hardMultiple Select
CS0-003 Practice Question: A remediation report shows repeated SLA breaches…
A remediation report shows repeated SLA breaches by one business unit. Which recommendations are appropriate? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that hiding or ignoring non-compliant data is an acceptable reporting strategy, when in fact the exam emphasizes transparency and root-cause analysis as the only valid path to remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review ownership, resourcing, and change-window constraints
Reviewing ownership, resourcing, and change-window constraints directly addresses the root causes of repeated SLA breaches. SLA breaches often stem from inadequate staffing, misaligned change windows, or unclear ownership of remediation tasks, not from technical failures alone. This recommendation aligns with the reporting and communication domain's emphasis on actionable, root-cause analysis rather than superficial fixes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automatically accept all future risk permanently
Why it's wrong here
Automatically accepting all future risks permanently bypasses formal risk management frameworks and violates governance standards. It leaves the organization vulnerable to unmitigated threats without ongoing executive oversight or periodic re-evaluation. Risk acceptance must be a deliberate, documented, and time-bound decision made by authorized stakeholders, not an automated default for failing SLAs.
- ✓
Review ownership, resourcing, and change-window constraints
Why this is correct
Persistent SLA breaches usually stem from underlying operational bottlenecks rather than simple negligence. Investigating who owns the system, whether the team has adequate staff and tools, and if restrictive maintenance windows prevent timely patching allows security analysts to identify and resolve the root causes of remediation delays.
- ✗
Hide the business unit from future reports
Why it's wrong here
Excluding a non-compliant business unit from remediation reports obscures critical vulnerabilities and severely undermines organizational accountability. This practice distorts the organization's overall risk posture, misleads executive leadership, and leaves unpatched systems exposed to exploitation without visibility or tracking.
- ✓
Create an agreed corrective action plan with dates
Why this is correct
Establishing a formal corrective action plan with defined milestones and deadlines transforms passive reporting into active risk reduction. This collaborative approach ensures the business unit commits to specific remediation targets while allowing security teams to track progress, hold stakeholders accountable, and systematically close security gaps.
Go deeper
Related to this question
Learn chapter
Executive Security Reporting
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
SLA
A Service Level Agreement (SLA) is a contract between a service provider and a customer that defines the level of service expected, including metrics like uptime, response time, and penalties for non-compliance.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.