CS0-003 Reporting and Communication Practice Question
A cybersecurity analyst is preparing a report for the executive leadership team. Which type of report is most appropriate for communicating high-level security posture and risk to non-technical stakeholders?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Executive dashboard
Executive dashboards provide a high-level overview of security posture, using metrics and visualizations that are easily understood by non-technical stakeholders. Technical reports are too detailed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat intelligence feed
Why it's wrong here
Threat intelligence feeds provide raw, real-time streams of indicators of compromise (IoCs) and threat data, such as malicious IP addresses or file hashes. Because they lack contextual analysis and high-level aggregation, they are designed for automated ingestion by security tools like SIEMs rather than consumption by executive leadership.
- ✗
Technical vulnerability report
Why it's wrong here
A technical vulnerability report contains granular, low-level details of specific system weaknesses, including CVE identifiers, affected registry keys, and CVSS scores. While invaluable for system administrators and remediation teams, this level of technical minutiae overwhelms executive stakeholders who require a strategic overview of organizational risk.
- ✓
Executive dashboard
Why this is correct
An executive dashboard aggregates complex security data into high-level key performance indicators (KPIs) and risk metrics, such as overall compliance posture and mean time to detect (MTTD). This visual format allows non-technical leadership to quickly grasp the organization's current security posture and make informed resource allocation decisions.
- ✗
Incident response playbook
Why it's wrong here
Incident response playbooks are highly structured, step-by-step operational guides used by the Security Operations Center (SOC) to contain and mitigate specific security incidents. They are designed for tactical execution during an active breach rather than presenting retrospective or strategic security metrics to corporate stakeholders.
Go deeper
Related to this question
Learn chapter
Infrastructure-as-Code Security Scanning
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.