712-50 exam dumps

712-50 practice question 402 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 402

Single answerDefine key performance indicators and measure effectiveness on continuous basis

A newly appointed CISO is asked by the board to demonstrate whether the security awareness program is improving the organization's resilience against phishing. The current dashboard reports only the number of employees who completed annual training, and the board is dissatisfied because it does not show whether the program is actually reducing risk. Which KPI would be the MOST effective for measuring the program's effectiveness on a continuous basis?

  1. A

    Percentage of employees who completed mandatory security awareness training by the deadline

  2. B

    Number of phishing simulation emails sent to employees each quarter

  3. C

    Rate at which employees click simulated phishing links and the percentage who correctly report the simulation

  4. D

    Total budget spent on awareness content, external trainers, and learning platform licenses

Show answer and explanation

Correct answer: C

Explanation

Effective CCISO-level KPI design should distinguish between inputs, activities, outputs, and outcomes. For board reporting, the strongest security KPIs are outcome-oriented, tied to business risk, and measured consistently over time. In this scenario, training completion is an output/compliance metric, while phishing click and reporting rates are behavioral outcome metrics that better demonstrate whether the awareness program is effective. This aligns with common security governance and performance management practices reflected in frameworks such as NIST Cybersecurity Framework (governance and improvement through measurement), NIST SP 800-55 on performance measurement, and ISO/IEC 27004, which emphasizes selecting metrics that support decision-making and demonstrate effectiveness rather than mere activity. A mature CISO function should use trend-based KPIs with targets, thresholds, and periodic review to show continuous improvement and support resource decisions.

  • A. Incorrect.

    This is a useful activity or compliance metric, but by itself it does not measure whether behavior changed or whether phishing risk decreased. Completion rates show participation, not effectiveness. A board looking for evidence of improved resilience needs an outcome-oriented KPI tied to security behavior.

  • B. Incorrect.

    This measures testing volume, not program effectiveness. Sending more simulations does not mean employees are better at identifying phishing. It could even distort interpretation if the organization increases testing frequency without normalizing results.

  • C. Correct.

    This is the best answer because it directly measures behavioral outcomes that align to the objective of the awareness program: reducing successful phishing attacks and improving employee detection/reporting. Tracking click rate and report rate over time provides a continuous, trend-based indicator of whether the program is changing user behavior and improving organizational resilience.

  • D. Incorrect.

    Budget is an input metric, not an effectiveness metric. Higher spending does not necessarily produce better awareness outcomes. Executives may review cost efficiency separately, but it is not the strongest KPI for showing continuous reduction in phishing-related risk.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam