Courseiva

CISM Information Security Governance Practice Question

Which of the following is the BEST metric for the board to assess the security program's effectiveness in detecting threats?

⚠ Common exam trap

CISM often tests the difference between preventive, detective, and corrective metrics; candidates may mistakenly choose a preventive metric like patch compliance when asked for a detection effectiveness measure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean time to detect (MTTD)

Mean time to detect (MTTD) directly measures how quickly the security program identifies threats, which is the core of detection effectiveness. It is a quantitative metric that the board can use to assess improvement over time and benchmark against industry standards. Other metrics like patch compliance or phishing click rate are preventive or user-awareness measures, not detection performance indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Patch compliance percentage

    Why it's wrong here

    Patch compliance measures remediation coverage of known vulnerabilities, not whether malicious activity is actually identified. It is tempting because patching reduces exploitable exposure, but it belongs to vulnerability management reporting. Detection effectiveness requires metrics such as mean time to detect or the proportion of incidents found internally rather than by external parties.

  • ✗

    Number of security incidents

    Why it's wrong here

    Incident counts measure how much activity occurred, not how much was detected; a low count can equally indicate poor visibility. It is tempting because incidents are the output of detection tooling, but volume alone lacks a denominator. Detection effectiveness needs coverage or time-based measures, such as percentage of incidents detected internally.

  • ✗

    Phishing simulation click rate

    Why it's wrong here

    Phishing simulation click rate measures user susceptibility and awareness training outcomes, not the capability of detection tooling to identify threats. It is tempting because phishing is a common attack vector, but it belongs to security awareness metrics. Detection effectiveness requires measures such as mean time to detect or internal discovery rate.

  • ✓

    Mean time to detect (MTTD)

    Why this is correct

    Mean time to detect directly quantifies how quickly the security programme identifies threats, giving the board a measurable indicator of detection effectiveness. Unlike volume-based metrics, MTTD reflects actual capability against the stem's detection constraint, and its trend over time shows whether monitoring, tuning and staffing investments are improving outcomes.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.