hardMultiple Select
CISSP Practice Question: Which THREE of the following are commonly used…
Which THREE of the following are commonly used metrics for measuring the effectiveness of a vulnerability management program?
⚠ Common exam trap
A common mix-up: candidates confuse Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) as both being relevant to vulnerability management, but MTTD is specific to incident response, not to the proactive patching and remediation cycle measured by MTTR and patch coverage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patch coverage percentage
Patch coverage percentage (A) is a core effectiveness metric because it quantifies the proportion of assets that have received required patches, directly reflecting how well the program closes known vulnerabilities. Mean time to remediate (C) measures the average elapsed time from vulnerability discovery to fix, showing how quickly the program reduces exposure window. Number of vulnerabilities per scan (D) tracks the volume of findings over successive scans, indicating whether the program is reducing the overall vulnerability backlog. Mean time to detect (B) is a detection/incident-response metric rather than a vulnerability management effectiveness measure, and number of security incidents (E) reflects overall security posture or incident response outcomes, not the performance of the vulnerability management process itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Patch coverage percentage
Why this is correct
Patch coverage percentage quantifies the proportion of an organization's assets (e.g., servers, applications, network devices) that have successfully received and applied necessary security patches. This metric directly measures the completeness and effectiveness of the patching process, indicating how well the vulnerability management program is protecting the environment from known exploits. A high percentage signifies a robust defense against common, remediable vulnerabilities.
- ✗
Mean time to detect (MTTD)
Why it's wrong here
Mean Time To Detect (MTTD) is a crucial metric within incident response, measuring the average time it takes for an organization to identify a security incident or breach from its inception. While vital for overall security posture and incident response capabilities, MTTD does not directly measure the effectiveness of *vulnerability management*, which focuses on proactively identifying, assessing, and remediating weaknesses before they are exploited. It pertains to post-exploitation detection, not pre-exploitation remediation.
- ✓
Mean time to remediate (MTTR)
Why this is correct
Mean Time To Remediate (MTTR) is a direct and critical metric for vulnerability management, representing the average duration from the discovery of a vulnerability to its complete resolution or mitigation. A consistently lower MTTR indicates a highly efficient and responsive vulnerability management program, demonstrating the organization's ability to quickly address and eliminate security weaknesses, thereby significantly reducing the window of exposure to potential exploits.
- ✓
Number of vulnerabilities per scan
Why this is correct
The number of vulnerabilities per scan tracks the total count of identified vulnerabilities discovered during a specific security assessment or vulnerability scan. When monitored as a trend over time, a decreasing number of vulnerabilities per scan indicates an improving security posture and the effectiveness of vulnerability management efforts in reducing the overall attack surface. It provides a quantitative measure of the ongoing vulnerability landscape and the impact of remediation activities.
- ✗
Number of security incidents
Why it's wrong here
The number of security incidents is a broad metric reflecting the overall frequency of security events that require a response from the security team. While a high number of incidents *might* indirectly suggest underlying vulnerabilities, it does not specifically measure the effectiveness of the *vulnerability management program* itself, which aims to prevent incidents by proactively addressing weaknesses. This metric is more indicative of overall security outcomes and incident response workload rather than the process of managing vulnerabilities.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.