CS0-003 Reporting and Communication Practice Question
A financial services organization experienced a ransomware incident that encrypted several file servers. The CISO must deliver a post-incident report to the board of directors and the audit committee. The report must communicate both the business impact and the effectiveness of the response. Which of the following should be included in this executive-level report? (Choose two.)
⚠ Common exam trap
The trap here is assuming that more technical detail always makes a report more credible, when executive audiences actually need summarized business impact and response effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A timeline of key response actions and the measured effectiveness of containment, eradication, and recovery
Executive-level post-incident reports must translate technical events into business language. Quantifying financial loss and presenting a timeline with response effectiveness give the board the information they need to evaluate risk, resilience, and investment priorities. Technical artifacts like packet captures, hashes, and file lists belong in operational reports, not board communications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The complete raw packet capture from the initial compromise vector
Why it's wrong here
Raw packet captures are far too granular and technical for a board audience. Executives need summarized business impact and response effectiveness, not low-level forensic artifacts. Including raw captures would obscure the key message, overwhelm non-technical readers, and fail to support strategic decision-making. This level of detail belongs in the technical incident report for the security operations team.
- ✓
A timeline of key response actions and the measured effectiveness of containment, eradication, and recovery
Why this is correct
An executive report should demonstrate how well the organization responded and where improvements are needed. A concise timeline with effectiveness metrics for containment, eradication, and recovery shows whether controls worked and where gaps exist. This helps leadership assess resilience and prioritize investments. It is a standard component of post-incident reporting for senior stakeholders.
- ✓
A quantified estimate of financial loss, including downtime, recovery costs, and regulatory exposure
Why this is correct
Board members and audit committees need to understand impact in financial and business terms. Quantifying downtime, recovery costs, and potential regulatory penalties allows them to evaluate risk tolerance, insurance coverage, and future investment. This is a core element of executive-level incident reporting under the Reporting and Communication domain, translating technical events into business consequences.
- ✗
The full malware binary hash list and YARA rule syntax used during triage
Why it's wrong here
Hash lists and YARA rule syntax are technical detection artifacts, not executive reporting content. They do not help the board understand business impact, risk, or response effectiveness. Including them could confuse non-technical readers and dilute the strategic message. Such details are appropriate for the technical incident report or threat intelligence sharing, not for board-level communication.
- ✗
A detailed list of every file that was encrypted, including full directory paths
Why it's wrong here
Enumerating every encrypted file with full paths is excessive and not meaningful to executives. The board needs aggregate impact, such as number of affected systems or business functions, not a file-level inventory. This level of detail belongs in forensic documentation and would distract from the strategic narrative. Executive reports should summarize, not exhaustively list, technical artifacts.
Go deeper
Related to this question
Learn chapter
Executive Security Reporting
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.