Mean time to close is the most relevant measurement because the manager needs to quantify how long cases or incidents remain open before all required closure activities—including after-action documentation—are completed.
An incident may already be technically contained and remediated while administrative closure remains outstanding. Mean time to remediate measures how long it takes to correct or neutralize the security problem, but it does not necessarily include final reporting and formal case closure. Mean time to respond measures how quickly responders begin or perform response activity after detection. Mean time between failures is primarily a reliability metric describing the average operating duration between failures and does not measure SOC reporting performance.
Current Microsoft Sentinel SOC guidance explicitly includes mean time to closure and time-to-closure percentiles among incident-management metrics used to evaluate SOC performance. This directly maps to the manager's concern: if after-action reports delay completion of incidents, the organization's mean closure time will increase and can be trended by analyst, severity, team, or incident category.
Therefore, B provides the quantitative evidence needed to determine whether after-action reporting is preventing incidents from being closed promptly.
Study Guide Reference: Reporting and Communication → Incident Metrics → Mean Time to Close → After-Action Reporting → SOC Performance Measurement → Continuous Improvement.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit