Courseiva

CISM Information Security Programme Practice Question

A security manager is developing a set of objectives and key results (OKRs) for the security program. Which THREE would be considered effective security OKRs?

⚠ Common exam trap

CISM often tests the difference between output/deliverable metrics and outcome-based key results — candidates select activity-based statements (deploy, conduct) as OKRs when true KRs must measure results or impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Objective: Enhance incident response. Key Result: Achieve 100% of incidents logged within 1 hour of detection.

Effective security OKRs pair a qualitative Objective with measurable, outcome-focused Key Results that have a baseline, target, and timeframe. Option B is correct because 'Achieve 100% of incidents logged within 1 hour of detection' is a quantifiable, time-bound metric that directly measures improved incident response performance. Option C is correct because reducing mean time to remediate critical vulnerabilities from 30 to 7 days specifies a clear baseline (30 days), target (7 days), and metric (MTTR), making it a measurable risk-reduction outcome. Option E is correct because completing risk assessments for 100% of high-tier vendors by year-end is a specific, measurable, and time-bound result tied to reducing third-party risk. Option A is not correct because 'Deploy SIEM by Q3' is a project deliverable/milestone, not an outcome-based key result measuring security improvement. Option D is not correct because 'Conduct quarterly phishing simulations' is an activity/output rather than a measurable outcome such as reduced click rate or reporting rate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Objective: Implement a new SIEM. Key Result: Deploy SIEM by Q3.

    Why it's wrong here

    Deploying a SIEM is a project deliverable, not a measurable outcome; the key result restates the objective rather than quantifying risk reduction or detection improvement. It is tempting because tool rollouts feel concrete and trackable, and such a milestone would be correct as a project plan task rather than a security OKR.

  • ✓

    Objective: Enhance incident response. Key Result: Achieve 100% of incidents logged within 1 hour of detection.

    Why this is correct

    The key result is measurable, time-bound and outcome-focused: logging every incident within one hour of detection is verifiable and directly supports faster containment. It avoids vague activity statements, satisfying the OKR requirement for quantifiable progress tied to a clear objective.

  • ✓

    Objective: Improve vulnerability management. Key Result: Reduce mean time to remediate critical vulnerabilities from 30 to 7 days.

    Why this is correct

    Reducing mean time to remediate from 30 to 7 days is a specific, numeric improvement with a baseline and target, exactly what an effective key result requires. It measures risk reduction outcome rather than effort, making progress objectively verifiable.

  • ✗

    Objective: Increase security awareness. Key Result: Conduct quarterly phishing simulations.

    Why it's wrong here

    Counting simulations run measures activity, not whether awareness improved; a valid key result would track phishing click-through or report rates. It is tempting because quarterly simulations are concrete and schedulable, and that cadence would be correct as an operational control activity rather than an outcome-based key result.

  • ✓

    Objective: Reduce risk from third parties. Key Result: Complete risk assessments for 100% of high-tier vendors by year-end.

    Why this is correct

    Completing risk assessments for all high-tier vendors by year-end is binary, time-bound and scoped to the riskiest relationships. It ties directly to the objective of reducing third-party risk and provides unambiguous evidence of completion, satisfying key result criteria.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.