Courseiva

CISM Information Security Programme Practice Question

A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch compliance percentage

Leading indicators are forward-looking metrics that measure the strength of preventive and detective controls before incidents occur. B (Patch compliance percentage) is correct because it quantifies how much of the environment is protected against known vulnerabilities, predicting future exploit risk. C (Phishing simulation click rate) is correct because it measures current user susceptibility to social engineering, forecasting the likelihood of future successful phishing compromises. E (Access review completion rate) is correct because it reflects whether least-privilege and entitlement hygiene processes are being executed, reducing future unauthorized-access risk. A (MTTD) is a detective/operational metric that measures how quickly incidents are found after they occur, and D (number of data breaches) is a lagging outcome metric that reports incidents that already happened, so neither is a leading indicator.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Mean time to detect (MTTD)

    Why it's wrong here

    MTTD measures how quickly incidents are found after they occur, so it reports past detection performance rather than predicting future risk. It is tempting because faster detection feels proactive, but leading indicators must measure preventive control effectiveness before incidents happen.

  • ✓

    Patch compliance percentage

    Why this is correct

    Patch compliance percentage measures preventive maintenance before exploitation occurs, satisfying the stem's leading-indicator requirement. Unlike breach counts or incident volumes, which record events already realised, it tracks control effectiveness prospectively, giving the CISO an early signal of exposure reduction across Microsoft Entra ID-managed and on-premises estates.

  • ✓

    Phishing simulation click rate

    Why this is correct

    Phishing simulation click rate measures user susceptibility before a real campaign succeeds, forecasting likely breach likelihood. This predictive quality makes it a leading indicator, satisfying the scorecard's requirement for metrics that anticipate rather than report incidents.

  • ✗

    Number of data breaches

    Why it's wrong here

    Breach counts are lagging indicators, recording incidents after impact. It is tempting because breaches are highly visible and board-relevant, but leading indicators must measure control effectiveness or exposure before incidents occur, such as vulnerability remediation rates.

  • ✓

    Access review completion rate

    Why this is correct

    Access review completion rate measures preventive identity governance effort before access-related incidents occur, satisfying the stem's leading indicator requirement. Unlike lagging metrics such as breach counts, it tracks proactive control execution within Microsoft Entra ID, signalling whether excessive access is being curtailed. High completion predicts reduced standing privilege risk, making it forward-looking.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.