Courseiva
Information Security ProgrammehardMultiple SelectObjective-mapped

CISM Information Security Programme Practice Question

A security manager is developing a security scorecard for the CISO. Which THREE of the following metrics are considered LEADING indicators?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Patch compliance percentage

Leading indicators predict future incidents. Patch compliance, access review completion, and phishing click rate are proactive measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mean time to detect (MTTD)

    Why it's wrong here

    Lagging indicator of detection capability.

  • Patch compliance percentage

    Why this is correct

    Measures proactive vulnerability remediation.

  • Phishing simulation click rate

    Why this is correct

    Predicts likelihood of successful phishing attacks.

  • Number of data breaches

    Why it's wrong here

    Lagging indicator.

  • Access review completion rate

    Why this is correct

    Indicates proactive identity governance.

About these practice questions

Courseiva writes every CISM question from scratch — 871 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.