Metrics question
You are the PM for privacy and security at Facebook. What goal would you set and how would you measure success?
- Meta
- Metrics
- Hard
Practice this question out loud. An AI interviewer asks it, follows up like a real interviewer would, and scores your answer. Type or speak.
Start a mock interview on this question · Mock interview from a job description
What this question tests
Ability to set goals and metrics for a trust-and-safety function where success is partly about preventing bad outcomes, a harder measurement problem.
How to approach it
- Clarify the mandate: protect user data and account security while minimizing friction for legitimate users, a genuine tension to state upfront.
- Set the goal: minimize successful account compromise and data misuse incidents while keeping login and sharing friction low.
- Define security metrics: account takeover rate, time to detect and remediate a breach, and share of accounts with strong authentication enabled.
- Define privacy metrics: share of users using privacy controls and data requests handled on time, plus privacy complaint volume.
- Add a guardrail: login success rate and support tickets from legitimate users locked out, since overly strict security hurts real usage.
- Report a security incident trend line alongside a proactive metric like suspicious logins blocked.
What a strong answer includes
- Explicitly names the core tension, security versus friction, upfront rather than treating them as unrelated goals.
- Distinguishes privacy from security as genuinely different goal areas.
- Proposes a guardrail against over-restriction, a nuance many candidates miss.
- Combines a lagging metric with a leading metric for a fuller picture.
Common mistakes
- Setting goals that only minimize risk without any guardrail for legitimate user friction.
- Conflating privacy and security into one vague goal.
- Proposing metrics that only look backward at incidents with no proactive leading indicator.
Likely follow-up questions
- How would you measure privacy specifically, separate from security?
- How would you balance stronger security requirements against user drop-off from added friction?
- How would you report this to leadership in a way that reflects both prevention and usability?
More metrics questions
- How would you measure the success of Facebook Likes?Meta · Metrics · Medium
- How would you measure improvements made to Facebook messenger?Meta · Metrics · Easy
- Imagine you are the PM in charge of Reactions on Facebook - the new way to interact with posts by using “love”, “haha”, “wow”, “sad”, and “angry” reactions. What would success look like in terms of number of non-like reactions per post at launch and how do you come up with this? Would this number differ by reaction? Why or why not?Meta · Metrics · Hard
- You launched a new signup flow to encourage new users to add more profile information. A/B test results indicate that the % of people that added more information increased by 8%. However, 7 day retention decreased by 2%. What do you do?Google · Metrics · Hard
- Define the metrics for YouTube search.Google · Metrics · Medium
- You are the PM of Instagram app. The MAU has been constant but DAU has declined. What will you do?Meta · Metrics · Medium
More questions from Meta
Learn the skill behind it
Chapters of the AI PM course that teach what this question tests.
- Chapter 9: Prove it paid off: outcomes, economics, and pricing
- Chapter 2: Data fluency: SQL, logs, and reading the truth yourself
- Chapter 14: Get the job: the AI PM interview loop