Courseiva

CISM Information Security Programme Practice Question

An organization's SOC team is measured on mean time to detect (MTTD) and mean time to respond (MTTR). The security manager notices that MTTD is low but MTTR is high. What is the most likely cause?

⚠ Common exam trap

CISM often tests metric interpretation — candidates see 'high MTTR' and blame detection tools or staffing, but the question's low MTTD is the clue that the response process, not detection, is the bottleneck.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The incident response process lacks automation or clear procedures

Low MTTD means detection is working well, but high MTTR indicates the response phase is slow — typically due to manual processes, lack of automation (SOAR), unclear playbooks, or approval bottlenecks. The most likely cause is that the incident response process itself is inefficient, not that detection is failing. This points to a response capability gap rather than a detection or staffing issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The team is understaffed during off-hours

    Why it's wrong here

    Off-hours understaffing delays detection because fewer analysts watch alerts, so MTTD would rise, not stay low. It is the right answer when coverage gaps push detection times up; here detection is already fast, so the delay must occur after an alert is raised, during response.

  • ✗

    The vulnerability management program is ineffective

    Why it's wrong here

    An ineffective vulnerability management programme concerns patching exposure, not the speed of investigating and containing alerts already raised. It would be the correct focus when remediation backlogs or recurring exploited vulnerabilities drive risk, not when the SOC's detection is fast but containment lags.

  • ✗

    The SIEM is generating too many false positives

    Why it's wrong here

    False positives inflate triage workload, which raises MTTD rather than leaving it low; detection is already fast here, so the bottleneck sits in response. High false-positive volume is the classic cause of slow detection, making it the right answer when MTTD itself is the failing metric.

  • ✓

    The incident response process lacks automation or clear procedures

    Why this is correct

    Low MTTD with high MTTR indicates detection works but containment stalls, pointing to missing automation or unclear incident response procedures. The SOC identifies incidents promptly yet lacks defined escalation and remediation workflows to close them efficiently.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.