Courseiva
easyMultiple Select

CAS-004 Practice Question: A risk assessment report is being prepared for…

A risk assessment report is being prepared for senior management. Which TWO of the following should be included to effectively communicate risk?

⚠ Common exam trap

In risk assessment reports for senior management, it is important to include summary-level strategic information such as the risk register with scores and an executive summary, rather than overly detailed operational items like remediation deadlines or employee names.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk register with scores

Option B (Risk register with scores) is correct because a risk register provides senior management with a structured, prioritized view of identified risks, their likelihood and impact scores, and current status, which is essential for informed decision-making at an executive level. Option C (Executive summary) is correct because senior management needs a concise, high-level overview of the most significant risks, key findings, and recommended actions, enabling them to grasp the risk posture quickly without wading through technical detail. Option A (Remediation deadlines) is not appropriate as a primary communication element for senior management, since deadlines are operational details better suited to tactical plans or project schedules rather than strategic risk communication. Option D (Names of employees responsible) is not included because attributing risk ownership to specific individuals is a management/accountability detail that does not effectively convey the nature or severity of risk to executives. Option E (Detailed control configurations) is not included because granular technical settings are far too low-level for senior management and belong in technical documentation or audit workpapers, not executive risk reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remediation deadlines

    Why it's wrong here

    Deadlines describe planned treatment activity, not the risk itself, so management cannot judge likelihood or impact from them. They belong in remediation tracking once risks are accepted. A risk report needs the risk statement, affected assets and inherent or residual ratings to prioritise decisions.

  • ✓

    Risk register with scores

    Why this is correct

    A risk register with scores presents each identified risk alongside its likelihood and impact rating, giving senior management a prioritised, comparable view. This satisfies the requirement to communicate risk effectively, supporting informed decisions on acceptance, mitigation and resource allocation.

  • ✓

    Executive summary

    Why this is correct

    Senior management needs a concise overview of key risks, impacts and recommended actions without technical detail. An executive summary satisfies the report's communication constraint by translating findings into business language, enabling informed decision-making and resource allocation at board level.

  • ✗

    Names of employees responsible

    Why it's wrong here

    Naming responsible employees personalises the report and exposes individuals to blame rather than conveying likelihood, impact, velocity and treatment options. Risk reporting to senior management needs quantified exposure, prioritisation and ownership by role or function. Employee names would be appropriate in an operational remediation tracker or audit finding log, not an executive risk summary.

  • ✗

    Detailed control configurations

    Why it's wrong here

    Detailed control configurations are implementation-level artefacts; senior management needs risk expressed in business impact, likelihood and treatment terms. Control configurations belong in technical remediation plans or audit working papers, not an executive risk summary, which should present prioritised risks and recommended responses.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.