CAS-004 Governance, Risk, and Compliance Practice Question
Which key performance indicator (KPI) is most useful for measuring the effectiveness of an incident response process?
⚠ Common exam trap
CAS-005 often tests the confusion between preventive metrics (like patch compliance) and response metrics (like MTTR), leading candidates to choose a vulnerability management metric.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to respond (MTTR)
Mean time to respond (MTTR) measures the average time taken to respond to and contain a security incident from detection. It directly reflects the efficiency and effectiveness of the incident response process, as lower MTTR indicates faster containment and reduced impact. Other metrics like patch compliance or vulnerabilities by severity are related to vulnerability management, not incident response effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch compliance percentage
Why it's wrong here
Patch compliance measures preventive hygiene, not how quickly or effectively incidents are detected, contained and resolved. It tempts because unpatched systems cause incidents, yet the KPI must track response performance — mean time to detect, contain or recover — rather than the vulnerability backlog that feeds incidents.
- ✗
Vulnerabilities by severity
Why it's wrong here
Vulnerability counts by severity describe exposure in the estate, not the speed or quality of incident handling. It tempts because severe vulnerabilities often precede incidents, but the response process is measured by detection, containment and recovery times, so this indicator says nothing about how well an incident was managed.
- ✗
Number of security awareness training sessions
Why it's wrong here
Counting training sessions measures awareness activity, not incident response effectiveness; attendance does not reveal detection, containment or recovery performance. It tempts because trained staff report incidents sooner, but the KPI must quantify response outcomes such as mean time to detect or contain, not the volume of education delivered.
- ✓
Mean time to respond (MTTR)
Why this is correct
MTTR measures elapsed time from incident detection to containment or resolution, directly reflecting how quickly the response process actually works. It satisfies the stem's requirement for a KPI gauging incident response effectiveness, unlike volume or cost metrics.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.