350-201 Question 34
Select 3During a post-incident review, the cybersecurity team evaluates their incident response metrics to identify areas of improvement. Which metrics should they focus on to measure the efficiency and effectiveness of their incident response process?
- A
Mean Time to Detect (MTTD)
- B
Mean Time to Respond (MTTR)
- C
Number of incidents escalated to external partners
- D
Percentage of false positives in threat alerts
- E
Uptime of critical systems during the incident
- F
Cost per incident resolved
Show answer and explanation
Correct answers: A, B, D
Explanation
The most relevant metrics for evaluating and improving the efficiency and effectiveness of the incident response process are Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), and the percentage of false positives in threat alerts. These metrics highlight the team's ability to detect and respond to threats quickly and accurately, minimizing resource wastage and improving operational response capabilities.
- A. Correct.
Mean Time to Detect (MTTD) is a critical metric that measures how quickly threats are identified. A shorter MTTD indicates better detection capabilities, making this a key area for improvement.
- B. Correct.
Mean Time to Respond (MTTR) measures how quickly the team can mitigate and remediate threats after detection. Reducing MTTR is crucial for minimizing damage and restoring normal operations efficiently.
- C. Incorrect.
While the number of incidents escalated to external partners could provide some insight into resource utilization, it is not a direct measure of incident response efficiency or effectiveness.
- D. Correct.
The percentage of false positives in threat alerts directly impacts the efficiency of the incident response process. High false positives can waste resources and delay response to real threats.
- E. Incorrect.
Uptime of critical systems during an incident is more of an operational metric and does not directly measure the incident response process's efficiency or effectiveness.
- F. Incorrect.
Cost per incident resolved is more of a business efficiency metric and does not specifically measure the technical or procedural aspects of incident response.