CISSP Security Assessment and Testing Practice Question
Which TWO of the following are examples of security metrics that can be used as key performance indicators (KPIs)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mean time to remediate critical vulnerabilities
Security KPIs often include patch compliance percentages and mean time to remediate critical vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mean time to remediate critical vulnerabilities
Why this is correct
Mean time to remediate critical vulnerabilities is a crucial operational security metric, directly indicating the efficiency and effectiveness of an organization's vulnerability management program. It quantifies the average duration from the discovery of a critical vulnerability to its complete resolution, reflecting the organization's ability to mitigate high-risk threats promptly and reduce its attack surface. A lower mean time signifies a more robust and responsive security posture, directly impacting risk reduction.
- ✗
Number of servers in the data center
Why it's wrong here
The number of servers in a data center represents an inventory or asset management metric, not a direct measure of security effectiveness or performance. While understanding the asset landscape is foundational for security, this count alone does not provide insight into the security posture of those assets, the effectiveness of controls, or the organization's ability to prevent, detect, or respond to threats. It is a quantitative measure of infrastructure, not a security outcome or process metric.
- ✗
Total IT budget
Why it's wrong here
The total IT budget is a financial resource allocation metric, indicating the monetary investment in technology and operations, but it does not inherently measure security outcomes or performance. While a sufficient budget is necessary for robust security initiatives, the amount spent does not directly correlate with the effectiveness of security controls, the actual reduction of risk, or the organization's resilience against cyber threats. It quantifies input, not output or impact on the security posture.
- ✓
Patch compliance percentage
Why this is correct
Patch compliance percentage is a vital security metric that quantifies the proportion of systems that have successfully applied required security patches within a specified timeframe. This metric directly reflects the organization's diligence in maintaining system hygiene and reducing known vulnerabilities, which are frequently exploited by attackers. A high compliance rate indicates a proactive approach to mitigating common attack vectors and strengthening the overall security posture against known threats.
- ✗
Number of employees in the security department
Why it's wrong here
The number of employees in the security department is a staffing or resource metric, indicating the size of the security team, but it is not a direct measure of security performance or effectiveness. While adequate staffing is important for operational capacity, the quantity of personnel does not inherently reflect the quality of their work, the efficiency of security operations, or the actual reduction of risk to the organization. It is an input metric, not an outcome or process efficiency metric.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.