CISM Information Security Programme Practice Question
An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?
⚠ Common exam trap
CISM often tests metric interpretation — candidates see 'high MTTR' and blame detection tools or staffing, but the question's low MTTD is the clue that the response process, not detection, is the bottleneck.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The incident response process lacks automation or clear procedures
Low MTTD means detection is working well, but high MTTR indicates the response phase is slow — typically due to manual processes, lack of automation (SOAR), unclear playbooks, or approval bottlenecks. The most likely cause is that the incident response process itself is inefficient, not that detection is failing. This points to a response capability gap rather than a detection or staffing issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The team is understaffed during off-hours
Why it's wrong here
Off-hours understaffing delays detection because fewer analysts watch alerts, so MTTD would rise, not stay low. It is the right answer when coverage gaps push detection times up; here detection is already fast, so the delay must occur after an alert is raised, during response.
- ✗
The vulnerability management program is ineffective
Why it's wrong here
An ineffective vulnerability management programme concerns patching exposure, not the speed of investigating and containing alerts already raised. It would be the correct focus when remediation backlogs or recurring exploited vulnerabilities drive risk, not when the SOC's detection is fast but containment lags.
- ✗
The SIEM is generating too many false positives
Why it's wrong here
False positives inflate triage workload, which raises MTTD rather than leaving it low; detection is already fast here, so the bottleneck sits in response. High false-positive volume is the classic cause of slow detection, making it the right answer when MTTD itself is the failing metric.
- ✓
The incident response process lacks automation or clear procedures
Why this is correct
Low MTTD with high MTTR indicates detection works but containment stalls, pointing to missing automation or unclear incident response procedures. The SOC identifies incidents promptly yet lacks defined escalation and remediation workflows to close them efficiently.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.