Courseiva
Reporting and CommunicationeasyMultiple ChoiceObjective-mapped

CS0-003 Reporting and Communication Practice Question

Which metric measures the average time it takes for an organization to identify a security incident from the moment it occurs?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mean Time to Detect (MTTD)

Mean Time to Detect (MTTD) is the average time to detect an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mean Time to Resolve (MTTR)

    Why it's wrong here

    Mean Time to Resolve (MTTR) is an incident response metric that measures the duration from when an incident is identified to when it is fully resolved and operations are restored. It encompasses containment, eradication, and recovery activities, but assumes detection already happened. Because MTTR focuses on post-detection response, it does not quantify how quickly an organization becomes aware of a threat.

  • Patch SLA compliance percentage

    Why it's wrong here

    Patch SLA compliance percentage is a vulnerability management KPI that tracks the percentage of systems patched within a predefined service-level agreement deadline, such as 72 hours for critical vulnerabilities. It gauges operational discipline in applying fixes, not the speed of detecting an incident. This metric measures process adherence for remediation activities, completely unrelated to the time between compromise and alerting.

  • Mean Time to Remediate (MTTRem)

    Why it's wrong here

    Mean Time to Remediate (MTTRem) is a metric that measures the elapsed time from the moment a threat is detected to when the vulnerability or infection is effectively eliminated and normal service is restored. Unlike detection metrics, MTTRem always starts after detection has occurred, making it a measure of response efficiency. Therefore, it cannot represent the average time needed to discover an incident in the first place.

  • Mean Time to Detect (MTTD)

    Why this is correct

    Mean Time to Detect (MTTD) is the correct metric, as it measures the average elapsed time between the initial occurrence of a security incident—such as an intrusion or malware compromise—and the moment it is identified by monitoring tools or security personnel. Shorter MTTD directly reduces attacker dwell time and potential damage. This metric is specifically designed to gauge the speed and effectiveness of an organization's detection capabilities.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.