CS0-003 Reporting and Communication Practice Question
Which of the following metrics measures the average time it takes to identify a security incident after it occurs?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to detect (MTTD)
MTTD is specifically defined as the average time to detect an incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch SLA compliance percentage
Why it's wrong here
Patch SLA compliance percentage is a configuration-management metric that measures whether security patches are applied within a contractual or policy-defined window (e.g., critical updates within 72 hours). It reflects the speed and discipline of patch deployment relative to vendor release dates, not the speed at which an ongoing or emerging compromise is discovered. It tracks remediation/maintenance progress after a patch is available, so it has no bearing on detecting an active threat that occurs before or during the patch cycle.
- ✗
Mean time to remediate (MTTRem)
Why it's wrong here
Mean time to remediate (MTTRem) measures the average elapsed time from when a vulnerability or incident is confirmed to when the root cause is actually neutralized, such as applying a fix, removing malware, or rebuilding a system. It is a post-detection metric because the clock starts only after an issue is already known, so it cannot indicate how quickly an attack was spotted. In contrast to MTTD, MTTRem focuses on the efficacy of the remediative response phase, not on the initial recognition of the incident.
- ✗
Mean time to respond (MTTR)
Why it's wrong here
Mean time to respond (MTTR) is a performance metric that quantifies the average duration between the initial detection/alert and the start of active response actions, such as isolating a host, stopping a process, or notifying incident responders. Like MTTRem, it is a post-detection measure—the incident must be detected before a response can occur—so it does not capture the time required to become aware of the incident in the first place. It emphasizes operational reaction speed and containment, which is conceptually separate from the detection-discovery gap that MTTD addresses.
- ✓
Mean time to detect (MTTD)
Why this is correct
Mean time to detect (MTTD) is the average elapsed time between the actual occurrence of a security incident or malicious activity and the moment it is recognized or flagged as suspicious by telemetry, analytics, or an analyst. It is the definitive metric for measuring detection velocity, because it captures the so-called "dwell time" before discovery, where the adversary may be operating unnoticed. Lower MTTD directly reduces the opportunity for attackers to achieve their objectives by limiting the window of undetected access.
Go deeper
Related to this question
Learn chapter
Incident Categories and Severity
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.