Courseiva

CISM Information Security Programme Practice Question

A security dashboard is being designed for the C-suite. Which metric is most appropriate for a one-page executive summary?

⚠ Common exam trap

Watch out — candidates often confuse operational metrics (like patch compliance or incident counts) with strategic metrics, failing to recognize that the C-suite requires a synthesized risk indicator rather than detailed technical data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security scorecard with overall risk level

The security scorecard with overall risk level is the most appropriate metric for a one-page executive summary because it provides a high-level, aggregated view of the organization's security posture. Executives need a concise, actionable summary that distills complex security data into a single risk indicator, enabling quick decision-making without technical details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of phishing simulation campaigns

    Why it's wrong here

    Phishing simulation counts measure programme activity, not enterprise risk posture, so they crowd an executive page without informing decisions. It tempts because it is a genuine security-awareness metric, and would suit a security team's operational report rather than a C-suite risk summary.

  • ✗

    List of all security incidents in the quarter

    Why it's wrong here

    An exhaustive incident list is raw operational data, not an executive metric; the C-suite needs counts, severity mix or trend, not every ticket. It is tempting because incident volume feels like a direct security indicator, and it would suit a security operations review rather than a board summary.

  • ✓

    Security scorecard with overall risk level

    Why this is correct

    A security scorecard with an overall risk level condenses many technical metrics into one business-oriented rating, satisfying the one-page C-suite constraint. Executives need aggregated posture and trend for decision-making, not operational detail such as individual vulnerability counts or patch percentages.

  • ✗

    Detailed patch compliance by system

    Why it's wrong here

    Per-system patch detail is operational granularity that cannot fit or inform a one-page executive view; executives need aggregated exposure or risk trend. It is tempting because patch compliance genuinely evidences vulnerability management maturity, making it the right choice for practitioner or audit-level reporting.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.