Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security manager is reviewing Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the security program. Which of the following is an example of a KRI?

⚠ Common exam trap

The trap is that many security metrics (MTTD, patch rate, incident count) sound risk-related but are actually KPIs measuring process performance; only metrics tied to risk appetite thresholds qualify as KRIs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Number of critical vulnerabilities exceeding the risk appetite threshold

A Key Risk Indicator (KRI) measures risk exposure and whether it is approaching or exceeding the organization's risk appetite — the number of critical vulnerabilities exceeding the risk appetite threshold is a direct measure of unacceptable risk exposure. KRIs are forward-looking indicators that signal when risk levels are becoming dangerous.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mean time to detect (MTTD) security incidents

    Why it's wrong here

    MTTD measures how quickly the security team detects incidents, which is operational performance, so it is a KPI. It is tempting because faster detection lowers risk, but a KRI indicates current risk exposure or threat level, not the efficiency of a detection process.

  • ✓

    Number of critical vulnerabilities exceeding the risk appetite threshold

    Why this is correct

    A KRI signals exposure against a defined risk appetite, not operational throughput. Critical vulnerabilities breaching that threshold indicate the security posture has moved beyond acceptable tolerance, prompting escalation. KPIs, by contrast, measure performance such as patch coverage or mean time to remediate, so this metric is the risk indicator.

  • ✗

    Percentage of systems patched within 30 days

    Why it's wrong here

    Patch percentage within 30 days measures control execution performance, making it a KPI, not a KRI. It is tempting because patching reduces risk, but KRIs track exposure or threat conditions that indicate rising risk, whereas this metric reports how well a process is performing.

  • ✗

    Number of security incidents per month

    Why it's wrong here

    Incident counts per month measure operational workload and response performance, making this a KPI. It is tempting because more incidents suggest greater risk, but a KRI tracks leading indicators of exposure or vulnerability, whereas incident volume is a lagging performance measure of the security function.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.