The correct answer is A because SLOs — service-level objectives are measurable targets used to evaluate whether a service or process is meeting expected performance levels. When incident response is outsourced to a third party, SLOs help the organization measure whether the provider is meeting key performance expectations, such as detection time, response time, remediation time, and reporting quality.
Exact supporting extract: the Secbay CySA+ guide defines SLOs as specific, measurable targets set for the performance and reliability of a service or process. It also states that SLOs provide a framework for defining and measuring effectiveness, and that reporting on SLOs allows stakeholders to assess performance and make informed decisions.
The same guide explains that SLOs depict explicit measurements and may be set by a company or defined as part of a service-level agreement with a service provider. It also states that estimating whether SLOs are being met is a typical component of SLA management.
The official CySA+ objectives include SLOs under metrics and KPIs for reporting and communication.
Why the other options are incorrect:
B is incorrect because SLOs are performance targets, not a method for identifying hidden costs.
C is incorrect because SLOs may support risk management, but they do not directly calculate an objective risk score.
D is incorrect because risk appetite is a governance/risk-management concept, not the purpose of SLOs.
A is correct because SLOs allow the organization to measure third-party IR performance against defined KPIs.
Submit