โ† All CySA+ Test Flashcard Decks

CySA+ Performance Tracking and Feedback Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CySA+ Performance Tracking and Feedback flashcards as text
  1. A security program uses OKRs (Objectives and Key Results). Which example correctly represents a security OKR?

    Answer: Objective: Reduce breach risk; KR: Decrease critical vuln remediation time from 30 to 10 days by Q4

    A well-formed security OKR links an aspirational objective (reduce breach risk) to a measurable, time-bound key result (remediation time improvement).

  2. Which practice best ensures that security metrics remain relevant and aligned with evolving business objectives?

    Answer: Review and update metrics regularly against current business goals and threat landscape

    Regular metric reviews ensure alignment with evolving business priorities and the current threat environment, keeping the security program relevant and effective.

  3. An analyst is creating a report for the security steering committee. Which data visualization best shows the distribution of incidents by category over 12 months?

    Answer: Stacked bar chart of incident categories per month

    A stacked bar chart effectively shows both the total incident volume and the proportion of each category across multiple time periods.

  4. A threat intelligence program tracks 'indicator sharing timeliness.' What does this metric measure?

    Answer: The time elapsed between receiving a threat indicator and sharing it with trusted partners

    Indicator sharing timeliness measures how quickly the organization disseminates actionable threat indicators to partners after receiving them, impacting collective defense.

  5. Which of the following is an example of a lagging indicator in a security program?

    Answer: Number of security incidents confirmed last quarter

    Incidents confirmed last quarter are a lagging indicator because they reflect past performance rather than current or predictive security posture.

  6. A security manager wants to benchmark the organization's mean time to detect against industry peers. Which resource is most appropriate?

    Answer: Industry threat reports and benchmarking studies such as Verizon DBIR

    Reports like the Verizon Data Breach Investigations Report (DBIR) provide industry-aggregated statistics that enable meaningful benchmarking of detection metrics.

  7. Which metric is most useful for evaluating the ROI of a recently deployed endpoint detection and response (EDR) tool?

    Answer: Reduction in average dwell time and incidents reaching critical severity since deployment

    Reduction in dwell time and critical-severity incidents directly ties the EDR tool's output to improved detection effectiveness, demonstrating return on investment.