Courseiva
Information Security Risk ManagementeasyMultiple SelectObjective-mapped

CISM Information Security Risk Management Practice Question

Which TWO of the following are examples of key risk indicators (KRIs) for cybersecurity risk?

⚠ Common exam trap

A common mix-up: candidates confuse KRIs with KPIs, selecting metrics like training completion or phishing simulation results because they seem risk-related, but KRIs must directly measure the likelihood or impact of a risk event, not the performance of a control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Time to patch critical vulnerabilities

The time to patch critical vulnerabilities directly measures the organization's exposure window to known exploits, which is a leading indicator of cybersecurity risk. A longer patch time increases the likelihood of a successful attack, making it a key risk indicator (KRI) for vulnerability management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Time to patch critical vulnerabilities

    Why this is correct

    Patch latency is a key indicator of vulnerability risk.

  • Number of successful phishing simulations

    Why it's wrong here

    This measures training effectiveness, not risk level.

  • Number of vendors with SOC 2 reports

    Why it's wrong here

    This indicates vendor compliance, not direct risk.

  • Number of unresolved security incidents

    Why this is correct

    This is a direct measure of risk exposure.

  • Percentage of employees completing security training

    Why it's wrong here

    This measures awareness, not current risk level.

About these practice questions

One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.