CRISC Risk Response and Reporting Practice Question
Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a firewall?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Number of blocked intrusion attempts
A KCI measures the performance or effectiveness of a control. The number of blocked intrusion attempts is a direct measure of the firewall's preventive effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of security incidents reported
Why it's wrong here
Incident counts aggregate outcomes across all controls, so a firewall blocking traffic effectively cannot be distinguished from other defences preventing the same incidents. It is tempting because incident volume is readily available, and would be a valid KRI for overall security posture rather than a KCI for one firewall.
- ✓
Number of blocked intrusion attempts
Why this is correct
Blocked intrusion attempts measure the firewall's actual defensive effectiveness against real traffic, making it a KCI rather than a configuration metric. Rule counts or patch levels indicate effort or state, not control performance, so this satisfies the stem's requirement for an effectiveness measure.
- ✗
Average time to patch vulnerabilities
Why it's wrong here
Patch latency measures vulnerability management on hosts, not the firewall's rule enforcement, configuration integrity or traffic filtering capability. It is tempting because patching is a measurable control activity, and would be a valid KCI for a patch management process, not for the firewall itself.
- ✗
Percentage of employees who completed security training
Why it's wrong here
Training completion measures personnel awareness, not firewall rule enforcement, throughput or blocked-traffic outcomes, so it cannot indicate whether the firewall control itself operates effectively. It is tempting because awareness metrics are easy to collect and report, and would be a valid KCI for a security awareness programme rather than a perimeter device.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.