Courseiva

CISM Information Security Programme Practice Question

A CISO is designing a security scorecard for the board of directors. Which metric is most appropriate to include for a one-page executive dashboard?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of systems patched within SLA

The board needs high-level, strategic metrics. Percentage of systems patched within SLA provides a clear, concise view of vulnerability management status, which is critical for risk reduction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Detailed list of known vulnerabilities

    Why it's wrong here

    A vulnerability list is operational detail, not a board-level risk indicator, and cannot fit a one-page dashboard. Such lists belong in vulnerability management reporting to technical teams. Boards need aggregated risk exposure and trend metrics that map to business objectives.

  • ✗

    Number of phishing simulations conducted

    Why it's wrong here

    Counting phishing simulations measures activity volume, not security effectiveness or risk reduction. Boards need outcome metrics such as click rates or incident trends. Simulation counts suit awareness programme tracking by security managers, not executive risk oversight.

  • ✗

    Names of vendors with critical findings

    Why it's wrong here

    Naming vendors with critical findings exposes operational detail and third-party identities unsuitable for board reporting. Vendor risk belongs in supply chain risk reviews with procurement and security teams. Boards require aggregated third-party risk exposure, not individual vendor names.

  • ✓

    Percentage of systems patched within SLA

    Why this is correct

    Patch compliance within SLA is a quantifiable, outcome-based operational metric that translates technical risk into business terms the board can act on. It shows whether vulnerability exposure is being managed within agreed timeframes, fitting a one-page dashboard.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.