Study. uk . com
  1. Home
  2. All questions
  3. Question 175

CompTIA Security+ study material · question 175 of 611

A patching programme reports the number of patches installed each month. Why is this a weak enterprise-level metric?

  1. It cannot be gathered automatically
  2. It excludes firmware updates by definition
  3. It measures activity rather than how quickly the organisation responds to risk
  4. It duplicates the CVSS environmental score
Show the answer

Answer: C. It measures activity rather than how quickly the organisation responds to risk

Actionable metrics describe responsiveness, so a busy month of low-risk patches does not look like success.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 3.6 Choose Actionable Enterprise-Level Patching Metrics

Challenge yourself on this topic → Study as cards