Courseiva

CISA Governance and Management of IT Practice Question

An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?

⚠ Common exam trap

Watch out — candidates often confuse incident management metrics with service desk or availability metrics, picking 'percentage of incidents resolved on first call' because it sounds like a measure of effectiveness, but it actually measures first-contact resolution efficiency, not the end-to-end incident management process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean time to resolve (MTTR) incidents

Mean time to resolve (MTTR) is the most appropriate metric for measuring the effectiveness of incident management because it directly reflects how quickly the IT team can restore normal service operation after an incident. In ITIL-based ITSM tools, MTTR tracks the elapsed time from incident logging to resolution, providing a clear indicator of process efficiency and team responsiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mean time to resolve (MTTR) incidents

    Why this is correct

    MTTR directly quantifies how quickly incidents are resolved, which is the core effectiveness measure for incident management. It satisfies the stem's requirement to gauge the ITSM process's performance by tracking elapsed time from incident logging to restoration of normal service.

  • ✗

    Percentage of incidents resolved on first call

    Why it's wrong here

    First-call resolution measures service desk efficiency at the point of contact, not the overall effectiveness of incident management, which requires metrics such as the percentage of incidents resolved within agreed service levels or reopened rates. It is tempting because it is easy to collect from the ITSM tool.

  • ✗

    Number of incidents reported per month

    Why it's wrong here

    Incident volume measures demand on the service desk, not how effectively incidents are managed, since a rising count can accompany either good or poor handling. It is tempting because volume is easy to report, and it would be correct when capacity planning or trend analysis is the goal.

  • ✗

    Percentage of system uptime

    Why it's wrong here

    Uptime measures service availability, not incident management effectiveness, since it reflects infrastructure resilience rather than how well incidents are handled. It is tempting because availability is a headline ITSM outcome, and uptime would be correct when reporting service level availability against targets.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.