ExamGecko
Home / Isaca / CISA / Practice Test 8
Ask Question

Isaca CISA Practice Test 8

00:00:00
Show Answer
Report Issue   Restart test

Question 1 / 40

Which of the following is the BEST indicator of the effectiveness of an organization's incident response program?

Number of successful penetration tests
Number of successful penetration tests
Percentage of protected business applications
Percentage of protected business applications
Financial impact per security event
Financial impact per security event
Number of security vulnerability patches
Number of security vulnerability patches
Comment (0)
Suggested answer: C
Explanation:

The best indicator of the effectiveness of an organization's incident response program is the financial impact per security event. This metric measures the direct and indirect costs associated with security incidents, such as loss of revenue, reputation damage, legal fees, recovery expenses, and fines. By reducing the financial impact per security event, the organization can demonstrate that its incident response program is effective in mitigating the consequences of security breaches and restoring normal operations as quickly as possible. Number of successful penetration tests, percentage of protected business applications, and number of security vulnerability patches are indicators of the security posture of the organization, but they do not reflect the effectiveness of the incident response program.Reference:ISACA Journal Article: Measuring Incident Response Effectiveness

asked 18/09/2024
Tuan Nguyen
48 questions