CS0-003 Incident Response and Management Practice Question
After a DDoS attack, the incident response team wants to improve detection and prevention. Which of the following metrics would be MOST useful for evaluating the effectiveness of the response?
⚠ Common exam trap
CS0-004 often tests the distinction between detection metrics (MTTD) and response metrics (MTTR), so candidates must carefully read whether the question asks about detection or response effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean Time to Respond (MTTR)
Mean Time to Respond (MTTR) measures the average time taken to respond to and resolve an incident after it is detected. In the context of evaluating the effectiveness of the response to a DDoS attack, MTTR directly reflects how quickly the team mitigated the attack and restored normal operations. A lower MTTR indicates a more effective response process, making it the most useful metric among the options.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mean Time to Respond (MTTR)
Why this is correct
Mean Time to Respond (MTTR) is the definitive metric for evaluating incident response effectiveness because it quantifies the average time taken to contain, mitigate, and resolve a security incident once it has been identified. For a DDoS attack, reducing MTTR directly correlates with minimizing service downtime and financial loss, demonstrating the team's operational efficiency in executing playbooks and deploying countermeasures like rate limiting or BGP blackholing.
- ✗
Number of false positives
Why it's wrong here
Tracking the number of false positives is a metric used to evaluate the tuning and accuracy of security monitoring tools, such as SIEM correlation rules or IDS signatures. While minimizing false positives reduces alert fatigue for analysts, it does not measure the speed or quality of the incident response team's mitigation actions once a genuine DDoS attack is underway.
- ✗
Mean Time to Detect (MTTD)
Why it's wrong here
Mean Time to Detect (MTTD) measures the duration between the initial onset of a security event and its identification by security analysts or monitoring systems. Although rapid detection is a critical precursor to mitigation, MTTD only reflects visibility and alerting capabilities rather than the team's subsequent containment and eradication performance during a DDoS scenario.
- ✗
Incidents per week
Why it's wrong here
The volume of incidents per week is a high-level threat landscape metric that indicates the frequency of attacks targeting the organization. This metric is largely determined by external threat actor activity and the organization's attack surface, making it an ineffective measure of the internal incident response team's operational efficiency or mitigation speed.
Visual reference
Go deeper
Related to this question
Learn chapter
Incident Response Process
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
MTTR
MTTR stands for Mean Time to Repair, a metric that measures the average time it takes to restore a failed system or component to full working order after a failure occurs.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.