Courseiva

CS0-003 Incident Response and Management Practice Question

After a DDoS attack, the incident response team wants to improve detection and prevention. Which of the following metrics would be MOST useful for evaluating the effectiveness of the response?

⚠ Common exam trap

CS0-004 often tests the distinction between detection metrics (MTTD) and response metrics (MTTR), so candidates must carefully read whether the question asks about detection or response effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean Time to Respond (MTTR)

Mean Time to Respond (MTTR) measures the average time taken to respond to and resolve an incident after it is detected. In the context of evaluating the effectiveness of the response to a DDoS attack, MTTR directly reflects how quickly the team mitigated the attack and restored normal operations. A lower MTTR indicates a more effective response process, making it the most useful metric among the options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mean Time to Respond (MTTR)

    Why this is correct

    Mean Time to Respond (MTTR) is the definitive metric for evaluating incident response effectiveness because it quantifies the average time taken to contain, mitigate, and resolve a security incident once it has been identified. For a DDoS attack, reducing MTTR directly correlates with minimizing service downtime and financial loss, demonstrating the team's operational efficiency in executing playbooks and deploying countermeasures like rate limiting or BGP blackholing.

  • ✗

    Number of false positives

    Why it's wrong here

    Tracking the number of false positives is a metric used to evaluate the tuning and accuracy of security monitoring tools, such as SIEM correlation rules or IDS signatures. While minimizing false positives reduces alert fatigue for analysts, it does not measure the speed or quality of the incident response team's mitigation actions once a genuine DDoS attack is underway.

  • ✗

    Mean Time to Detect (MTTD)

    Why it's wrong here

    Mean Time to Detect (MTTD) measures the duration between the initial onset of a security event and its identification by security analysts or monitoring systems. Although rapid detection is a critical precursor to mitigation, MTTD only reflects visibility and alerting capabilities rather than the team's subsequent containment and eradication performance during a DDoS scenario.

  • ✗

    Incidents per week

    Why it's wrong here

    The volume of incidents per week is a high-level threat landscape metric that indicates the frequency of attacks targeting the organization. This metric is largely determined by external threat actor activity and the organization's attack surface, making it an ineffective measure of the internal incident response team's operational efficiency or mitigation speed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.