Courseiva
Security Assessment and TestingeasyMultiple SelectObjective-mapped

CISSP Security Assessment and Testing Practice Question

Which TWO of the following are examples of security metrics that can be used as key performance indicators (KPIs)?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mean time to remediate critical vulnerabilities

Security KPIs often include patch compliance percentages and mean time to remediate critical vulnerabilities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mean time to remediate critical vulnerabilities

    Why this is correct

    Mean time to remediate critical vulnerabilities is a crucial operational security metric, directly indicating the efficiency and effectiveness of an organization's vulnerability management program. It quantifies the average duration from the discovery of a critical vulnerability to its complete resolution, reflecting the organization's ability to mitigate high-risk threats promptly and reduce its attack surface. A lower mean time signifies a more robust and responsive security posture, directly impacting risk reduction.

  • Number of servers in the data center

    Why it's wrong here

    The number of servers in a data center represents an inventory or asset management metric, not a direct measure of security effectiveness or performance. While understanding the asset landscape is foundational for security, this count alone does not provide insight into the security posture of those assets, the effectiveness of controls, or the organization's ability to prevent, detect, or respond to threats. It is a quantitative measure of infrastructure, not a security outcome or process metric.

  • Total IT budget

    Why it's wrong here

    The total IT budget is a financial resource allocation metric, indicating the monetary investment in technology and operations, but it does not inherently measure security outcomes or performance. While a sufficient budget is necessary for robust security initiatives, the amount spent does not directly correlate with the effectiveness of security controls, the actual reduction of risk, or the organization's resilience against cyber threats. It quantifies input, not output or impact on the security posture.

  • Patch compliance percentage

    Why this is correct

    Patch compliance percentage is a vital security metric that quantifies the proportion of systems that have successfully applied required security patches within a specified timeframe. This metric directly reflects the organization's diligence in maintaining system hygiene and reducing known vulnerabilities, which are frequently exploited by attackers. A high compliance rate indicates a proactive approach to mitigating common attack vectors and strengthening the overall security posture against known threats.

  • Number of employees in the security department

    Why it's wrong here

    The number of employees in the security department is a staffing or resource metric, indicating the size of the security team, but it is not a direct measure of security performance or effectiveness. While adequate staffing is important for operational capacity, the quantity of personnel does not inherently reflect the quality of their work, the efficiency of security operations, or the actual reduction of risk to the organization. It is an input metric, not an outcome or process efficiency metric.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.