Courseiva
hardMultiple Select

CISSP Practice Question: Which THREE of the following are commonly used…

Which THREE of the following are commonly used metrics for measuring the effectiveness of a vulnerability management program?

⚠ Common exam trap

A common mix-up: candidates confuse Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) as both being relevant to vulnerability management, but MTTD is specific to incident response, not to the proactive patching and remediation cycle measured by MTTR and patch coverage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Patch coverage percentage

Patch coverage percentage (A) is a core effectiveness metric because it quantifies the proportion of assets that have received required patches, directly reflecting how well the program closes known vulnerabilities. Mean time to remediate (C) measures the average elapsed time from vulnerability discovery to fix, showing how quickly the program reduces exposure window. Number of vulnerabilities per scan (D) tracks the volume of findings over successive scans, indicating whether the program is reducing the overall vulnerability backlog. Mean time to detect (B) is a detection/incident-response metric rather than a vulnerability management effectiveness measure, and number of security incidents (E) reflects overall security posture or incident response outcomes, not the performance of the vulnerability management process itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Patch coverage percentage

    Why this is correct

    Patch coverage percentage quantifies the proportion of an organization's assets (e.g., servers, applications, network devices) that have successfully received and applied necessary security patches. This metric directly measures the completeness and effectiveness of the patching process, indicating how well the vulnerability management program is protecting the environment from known exploits. A high percentage signifies a robust defense against common, remediable vulnerabilities.

  • ✗

    Mean time to detect (MTTD)

    Why it's wrong here

    Mean Time To Detect (MTTD) is a crucial metric within incident response, measuring the average time it takes for an organization to identify a security incident or breach from its inception. While vital for overall security posture and incident response capabilities, MTTD does not directly measure the effectiveness of *vulnerability management*, which focuses on proactively identifying, assessing, and remediating weaknesses before they are exploited. It pertains to post-exploitation detection, not pre-exploitation remediation.

  • ✓

    Mean time to remediate (MTTR)

    Why this is correct

    Mean Time To Remediate (MTTR) is a direct and critical metric for vulnerability management, representing the average duration from the discovery of a vulnerability to its complete resolution or mitigation. A consistently lower MTTR indicates a highly efficient and responsive vulnerability management program, demonstrating the organization's ability to quickly address and eliminate security weaknesses, thereby significantly reducing the window of exposure to potential exploits.

  • ✓

    Number of vulnerabilities per scan

    Why this is correct

    The number of vulnerabilities per scan tracks the total count of identified vulnerabilities discovered during a specific security assessment or vulnerability scan. When monitored as a trend over time, a decreasing number of vulnerabilities per scan indicates an improving security posture and the effectiveness of vulnerability management efforts in reducing the overall attack surface. It provides a quantitative measure of the ongoing vulnerability landscape and the impact of remediation activities.

  • ✗

    Number of security incidents

    Why it's wrong here

    The number of security incidents is a broad metric reflecting the overall frequency of security events that require a response from the security team. While a high number of incidents *might* indirectly suggest underlying vulnerabilities, it does not specifically measure the effectiveness of the *vulnerability management program* itself, which aims to prevent incidents by proactively addressing weaknesses. This metric is more indicative of overall security outcomes and incident response workload rather than the process of managing vulnerabilities.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.