ISC2 CISSP Practice Question

A security manager is implementing a comprehensive security metrics program and needs to select appropriate indicators to measure the effectiveness of the organization's security controls. Which of the following metrics would be the BEST example of a key risk indicator (KRI) for monitoring the organization's patch management effectiveness?

  • Percentage of systems with critical vulnerabilities older than 30 days

  • Number of security team members certified in patch management

  • Number of patches applied per month

  • Average time to deploy security tools

ISC2 CISSP
Security Assessment and Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot