ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your organization reports application-security metrics every quarter. Leadership wants a single KPI that shows whether the program is actually reducing exposure to high-severity vulnerabilities across several agile teams, without being distorted by how much code is written or how many scans are run in a given release. Which metric is the most appropriate choice?
Percentage of critical vulnerabilities remediated within the agreed service-level target
Average engineering hours spent fixing medium-severity defects per sprint
Total lines of source code scanned for security defects each quarter
Number of user stories that include explicit security acceptance criteria
Measuring the percentage of critical vulnerabilities that are closed within the organization's agreed service-level target focuses on the highest-risk issues and expresses performance as a proportion, making it less sensitive to raw scan counts or code volume than absolute numbers. While teams still need to interpret results in light of release complexity or vulnerability discovery rates, this KPI more directly reflects risk reduction than activity measures such as lines of code scanned, the count of user stories with security criteria, or the engineering hours spent on medium-severity fixes.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is the percentage of critical vulnerabilities remediated the most appropriate KPI for leadership metrics?
Open an interactive chat with Bash
What is a service-level target in the context of vulnerability remediation?
Open an interactive chat with Bash
Why are activity measures like lines of code scanned or user stories less suitable as KPIs for reducing exposure?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Lifecycle Management
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .