CISSP Security Assessment and Testing Practice Question
Which THREE of the following are common key performance indicators (KPIs) used in security assessment and testing?
⚠ Common exam trap
CISSP often tests the distinction between security assessment KPIs and general operational metrics; candidates may include training or help desk tickets, but those are not direct measures of assessment and testing effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to remediate critical vulnerabilities
Mean time to remediate critical vulnerabilities (A) is a core security-assessment KPI because it measures how quickly the organization closes high-risk findings, directly reflecting the effectiveness of its vulnerability management process. Patch compliance percentage (B) is also a standard KPI, quantifying the proportion of systems that have current patches applied and thus indicating exposure to known exploits. Open vulnerability count by severity (D) is a common KPI that tracks the outstanding backlog of vulnerabilities grouped by critical, high, medium, and low, giving a snapshot of residual risk and remediation workload. The other options are not typical security-assessment KPIs: the number of employees trained on security awareness (C) is a training/awareness metric rather than a measure of assessment or testing outcomes, and the number of help desk tickets (E) is an IT service management volume metric unrelated to security testing performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mean time to remediate critical vulnerabilities
Why this is correct
This is a crucial Key Performance Indicator (KPI) because it directly measures the efficiency and effectiveness of an organization's vulnerability management program. A shorter mean time indicates a robust process for identifying, prioritizing, and mitigating the most severe security flaws, thereby reducing the window of opportunity for potential exploitation. This metric reflects the operational responsiveness to high-risk findings.
- ✓
Patch compliance percentage
Why this is correct
This is a fundamental security KPI that quantifies the extent to which systems and applications adhere to required security updates and patches. A high patch compliance percentage demonstrates effective patch management processes and significantly reduces the attack surface by mitigating known vulnerabilities. It directly reflects the organization's proactive stance in maintaining a secure baseline against common exploits.
- ✗
Number of employees trained on security awareness
Why it's wrong here
While security awareness training is vital for fostering a strong security culture, the *number* of employees trained is an activity metric, not a direct security performance indicator. This metric measures the *delivery* of training rather than the *effectiveness* of security controls, the reduction of human-related risk, or the overall security posture. True KPIs would measure the *impact* of training, such as a reduction in phishing click rates or reported incidents.
- ✓
Open vulnerability count by severity
Why this is correct
This KPI provides a critical snapshot of an organization's current risk exposure by categorizing unaddressed security weaknesses based on their potential impact. Tracking this metric allows security teams to prioritize remediation efforts, allocate resources effectively, and communicate the residual risk to stakeholders. It is essential for understanding the ongoing security posture and identifying trends in vulnerability management.
- ✗
Number of help desk tickets
Why it's wrong here
The total number of help desk tickets is primarily an operational metric for IT support, reflecting user issues and system incidents across all categories. While some tickets may be security-related, this aggregate number does not specifically measure the performance of security controls, the effectiveness of vulnerability management, or the outcomes of security testing. It lacks the specificity required to be a meaningful security KPI.
Go deeper
Related to this question
Learn chapter
Security Assessment and Testing
Key term
Security assessment
A security assessment is a systematic evaluation of an organization’s systems, networks, and applications to identify vulnerabilities, threats, and risks, and to recommend improvements.
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.