CISM Information Security Programme Practice Question
A CISO wants to present a high-level security status to the board using a one-page dashboard. Which of the following metrics is MOST appropriate for this audience?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing click rate and patch compliance percentage
Leading indicators like phishing click rate and patch compliance are actionable and forward-looking, suitable for board-level oversight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing click rate and patch compliance percentage
Why this is correct
Leading indicators that show risk trends and control effectiveness.
- ✗
Mean time to detect (MTTD) for incidents
Why it's wrong here
Lagging indicator, not as forward-looking.
- ✗
Detailed vulnerability counts by severity
Why it's wrong here
Too granular for board; better for operational reporting.
- ✗
Total number of security controls implemented
Why it's wrong here
Does not measure effectiveness or risk reduction.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.