Courseiva
hardMultiple ChoiceObjective-mapped

CISM Practice Question: A financial services firm has a mature…

A financial services firm has a mature information security program but is struggling to demonstrate the value of security investments to the board. Which metric would BEST communicate the effectiveness of the security program in business terms?

⚠ Common exam trap

Watch out — candidates often choose a technical or operational metric (like time to patch or alert volume) because it seems directly measurable, but the CISM exam emphasizes that the board cares about business impact and financial outcomes, not technical details.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Reduction in average cost per security incident over the past year.

The reduction in average cost per security incident directly translates security program outcomes into financial terms that resonate with the board. This metric demonstrates the program's effectiveness by quantifying the monetary value of improved prevention, detection, and response capabilities, aligning with the CISM focus on governance and business alignment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Number of security alerts triaged per day.

    Why it's wrong here

    Operational metric, not a business value indicator.

  • Reduction in average cost per security incident over the past year.

    Why this is correct

    Directly ties security program effectiveness to financial impact.

  • Time to patch critical vulnerabilities.

    Why it's wrong here

    Technical metric, not directly showing business value.

  • Percentage of systems with endpoint protection installed.

    Why it's wrong here

    Does not reflect business value or risk reduction.

About these practice questions

This CISM question is part of Courseiva's 871-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.