Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security team is measuring the effectiveness of its incident response process. Which of the following metrics would best indicate how quickly the team can contain an incident after it is detected?

⚠ Common exam trap

CAS-005 often tests the confusion between MTTD and MTTR — candidates must read whether the question asks about detecting an incident (MTTD) or responding to/containing it after detection (MTTR).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean time to respond (MTTR)

Mean time to respond (MTTR) measures the average time between incident detection and containment/resolution, directly reflecting how quickly the team can act once an incident is identified. It is the standard metric for response and containment speed in incident response frameworks such as NIST SP 800-61. The other options measure detection speed, vulnerability posture, or patch hygiene, not containment speed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mean time to respond (MTTR)

    Why this is correct

    MTTR measures the elapsed time from incident detection to containment, directly quantifying response speed. Other metrics such as MTTD address detection latency, so MTTR is the precise indicator of how quickly the team contains a detected incident.

  • ✗

    Vulnerabilities by severity

    Why it's wrong here

    Vulnerabilities by severity counts outstanding weaknesses, measuring exposure rather than response speed, and says nothing about containment timing. It is tempting because severity data drives remediation prioritisation, which is the correct metric when assessing patch management rather than incident response.

  • ✗

    Patch compliance percentage

    Why it's wrong here

    Patch compliance measures remediation coverage, not elapsed time from detection to containment. It is tempting because it reflects vulnerability management hygiene, and would be the right metric when reporting on the percentage of systems meeting patching baselines, but it captures no incident-response timing data.

  • ✗

    Mean time to detect (MTTD)

    Why it's wrong here

    MTTD measures the interval from incident occurrence to detection, ending before containment begins, so it cannot express containment speed. It is tempting because it is a core incident response metric, and it is the correct choice when the question asks how quickly incidents are identified.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.