CISM Board-relevant security metric Practice Question
An information security manager is designing a metrics program to report to the board. Which of the following metrics would be MOST meaningful to the board?
⚠ Common exam trap
Many candidates confuse operational metrics (e.g., patch time, training completions) with strategic risk indicators, assuming the board wants to see activity volume rather than residual risk exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of systems with critical vulnerabilities
The board is primarily concerned with strategic risk posture and business impact. Percentage of systems with critical vulnerabilities directly quantifies the organization's exposure to high-severity threats, enabling informed risk acceptance or remediation decisions. This metric aligns with the board's fiduciary duty to oversee risk management, unlike operational details such as incident counts or training completions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security incidents reported
Why it's wrong here
Lagging indicator; board prefers leading indicators of risk.
- ✗
Average patch deployment time
Why it's wrong here
Operational detail; not strategic.
- ✗
Number of security awareness training completions
Why it's wrong here
Activity metric, not outcome.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CISM exam frequently reuses these exact scenarios with slightly different constraints.
✓Percentage of systems with critical vulnerabilitiesCorrect answer▾
✗Number of security incidents reportedWrong answer — click to see why▾
Why this is wrong here
Lagging indicator; board prefers leading indicators of risk.
✗Average patch deployment timeWrong answer — click to see why▾
Why this is wrong here
Operational detail; not strategic.
✗Number of security awareness training completionsWrong answer — click to see why▾
Why this is wrong here
Activity metric, not outcome.
Analysis generated from the official CISMblueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.