CS0-003 Reporting and Communication Practice Question
A cybersecurity analyst is building a compliance dashboard for an upcoming audit. Which TWO metrics are most relevant for demonstrating effective patch management? (Select TWO.)
⚠ Common exam trap
CS0-004 often tests whether candidates can distinguish patch management metrics (open vulns, SLA compliance) from adjacent security metrics (MTTD, phishing click rate, incident categories) that sound security-related but measure different programs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Open vulnerability counts by severity
Option A (Open vulnerability counts by severity) is correct because it directly reflects the backlog of unpatched exposures, and breaking it down by severity (critical/high/medium/low) shows whether the most dangerous CVEs are being remediated promptly, which is a core evidence point for patch management effectiveness. Option C (Patch SLA compliance %) is correct because it measures the percentage of patches applied within the organization's defined remediation timeframes (e.g., critical within 7 days, high within 30 days), directly demonstrating the discipline and performance of the patch management process. Option B (Security incidents by category) is not specific to patching—it describes overall incident trends and could stem from phishing, misconfiguration, or insider activity rather than patch status. Option D (Mean time to detect) measures detection capability (SOC/monitoring efficiency), not remediation of vulnerabilities. Option E (Phishing simulation click rates) is a security awareness metric and has no direct bearing on patch management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Open vulnerability counts by severity
Why this is correct
Tracks the number of unresolved vulnerabilities broken down by CVSS severity level (e.g., critical, high, medium, low). This is a core patch-management metric because it directly reflects the current attack-surface exposure and backlog of unpatched systems, which compliance frameworks typically require to be monitored and reduced over time.
- ✗
Security incidents by category
Why it's wrong here
Security incidents by category (e.g., malware, unauthorized access, DDoS) provide a high-level view of what has successfully compromised the environment. However, incident counts are outcome-based and can be affected by many controls beyond patching, so they do not specifically measure patch coverage, timeliness, or completeness. For a compliance dashboard focused on patch management, this metric would be too broad and indirect.
- ✓
Patch SLA compliance %
Why this is correct
Patch SLA compliance % calculates the proportion of patches that were applied within a defined service-level agreement window (e.g., critical patches within 72 hours, high within 7 days). It is a direct measure of operational discipline and regulatory adherence, since many standards mandate maximum allowable time frames for remediation. High compliance indicates both good process and low exposure to known vulnerabilities.
- ✗
Mean time to detect (MTTD)
Why it's wrong here
Mean time to detect (MTTD) measures the average duration between when a threat first compromises a system and when it is noticed by security monitoring. It is fundamentally a detection metric tied to visibility and analytics, not a metric for patch management or vulnerability remediation. Including it would evaluate the SOC's alerting efficiency rather than the patching pipeline's speed or completeness.
- ✗
Phishing simulation click rates
Why it's wrong here
Phishing simulation click rates measure how often employees fall for simulated malicious emails, reflecting the effectiveness of security awareness training. This metric belongs to a human-centric security program, not to patch management, which is about applying vendor-supplied fixes to systems. On a compliance dashboard for patching, it would provide no information about vulnerability backlog, patch SLA adherence, or unpatched hosts.
Go deeper
Related to this question
Learn chapter
Cloud Incident Response in AWS and Azure
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.