CAS-004 Governance, Risk, and Compliance Practice Question
A security manager is reviewing Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the security program. Which of the following is an example of a KRI?
⚠ Common exam trap
The trap is that many security metrics (MTTD, patch rate, incident count) sound risk-related but are actually KPIs measuring process performance; only metrics tied to risk appetite thresholds qualify as KRIs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Number of critical vulnerabilities exceeding the risk appetite threshold
A Key Risk Indicator (KRI) measures risk exposure and whether it is approaching or exceeding the organization's risk appetite — the number of critical vulnerabilities exceeding the risk appetite threshold is a direct measure of unacceptable risk exposure. KRIs are forward-looking indicators that signal when risk levels are becoming dangerous.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mean time to detect (MTTD) security incidents
Why it's wrong here
MTTD measures how quickly the security team detects incidents, which is operational performance, so it is a KPI. It is tempting because faster detection lowers risk, but a KRI indicates current risk exposure or threat level, not the efficiency of a detection process.
- ✓
Number of critical vulnerabilities exceeding the risk appetite threshold
Why this is correct
A KRI signals exposure against a defined risk appetite, not operational throughput. Critical vulnerabilities breaching that threshold indicate the security posture has moved beyond acceptable tolerance, prompting escalation. KPIs, by contrast, measure performance such as patch coverage or mean time to remediate, so this metric is the risk indicator.
- ✗
Percentage of systems patched within 30 days
Why it's wrong here
Patch percentage within 30 days measures control execution performance, making it a KPI, not a KRI. It is tempting because patching reduces risk, but KRIs track exposure or threat conditions that indicate rising risk, whereas this metric reports how well a process is performing.
- ✗
Number of security incidents per month
Why it's wrong here
Incident counts per month measure operational workload and response performance, making this a KPI. It is tempting because more incidents suggest greater risk, but a KRI tracks leading indicators of exposure or vulnerability, whereas incident volume is a lagging performance measure of the security function.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.