A raw count of firewall blocks measures an output or result , not whether the security capability itself is performing effectively. Under the terminology used by the supplied course material, this makes the measurement a Key Result Indicator rather than a Key Performance Indicator .
For example, a perimeter firewall could block ten million connection attempts because the public-facing address space is being heavily scanned. A second firewall might block only one million. Those numbers alone do not establish that the first firewall is ten times more effective. External scanning volume, Internet exposure, business architecture, and traffic characteristics can change the count independently of firewall performance.
A useful KPI should instead measure performance against a defined operational objective—for example, response latency, policy deployment accuracy, control availability, processing performance, or another measurable objective tied to effectiveness. The total-block count can still provide useful operational context, but it should not automatically be interpreted as evidence that the firewall program is improving.
Option D captures precisely this distinction between activity/result volume and control performance .
Study Guide topics: security metrics, KPIs, result indicators, control effectiveness, SOC reporting, meaningful measurement.