Apr 17, 2023

I'll go for C

takuanismOption: C
Jan 12, 2024

should be C

SwallowsOption: C
Jun 9, 2024

While communicating test results to staff members (option D) is also important for providing feedback and promoting awareness, ensuring that staff members who failed the test receive follow-up education is crucial for addressing their vulnerabilities and improving the organization's overall security posture. Therefore, the finding that staff members who failed the test did not receive follow-up education should be of greatest concern for an IS auditor in this scenario.

RS66Option: C
Jul 5, 2024

definitely C.