Courseiva

CISM Information Security Programme Practice Question

A security manager is developing OKRs for the security team. Which TWO key results are appropriate leading indicators? (Select TWO)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Complete 100% of privileged access reviews quarterly

Option A is correct because completing 100% of privileged access reviews quarterly is a proactive, measurable activity that the security team directly controls and that reduces the likelihood of credential misuse before any incident occurs, making it a classic leading indicator. Option D is correct because achieving 95% patch compliance within 30 days of release is likewise an actionable, preventive process metric that the team can drive and that lowers exploitability of known CVEs, so it predicts future risk reduction. By contrast, option B (zero critical vulnerabilities in external scans) is an outcome/target state rather than a controllable activity, option C (reduce data breaches by 20%) is a lagging outcome that only materializes after incidents, and option E (decrease MTTD to under 1 hour) measures detection performance after events have already occurred, so all three are lagging or outcome-oriented rather than leading indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Complete 100% of privileged access reviews quarterly

    Why this is correct

    Completing all privileged access reviews quarterly is a leading indicator because it measures preventive control activity rather than breach outcomes. It satisfies the stem's forward-looking constraint by evidencing proactive oversight of elevated permissions before misuse occurs, unlike lagging metrics such as incident counts or audit findings that only report after-the-fact results.

  • ✗

    Achieve zero critical vulnerabilities in external scans

    Why it's wrong here

    Zero critical vulnerabilities is an outcome measured after scanning, so it reports past state rather than driving future activity. It is tempting as a concrete, quantifiable target, and it would be a valid lagging key result when the objective is to demonstrate reduced exposure at a point in time.

  • ✗

    Reduce number of data breaches by 20%

    Why it's wrong here

    Breach counts are lagging: they record incidents after controls fail, so they cannot indicate whether security is improving. It is tempting because reducing breaches is a genuine outcome goal, but leading indicators must measure preventive activity, such as patch coverage or training completion.

  • ✓

    Achieve 95% patch compliance within 30 days of release

    Why this is correct

    Patch compliance within 30 days is a leading indicator because it measures proactive remediation activity that predicts reduced vulnerability exposure, rather than reporting breaches already suffered. It satisfies the OKR requirement for measurable, forward-looking key results tied to reducing exploitable attack surface.

  • ✗

    Decrease mean time to detect (MTTD) to under 1 hour

    Why it's wrong here

    MTTD measures detection after an incident has already occurred, so it lags the outcome rather than predicting it. It is tempting because it is a genuine, measurable security metric, and it would be a valid lagging key result when the objective is to reduce incident impact retrospectively.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.