
Information Systems Security Management Professional
Domain 1Objective 7
1.7 Define, Measure, and Report Security Metrics ISSMP Practice Questions (Page 4)
Part of the Leadership and Organizational Management domain, which accounts for 21% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~15–25 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
8concepts
21%of the exam
Questions 16–20
- 16
A security metric shows a consistent upward trend in the number of phishing emails reported by employees. What is the most appropriate use of this metric?
Select an answer first - 17
A security manager is establishing a baseline for the metric 'percentage of endpoints with a compliant security agent version'. The organization has just completed a major endpoint refresh, and the current compliance rate is 99%. Historical data from the previous year shows an average compliance rate of 92% with a standard deviation of 3%. What is the most appropriate baseline to use for this metric?
Select an answer first - 18
A security manager is reviewing the quarterly risk report. The KRI 'percentage of third-party vendors with an active, non-expired security assessment' has decreased from 90% to 70%. The threshold for this KRI is 80%. What is the most appropriate action for the security manager to take?
Select an answer first - 19
In security metrics, what is the role of a threshold?
Select an answer first - 20
What is the key difference between a Key Performance Indicator (KPI) and a Key Risk Indicator (KRI)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.