โ† All CySA+ Test Flashcard Decks

CySA+ Performance Tracking and Feedback Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CySA+ Performance Tracking and Feedback flashcards as text
  1. A SOC manager wants to measure how quickly analysts contain threats after detection. Which KPI best captures this?

    Answer: Mean Time to Contain (MTTC)

    Mean Time to Contain (MTTC) measures the elapsed time from detection to the point where the threat is isolated and no longer spreading.

  2. Which metric best indicates the effectiveness of a security awareness training program over time?

    Answer: Phishing simulation click-through rate trend

    A declining phishing simulation click-through rate over successive campaigns directly measures behavior change resulting from awareness training.

  3. A CISO reviews a report showing 95% of critical vulnerabilities are patched within the SLA window. This is an example of a:

    Answer: Key Performance Indicator (KPI)

    A patch compliance rate measured against an SLA target is a classic Key Performance Indicator (KPI) for vulnerability management.

  4. After an incident, an analyst documents that the initial alert fired 4 hours before analysts began investigation. This gap represents which metric?

    Answer: Mean Time to Acknowledge (MTTA)

    Mean Time to Acknowledge (MTTA) measures the time between an alert firing and an analyst beginning active investigation.

  5. Which dashboard component best helps management understand cybersecurity posture trends across multiple quarters?

    Answer: Rolling trend line charts for key metrics

    Rolling trend line charts aggregate historical metric data to show directional improvements or degradations in security posture over time.

  6. An organization tracks 'number of repeat incidents involving the same root cause.' This metric is intended to measure:

    Answer: Effectiveness of remediation and lessons learned

    Repeat incidents with the same root cause indicate that prior remediation or lessons-learned processes failed to address underlying weaknesses.

  7. A security team sets a target that 100% of high-severity alerts must be triaged within 15 minutes. This target is best described as a:

    Answer: Service Level Agreement (SLA)

    An SLA defines a committed performance standard, here specifying the maximum acceptable triage time for high-severity alerts.