CISSP Security Assessment and Testing Practice Question
A company wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate the organization's ability to respond quickly to critical vulnerabilities?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to remediate critical vulnerabilities
Mean time to remediate (MTTR) for critical vulnerabilities directly measures the speed of response, which is a key indicator of program effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch compliance percentage
Why it's wrong here
Patch compliance percentage indicates the proportion of systems that have successfully applied all required security patches within a specified timeframe. While a critical indicator of general system hygiene and a component of vulnerability management, this metric primarily measures the breadth of patch application, not the speed of response specifically to newly discovered or critical vulnerabilities. It doesn't inherently reflect the time taken to identify, prioritize, and fully remediate a critical vulnerability beyond just applying a patch.
- ✗
ROI of security controls
Why it's wrong here
ROI of security controls quantifies the financial return on investment for security expenditures, comparing the cost of controls against the avoided losses or increased business value. While essential for budget justification and demonstrating the financial prudence of security initiatives, it does not directly measure the operational speed or efficiency with which an organization identifies and resolves vulnerabilities. This metric focuses on economic impact rather than the agility of the vulnerability response process.
- ✓
Mean time to remediate critical vulnerabilities
Why this is correct
Mean time to remediate critical vulnerabilities is a direct and highly effective metric for measuring the operational speed and efficiency of an organization's vulnerability response program. It quantifies the average duration from the initial detection of a critical vulnerability to its complete resolution, including patching, configuration changes, or architectural redesigns. This metric precisely reflects how quickly the security team and supporting IT functions can address the most significant risks, directly indicating the effectiveness of their remediation processes.
- ✗
Number of open vulnerabilities by severity
Why it's wrong here
The number of open vulnerabilities by severity provides a snapshot of the current risk backlog and the overall volume of unaddressed security issues within an environment. While this metric is crucial for understanding the overall risk posture and resource allocation needs, it does not inherently measure the speed or effectiveness of the remediation process itself. It indicates the quantity of problems, not the velocity at which those problems are being resolved once identified.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.