CISA Domain 5B-1 Practice Test 001

This practice test covers Domain 5 (Protection of Information Assets) Subdomain B-1 (Security Awareness Training and Programs) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 5B-1 Security Awareness Training and Programs Practice Test 001
10 questions • Single best answer
Question 1
Following several successful phishing attacks, a retail bank's internal audit team is evaluating the enterprise security awareness program. Training completion stands at 98 percent, yet phishing simulation click rates remain unchanged year over year. Which finding should the IS auditor consider MOST significant when concluding on program effectiveness?
    Question 2
    An IS auditor wants to conclude on whether a government agency's security awareness program is effective at reducing human-related risk. The program manager offers several sources of support for the program's value. Which of the following would provide the BEST evidence that the program is achieving its intended outcome?
      Question 3
      During an audit of a healthcare provider, the IS auditor finds that clinical staff frequently share login credentials and disable endpoint warnings despite completing annual security training. Management attributes this to workload pressures. What should the IS auditor do FIRST before forming a conclusion on the awareness program?
        Question 4
        An IS auditor reviews an enterprise's security awareness program and notes that all employees receive the same generic annual training module. System administrators, developers, and finance staff who handle wire transfers receive no additional targeted content. Which recommendation is MOST appropriate to strengthen the program?
          Question 5
          A financial services firm's security awareness program is funded and delivered entirely by the IT department, with no formal ownership or oversight from senior management or the risk function. The IS auditor is assessing program governance. Which conclusion is MOST appropriate regarding this governance arrangement?
            Question 6
            An audit manager is evaluating how a manufacturing enterprise reports on its security awareness program to the board. The only metric presented quarterly is the number of employees who completed training, and the board uses this figure to gauge human risk exposure. Which finding is MOST significant?
              Question 7
              During an audit of a technology company, the IS auditor learns that new employees are granted full system access on their start date but do not receive security awareness training until the company-wide annual session, which may be months away. Which risk should the auditor highlight as MOST significant?
                Question 8
                A retail organization measures its awareness program using post-course quiz scores, which average 95 percent. However, help-desk data shows repeated malware infections traced to employees opening malicious attachments. The IS auditor is evaluating whether the program's measurement approach reflects real-world behavior. Which conclusion is MOST appropriate?
                  Question 9
                  An IS auditor reviewing a logistics company finds that security awareness training is mandatory for employees but excludes the large population of contractors and temporary staff who access the same production systems and routinely handle sensitive shipping data. Which recommendation is MOST appropriate for the auditor to make?
                    Question 10
                    An IS auditor previously reported that a bank's phishing simulation click rate was high and recommended targeted refresher training. During follow-up a year later, the auditor must evaluate whether the risk was sufficiently addressed. Which of the following provides the BEST evidence of effective remediation?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top