Courseiva

CISSP Security Assessment and Testing Practice Question

Which THREE of the following are common key performance indicators (KPIs) used in security assessment and testing?

⚠ Common exam trap

CISSP often tests the distinction between security assessment KPIs and general operational metrics; candidates may include training or help desk tickets, but those are not direct measures of assessment and testing effectiveness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mean time to remediate critical vulnerabilities

Mean time to remediate critical vulnerabilities (A) is a core security-assessment KPI because it measures how quickly the organization closes high-risk findings, directly reflecting the effectiveness of its vulnerability management process. Patch compliance percentage (B) is also a standard KPI, quantifying the proportion of systems that have current patches applied and thus indicating exposure to known exploits. Open vulnerability count by severity (D) is a common KPI that tracks the outstanding backlog of vulnerabilities grouped by critical, high, medium, and low, giving a snapshot of residual risk and remediation workload. The other options are not typical security-assessment KPIs: the number of employees trained on security awareness (C) is a training/awareness metric rather than a measure of assessment or testing outcomes, and the number of help desk tickets (E) is an IT service management volume metric unrelated to security testing performance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Mean time to remediate critical vulnerabilities

    Why this is correct

    This is a crucial Key Performance Indicator (KPI) because it directly measures the efficiency and effectiveness of an organization's vulnerability management program. A shorter mean time indicates a robust process for identifying, prioritizing, and mitigating the most severe security flaws, thereby reducing the window of opportunity for potential exploitation. This metric reflects the operational responsiveness to high-risk findings.

  • ✓

    Patch compliance percentage

    Why this is correct

    This is a fundamental security KPI that quantifies the extent to which systems and applications adhere to required security updates and patches. A high patch compliance percentage demonstrates effective patch management processes and significantly reduces the attack surface by mitigating known vulnerabilities. It directly reflects the organization's proactive stance in maintaining a secure baseline against common exploits.

  • ✗

    Number of employees trained on security awareness

    Why it's wrong here

    While security awareness training is vital for fostering a strong security culture, the *number* of employees trained is an activity metric, not a direct security performance indicator. This metric measures the *delivery* of training rather than the *effectiveness* of security controls, the reduction of human-related risk, or the overall security posture. True KPIs would measure the *impact* of training, such as a reduction in phishing click rates or reported incidents.

  • ✓

    Open vulnerability count by severity

    Why this is correct

    This KPI provides a critical snapshot of an organization's current risk exposure by categorizing unaddressed security weaknesses based on their potential impact. Tracking this metric allows security teams to prioritize remediation efforts, allocate resources effectively, and communicate the residual risk to stakeholders. It is essential for understanding the ongoing security posture and identifying trends in vulnerability management.

  • ✗

    Number of help desk tickets

    Why it's wrong here

    The total number of help desk tickets is primarily an operational metric for IT support, reflecting user issues and system incidents across all categories. While some tickets may be security-related, this aggregate number does not specifically measure the performance of security controls, the effectiveness of vulnerability management, or the outcomes of security testing. It lacks the specificity required to be a meaningful security KPI.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.