CS0-003 Reporting and Communication Practice Question
A cybersecurity analyst is preparing a vulnerability report for the IT manager. Which section should summarize the most critical risks for the organization?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Executive summary
The executive summary provides a high-level overview of the most critical risks and recommended actions for management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remediation timeline
Why it's wrong here
This section defines the specific schedule, milestones, and deadlines for patching or mitigating identified vulnerabilities based on SLA requirements. While it is crucial for tracking operational progress, it does not synthesize or summarize the overall critical risk posture of the organization for high-level stakeholders.
- ✗
Risk acceptance
Why it's wrong here
This section formally documents the organization's conscious decision to tolerate specific vulnerabilities without immediate mitigation, typically due to high remediation costs or low business impact. It serves as a compliance and governance record rather than a high-level synthesis of the most critical threats discovered during the assessment.
- ✗
Findings by severity
Why it's wrong here
This technical section categorizes every discovered vulnerability into tiers like critical, high, medium, or low to help security teams prioritize their patching efforts. However, this granular breakdown is too detailed and operationally focused to serve as a concise, high-level overview tailored for non-technical decision-makers.
- ✓
Executive summary
Why this is correct
This section is designed specifically for leadership and non-technical stakeholders, distilling complex technical findings into a high-level overview of critical risks, business impacts, and strategic recommendations. It provides the necessary context for resource allocation and risk management decisions without overwhelming the reader with granular vulnerability data.
Go deeper
Related to this question
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.