CISSP Security Assessment and Testing Practice Question
A company wants to measure the effectiveness of its vulnerability management program. Which metric would best indicate the organization's ability to respond quickly to critical vulnerabilities?
⚠ Common exam trap
CISSP often tests the difference between coverage/compliance metrics (patch percentage) and responsiveness metrics (MTTR) — candidates pick patch compliance because it sounds like a strong indicator, but the question specifically asks about speed of response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to remediate critical vulnerabilities
Mean time to remediate (MTTR) critical vulnerabilities directly measures how quickly the organization closes its highest-risk exposures, which is the clearest indicator of response speed and program effectiveness. It captures both detection-to-triage and triage-to-fix intervals, so a shrinking MTTR demonstrates improving operational capability. CISSP exam objectives emphasize metrics that reflect responsiveness and risk reduction, not just volume or compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch compliance percentage
Why it's wrong here
Patch compliance percentage indicates the proportion of systems that have successfully applied all required security patches within a specified timeframe. While a critical indicator of general system hygiene and a component of vulnerability management, this metric primarily measures the breadth of patch application, not the speed of response specifically to newly discovered or critical vulnerabilities. It doesn't inherently reflect the time taken to identify, prioritize, and fully remediate a critical vulnerability beyond just applying a patch.
- ✗
ROI of security controls
Why it's wrong here
ROI of security controls quantifies the financial return on investment for security expenditures, comparing the cost of controls against the avoided losses or increased business value. While essential for budget justification and demonstrating the financial prudence of security initiatives, it does not directly measure the operational speed or efficiency with which an organization identifies and resolves vulnerabilities. This metric focuses on economic impact rather than the agility of the vulnerability response process.
- ✓
Mean time to remediate critical vulnerabilities
Why this is correct
Mean time to remediate critical vulnerabilities is a direct and highly effective metric for measuring the operational speed and efficiency of an organization's vulnerability response program. It quantifies the average duration from the initial detection of a critical vulnerability to its complete resolution, including patching, configuration changes, or architectural redesigns. This metric precisely reflects how quickly the security team and supporting IT functions can address the most significant risks, directly indicating the effectiveness of their remediation processes.
- ✗
Number of open vulnerabilities by severity
Why it's wrong here
The number of open vulnerabilities by severity provides a snapshot of the current risk backlog and the overall volume of unaddressed security issues within an environment. While this metric is crucial for understanding the overall risk posture and resource allocation needs, it does not inherently measure the speed or effectiveness of the remediation process itself. It indicates the quantity of problems, not the velocity at which those problems are being resolved once identified.
Go deeper
Related to this question
Learn chapter
Legal, Regulatory, and Compliance Issues
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.