CISM Information Security Governance Practice Question
A CISO is presenting the information security program's value to the board. The board is particularly concerned about the organization's ability to detect and respond to advanced threats. Which of the following metrics would BEST demonstrate the program's effectiveness in this area?
⚠ Common exam trap
The trap here is selecting metrics that measure activity or coverage rather than the speed and success of detection and response, which are what the board cares about.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The mean time to detect (MTTD) and mean time to respond (MTTR) to advanced threats.
Mean time to detect (MTTD) and mean time to respond (MTTR) are outcome-based metrics that directly reflect the program's ability to detect and respond to threats. They are meaningful to the board because they quantify operational effectiveness and can be benchmarked. Other metrics like incident counts or control counts do not provide the same level of assurance regarding detection and response capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The mean time to detect (MTTD) and mean time to respond (MTTR) to advanced threats.
Why this is correct
MTTD and MTTR directly measure how quickly the organization detects and responds to threats. These metrics demonstrate the efficiency of detection and response processes, which is exactly what the board is concerned about. They provide actionable insights and can be tracked over time to show improvement.
- ✗
The percentage of critical assets covered by continuous monitoring.
Why it's wrong here
Coverage of critical assets is important for visibility, but it does not measure the effectiveness of detection and response. It indicates potential capability, not actual performance. The board is concerned with the ability to detect and respond, which requires metrics on speed and success of those activities.
- ✗
The number of security incidents detected per quarter.
Why it's wrong here
The number of incidents detected does not indicate effectiveness; it may simply reflect increased activity or improved detection. Without context on severity or response, it can be misleading. The board needs metrics that show how well the organization detects and responds, not just raw counts.
- ✗
The total number of security controls implemented across the enterprise.
Why it's wrong here
The number of controls implemented is a measure of effort, not effectiveness. It does not indicate whether threats are detected or responded to efficiently. The board wants assurance that the program can detect and respond to advanced threats, which requires outcome-based metrics, not input metrics.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.