Courseiva
Reporting and CommunicationeasyMultiple ChoiceObjective-mapped

CS0-003 Reporting and Communication Practice Question

Which of the following metrics measures the average time it takes to identify a security incident after it occurs?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mean time to detect (MTTD)

MTTD is specifically defined as the average time to detect an incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Patch SLA compliance percentage

    Why it's wrong here

    Patch SLA compliance percentage is a configuration-management metric that measures whether security patches are applied within a contractual or policy-defined window (e.g., critical updates within 72 hours). It reflects the speed and discipline of patch deployment relative to vendor release dates, not the speed at which an ongoing or emerging compromise is discovered. It tracks remediation/maintenance progress after a patch is available, so it has no bearing on detecting an active threat that occurs before or during the patch cycle.

  • Mean time to remediate (MTTRem)

    Why it's wrong here

    Mean time to remediate (MTTRem) measures the average elapsed time from when a vulnerability or incident is confirmed to when the root cause is actually neutralized, such as applying a fix, removing malware, or rebuilding a system. It is a post-detection metric because the clock starts only after an issue is already known, so it cannot indicate how quickly an attack was spotted. In contrast to MTTD, MTTRem focuses on the efficacy of the remediative response phase, not on the initial recognition of the incident.

  • Mean time to respond (MTTR)

    Why it's wrong here

    Mean time to respond (MTTR) is a performance metric that quantifies the average duration between the initial detection/alert and the start of active response actions, such as isolating a host, stopping a process, or notifying incident responders. Like MTTRem, it is a post-detection measure—the incident must be detected before a response can occur—so it does not capture the time required to become aware of the incident in the first place. It emphasizes operational reaction speed and containment, which is conceptually separate from the detection-discovery gap that MTTD addresses.

  • Mean time to detect (MTTD)

    Why this is correct

    Mean time to detect (MTTD) is the average elapsed time between the actual occurrence of a security incident or malicious activity and the moment it is recognized or flagged as suspicious by telemetry, analytics, or an analyst. It is the definitive metric for measuring detection velocity, because it captures the so-called "dwell time" before discovery, where the adversary may be operating unnoticed. Lower MTTD directly reduces the opportunity for attackers to achieve their objectives by limiting the window of undetected access.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.