exam questions

Exam CRISC All Questions

View all questions & answers for the CRISC exam

Exam CRISC topic 1 question 815 discussion

Actual exam question from Isaca's CRISC
Question #: 815
Topic #: 1
[All CRISC Questions]

The BEST key performance indicator (KPI) to measure the effectiveness of a vulnerability remediation program is the number of:

  • A. new vulnerabilities identified.
  • B. recurring vulnerabilities.
  • C. vulnerabilities remediated.
  • D. vulnerability scans.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Staanlee
10 months, 2 weeks ago
Selected Answer: C
C. vulnerabilities remediated. The best key performance indicator (KPI) to measure the effectiveness of a vulnerability remediation program is the number of vulnerabilities remediated. This KPI directly reflects the program's ability to address and mitigate security vulnerabilities in a timely manner. It demonstrates that identified vulnerabilities are being addressed and closed, reducing the organization's overall exposure to potential security risks. Tracking the number of vulnerabilities remediated over time allows for the monitoring of program effectiveness and helps ensure that security risks are being actively managed.
upvoted 1 times
...
CbtL
1 year, 3 months ago
Selected Answer: C
Going with C. Recurring seems more like a KRI to me.
upvoted 1 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: C
i have to change to 'C', reason: This indicates the actual progress made in addressing identified vulnerabilities, while the number of recurring vulnerabilities could indicate that the remediation efforts are not effective or not being applied consistently.
upvoted 2 times
...
john_boogieman
1 year, 5 months ago
Selected Answer: B
Agree.
upvoted 1 times
...
Ceecil1959
2 years, 3 months ago
B: is correct. Recurring vulnerabilities are those that have come up again after remediation. That is known as the Vulnerability Re-Open Rate.
upvoted 2 times
...
AllaAlla
2 years, 5 months ago
Selected Answer: B
b is more sence
upvoted 2 times
...
Raj1510
2 years, 6 months ago
B make most sense for effective vulnerability remediation program. Recurring vulnerability normally refer to same vulnerability found in system on next scan after remediation done or reported done. This will indicate the solution / remediation is not working or not done properly which warrant the effectiveness of remediation process. so B make more sense to me.
upvoted 4 times
...
MusMus
2 years, 6 months ago
Selected Answer: C
C makes most sense, recurring vulnerabilities could be on other hosts.
upvoted 2 times
...
Josh93
3 years, 3 months ago
I think C is the better answer for KPI
upvoted 4 times
...
hussmohsin
3 years, 5 months ago
B. recurring vulnerabilities shows a risk so its KRI not KPI. I don't know what is the best answer here but B is wrong.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...