CISM Information Security Programme Practice Question
A security manager is evaluating OKRs for the vulnerability management team. Which key result best aligns with an objective to reduce risk from vulnerabilities?
⚠ Common exam trap
CISM often tests the difference between activity-based metrics and outcome-based metrics — candidates pick scan coverage or scan frequency because they sound security-related, but OKRs demand measurable risk reduction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reduce mean time to remediate critical vulnerabilities by 30%
Reducing mean time to remediate (MTTR) critical vulnerabilities by 30% is a direct risk-reduction outcome — it shortens the window of exposure and is measurable, time-bound, and tied to the objective. OKRs require key results that measure outcomes, not activities. MTTR is a standard risk metric that security leadership uses to demonstrate reduced exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct quarterly penetration tests
Why it's wrong here
Penetration tests measure exploitation of existing weaknesses, not the reduction of known vulnerability exposure, so they do not evidence risk reduction. It is tempting because penetration testing validates controls and finds gaps, making it correct for an objective about assurance or detection rather than vulnerability risk reduction.
- ✗
Achieve 95% scan coverage of assets
Why it's wrong here
Scan coverage measures how much of the estate is assessed, not whether identified vulnerabilities were remediated, so risk may remain unchanged. It is tempting because coverage is a genuine prerequisite for effective vulnerability management, making it correct for an objective about visibility rather than risk reduction.
- ✓
Reduce mean time to remediate critical vulnerabilities by 30%
Why this is correct
Mean time to remediate is a measurable outcome tied directly to exposure duration: shortening it reduces the window in which critical vulnerabilities can be exploited. It therefore aligns with the objective to reduce risk, unlike activity counts such as scans completed.
- ✗
Increase the number of scans by 20%
Why it's wrong here
Scan volume is an activity output; more scans do not demonstrate reduced vulnerability risk, and may simply repeat findings. It is tempting because scanning underpins vulnerability management and is easy to measure, so it would be correct for an objective about increasing scanning capacity or operational throughput.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.