CySA+ Test CySA+ Performance Tracking and Feedback 2 — Questions and Answers
Question 1: A SOC manager wants to measure how quickly analysts contain threats after detection. Which KPI best captures this?
- Mean Time to Detect (MTTD)
- Mean Time to Contain (MTTC) (Correct answer)
- Mean Time to Recover (MTTR)
- Alert volume per shift
Correct answer: Mean Time to Contain (MTTC)
Mean Time to Contain (MTTC) measures the elapsed time from detection to the point where the threat is isolated and no longer spreading.
Question 2: Which metric best indicates the effectiveness of a security awareness training program over time?
- Number of training modules completed
- Phishing simulation click-through rate trend (Correct answer)
- Total training hours logged
- Number of employees enrolled
Correct answer: Phishing simulation click-through rate trend
A declining phishing simulation click-through rate over successive campaigns directly measures behavior change resulting from awareness training.
Question 3: A CISO reviews a report showing 95% of critical vulnerabilities are patched within the SLA window. This is an example of a:
- Qualitative risk indicator
- Key Performance Indicator (KPI) (Correct answer)
- Threat intelligence feed metric
- Incident severity score
Correct answer: Key Performance Indicator (KPI)
A patch compliance rate measured against an SLA target is a classic Key Performance Indicator (KPI) for vulnerability management.
Question 4: After an incident, an analyst documents that the initial alert fired 4 hours before analysts began investigation. This gap represents which metric?
- Dwell time
- Alert fatigue index
- Mean Time to Acknowledge (MTTA) (Correct answer)
- False positive rate
Correct answer: Mean Time to Acknowledge (MTTA)
Mean Time to Acknowledge (MTTA) measures the time between an alert firing and an analyst beginning active investigation.
Question 5: Which dashboard component best helps management understand cybersecurity posture trends across multiple quarters?
- Real-time event log viewer
- Rolling trend line charts for key metrics (Correct answer)
- Raw firewall packet captures
- Individual analyst ticket queues
Correct answer: Rolling trend line charts for key metrics
Rolling trend line charts aggregate historical metric data to show directional improvements or degradations in security posture over time.
Question 6: An organization tracks 'number of repeat incidents involving the same root cause.' This metric is intended to measure:
- Threat actor persistence
- Effectiveness of remediation and lessons learned (Correct answer)
- Vulnerability scanning coverage
- Incident response team size
Correct answer: Effectiveness of remediation and lessons learned
Repeat incidents with the same root cause indicate that prior remediation or lessons-learned processes failed to address underlying weaknesses.
Question 7: A security team sets a target that 100% of high-severity alerts must be triaged within 15 minutes. This target is best described as a:
- Vulnerability score threshold
- Service Level Agreement (SLA) (Correct answer)
- Risk appetite statement
- Threat hunting hypothesis
Correct answer: Service Level Agreement (SLA)
An SLA defines a committed performance standard, here specifying the maximum acceptable triage time for high-severity alerts.
A SOC manager wants to measure how quickly analysts contain threats after detection.
Which KPI best captures this?