CISM Information Security Risk Management Practice Question
Which TWO of the following are examples of key risk indicators (KRIs) for cybersecurity risk?
⚠ Common exam trap
A common mix-up: candidates confuse KRIs with KPIs, selecting metrics like training completion or phishing simulation results because they seem risk-related, but KRIs must directly measure the likelihood or impact of a risk event, not the performance of a control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Time to patch critical vulnerabilities
The time to patch critical vulnerabilities directly measures the organization's exposure window to known exploits, which is a leading indicator of cybersecurity risk. A longer patch time increases the likelihood of a successful attack, making it a key risk indicator (KRI) for vulnerability management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Time to patch critical vulnerabilities
Why this is correct
Patch latency is a key indicator of vulnerability risk.
- ✗
Number of successful phishing simulations
Why it's wrong here
This measures training effectiveness, not risk level.
- ✗
Number of vendors with SOC 2 reports
Why it's wrong here
This indicates vendor compliance, not direct risk.
- ✓
Number of unresolved security incidents
Why this is correct
This is a direct measure of risk exposure.
- ✗
Percentage of employees completing security training
Why it's wrong here
This measures awareness, not current risk level.
Go deeper
Related to this question
About these practice questions
One of 871 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.