Courseiva
Information Security ProgrammediumMultiple ChoiceObjective-mapped

CISM Board-relevant security metric Practice Question

An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?

⚠ Common exam trap

Many candidates confuse operational metrics (e.g., patch time, training completions) with strategic risk indicators, assuming the board wants to see activity volume rather than residual risk exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Percentage of systems with critical vulnerabilities

The board is primarily concerned with strategic risk posture and business impact. Percentage of systems with critical vulnerabilities directly quantifies the organization's exposure to high-severity threats, enabling informed risk acceptance or remediation decisions. This metric aligns with the board's fiduciary duty to oversee risk management, unlike operational details such as incident counts or training completions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Number of security incidents reported

    Why it's wrong here

    Lagging indicator; board prefers leading indicators of risk.

  • Average patch deployment time

    Why it's wrong here

    Operational detail; not strategic.

  • Number of security awareness training completions

    Why it's wrong here

    Activity metric, not outcome.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.

Percentage of systems with critical vulnerabilitiesCorrect answer
Number of security incidents reportedWrong answer — click to see why

Why this is wrong here

Lagging indicator; board prefers leading indicators of risk.

Average patch deployment timeWrong answer — click to see why

Why this is wrong here

Operational detail; not strategic.

Number of security awareness training completionsWrong answer — click to see why

Why this is wrong here

Activity metric, not outcome.

Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.