
Information Systems Security Management Professional
Domain 1Objective 7
1.7 Define, Measure, and Report Security Metrics ISSMP Practice Questions (Page 1)
Part of the Leadership and Organizational Management domain, which accounts for 21% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
8concepts
21%of the exam
Questions 1–5
- 1
When reporting security metrics to a board of directors, what is the most effective approach?
Select an answer first - 2
A financial services firm's board of directors asks the CISO for a single metric that will provide early warning that the firm's exposure to ransomware is increasing, before a breach actually occurs. The CISO wants to give the board a metric that is forward-looking and tied to specific risk factors. Which metric should the CISO report?
Select an answer first - 3
When selecting security metrics for an organization, what is the most important consideration?
Select an answer first - 4
A retail company's strategic goal is to reduce the impact of a potential data breach. The security team is defining KPIs to measure progress toward this goal. Which KPI is most directly aligned with reducing the impact of a breach?
Select an answer first - 5
What is the primary purpose of a Key Risk Indicator (KRI)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.