Triage BoardGet the app

Concept · Incident communication

MTTD vs MTTR vs MTTC

Mean time to detect (MTTD) measures how long malicious activity goes unnoticed. Mean time to respond measures how quickly the team acts once an alert fires, mean time to remediate how long until the cause is fixed, and in the CS0-004 objectives MTTC stands for mean time to close. CS0-004 lists all four among the key performance indicators (KPIs) of objective 4.2 in its exam objectives, and the questions check which clock each one starts and stops.

  • Exam code CS0-004
  • Tickets here 8

One incident, six timestamps

ticketFictional ticket INC-5120: every metric on this page is a gap between two of these lines
2026-04-14 02:47  event       first malicious VPN sign-in from 203.0.113.182026-04-14 06:05  alert       SIEM rule fires: impossible travel + new MFA device2026-04-14 06:21  responded   analyst acknowledges, opens case2026-04-14 07:02  contained   account disabled, sessions revoked2026-04-15 16:40  remediated  MFA re-enrollment enforced, VPN policy fixed2026-04-16 10:15  closed      after-action notes filed, ticket closed

Event to alert: 3 h 18 min, the detect gap. Alert to acknowledgment: 16 min. Alert to containment: 57 min. Alert to remediation: 34 h 35 min. Alert to closure: 52 h 10 min. Average each gap across a month of tickets and you have the KPIs.

Which clock each metric runs

Typical start and stop points; an exhibit's own definitions override these
MetricStartsStopsShortened by
MTTD (detect)Malicious activity beginsAlert or detectionLog coverage, detection rules, tuning
MTTR (respond)AlertFirst response actionStaffing, triage, alert quality
MTTR (remediate)Alert or ticket openedCause fixed and verifiedPatch process, automation, approvals
MTTC (close)Alert or ticket openedTicket closedDocumentation and handover discipline

Why the acronyms cause trouble

Computing a mean

Each KPI is a sum of gaps divided by the number of incidents. Three incidents in a month with detect gaps of 3 h 18 min, 40 min and 9 h 2 min add up to 13 hours, so MTTD for the month is about 4 h 20 min. The event time is often only established later, during analysis, so a month's MTTD can grow after the report is written when investigators push an intrusion's start date back.

Three readings of MTTR, two of MTTC

MTTR is the worst offender. CS0-004 lists mean time to respond and mean time to remediate as separate KPIs, and on a real incident they can differ by days, as INC-5120 shows. The CS0-003 objectives expanded MTTR in their acronym list as mean time to repair, a third reading. Spell the metric out before you calculate anything.

MTTC is new in CS0-004, and the objectives expand it as mean time to close. Vendor dashboards and some practice items use the same letters for mean time to contain, which is a different gap: 57 minutes on INC-5120, against more than two days to closure. Use whatever definition the stem or exhibit gives. If it gives none, read MTTC as close. Containment itself is covered under containment, eradication and recovery.

Averages can also move for reasons unrelated to performance. A team that closes false positives in two minutes and real incidents in two days will report a falling MTTC if it simply receives more noise. Automation that auto-closes duplicate alerts has the same effect, which is worth remembering when automation and process improvement claims a better number. Metrics like these feed the KPI section of incident reporting and communication, and an executive summary should quote the one that answers the reader's question.

MTTR with nothing after itTrap

When an option or exhibit says MTTR, settle whether it means respond or remediate before you compare or compute. The two share letters and can differ by days: on INC-5120 the respond gap is 16 minutes, the remediate gap more than 34 hours.

Reading the clocks

Keep scratch paper handy: timestamps, definitions and averages ahead.

Ticket 1 / 8

0 right

INC-001

Which metric is MOST useful for measuring the effectiveness of an organization's incident response capability?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Mean time to contain shows how fast the team stops an incident from causing more damage, which directly reflects response effectiveness. Mind the acronym: the CS0-004 objectives (4.2) expand MTTC as mean time to close, so read a bare MTTC that way.
  2. BBudget is an input; spending more does not prove the team responds well.
  3. CTeam size is an input too; a large team can still respond slowly.
  4. DCounting tools measures purchases, not how well incidents are handled.

INC-002

Which metric BEST measures an organization's ability to detect security incidents quickly?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: Mean time to detect is the average time between an incident starting and the team discovering it, so it directly measures detection speed.
  2. BHeadcount is a resource measure and says nothing about how fast incidents are found.
  3. COwning more tools does not mean incidents are detected faster.
  4. DIncidents per month measures volume, not how quickly each one is detected.

INC-003

A security manager reviews a quarterly report showing a significant reduction in the Mean Time to Detect (MTTD). The manager concludes that the team is now containing and eradicating threats much faster. What is the fundamental flaw in this conclusion?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AMTTD does not measure analyst workload, and the manager's error is about containment speed anyway.
  2. BCorrect: MTTD measures only how quickly threats are spotted; containment and eradication speed are tracked separately by mean time to contain and mean time to respond or remediate.
  3. CFaster detection does not affect the false-positive rate, but that is not the manager's claim either.
  4. DTotal alert volume is useful context, but the real flaw is treating a detection metric as a response metric.

INC-004

A SOC dashboard shows "Time to Containment" dropping during night shifts. An audit reveals night analysts mark incidents contained upon isolation, while day analysts await process termination. How should the manager resolve this?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AAutomatic process termination changes the response itself; it does not fix the inconsistent definitions that distort the metric.
  2. BCorrect: The metric is inconsistent because shifts define 'contained' differently, so the manager should set and publish one standard definition for containment and remediation timestamps.
  3. CUsing only day-shift data hides part of the operation and does not fix the definition problem.
  4. DWaiting for full recovery merges containment with recovery, which makes the containment metric meaningless.

INC-005

Analyze the incident metrics table below. Based on the calculated Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR), which process improvement should the security team prioritize?

Exhibit

Incident IDT0 (Compromise)T_AlertT_TriageT_Resolve
INC-0108:0008:1508:2012:00
INC-0209:0009:1009:1514:00
INC-0310:0010:1210:2016:00
INC-0411:0011:0511:1015:00

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AAlerts already arrive about 10.5 minutes after compromise on average, so faster detection rules would gain little.
  2. BBetter detection signatures also address detection, which is not the bottleneck.
  3. CCorrect: Triage is done within minutes, but resolution takes about 3.7 to 5.7 hours (about 4.5 hours on average), so automating containment and eradication targets the real bottleneck.
  4. DAnalysts acknowledge and triage alerts within about 5 to 8 minutes, so acknowledgment speed is not the problem.

INC-006

Based on the dashboard annotations, what is the total average time elapsed from the initial event occurring until the affected system is fully restored to normal operations?

Exhibit

KPI NameValueDefinition
MTTD12 minsTime from initial event occurrence to analyst acknowledgment
MTTC45 minsTime from acknowledgment to complete network isolation
MTTR72 hoursTime from network isolation to full system restoration

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. A72 hours 45 minutes adds MTTC to MTTR but forgets the 12 minutes of MTTD at the start.
  2. BCorrect: under these definitions the phases run back to back, so the total is 12 minutes + 45 minutes + 72 hours = 72 hours 57 minutes.
  3. C71 hours 03 minutes subtracts the 57 minutes instead of adding them.
  4. D73 hours 09 minutes adds too much; the phases sum to 57 minutes plus 72 hours.

INC-007

Using the incident timestamps provided, what is the Mean Time to Remediate (MTTR) for this period, defined as the average duration from Alert Generated to Ticket Closed?

Exhibit

Incident IDAlert GeneratedTicket Closed
INC-8108:0009:10
INC-8209:0011:15
INC-8310:0011:20

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. A100 minutes does not match the data; the three durations add up to 285 minutes, which averages 95.
  2. B115 minutes would require a larger total than the 285 minutes in the table.
  3. C135 minutes is only INC-82's duration, the longest single incident, so it cannot be the average.
  4. DCorrect: The durations are 70, 135, and 80 minutes, for a total of 285; divided by 3 incidents, that is 95 minutes.

INC-008

KPI averages appear acceptable yet long-tail incidents persist. Which supplemental metrics must be added?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ATotal alert volume and open ticket counts measure workload and say nothing about how long the slowest incidents take.
  2. BCorrect: The median and 90th percentile, plus distribution charts, show the long-tail incidents that an average hides.
  3. CThe percentage closed on time is useful, but it does not show how far the outliers stretch.
  4. DMonthly averages alone are the problem described, because averages hide long-tail incidents.

Shift tally

0 / 0

Before you close this tab

  • MTTD runs from the start of malicious activity to detection; it measures visibility.
  • Mean time to respond and mean time to remediate share an acronym. Spell them out.
  • In the CS0-004 objectives MTTC is mean time to close; follow the stem if it defines it differently.
  • A mean can improve because the mix of tickets changed, with no team getting faster.

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.