easyMultiple ChoiceObjective-mapped
CS0-003 Practice Question: A security analyst has identified a critical…
A security analyst has identified a critical vulnerability in a customer-facing web application. The analyst needs to communicate this to senior management. Which of the following is the best approach for this communication?
⚠ Common exam trap
CompTIA often tests the distinction between technical reporting (for engineers) and business-risk communication (for management), trapping candidates who overemphasize technical detail or assume management needs exploit-level information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Summarize the vulnerability in terms of business risk, potential financial impact, and recommended mitigation timeline.
Communicating a critical vulnerability to senior management requires translating technical risk into business impact. Security analysts must present findings in terms of potential financial loss, regulatory consequences, and a clear mitigation timeline, enabling informed decision-making without requiring deep technical expertise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send a brief email stating that a critical vulnerability exists and ask management to schedule a meeting.
Why it's wrong here
Sending a brief, vague email to management about a critical vulnerability without specific details is insufficient for effective decision-making. Management requires actionable intelligence, including the vulnerability's severity, scope, potential business impact, and urgency, to properly assess the risk and prepare for a productive discussion. This approach delays the necessary understanding and resource allocation required to address the issue promptly.
- ✗
Notify the development team only and have them fix it before informing management.
Why it's wrong here
Notifying only the development team to fix a critical vulnerability before informing management constitutes a serious violation of established incident response and vulnerability management policies. Executive leadership must be immediately apprised of significant risks that could impact organizational assets, reputation, or compliance posture, regardless of ongoing remediation efforts. This ensures proper oversight, strategic decision-making, and transparent communication with all relevant stakeholders.
- ✗
Provide a detailed technical analysis of the vulnerability, including exploit code.
Why it's wrong here
Presenting a detailed technical analysis, including raw exploit code, to management is generally counterproductive and can cause confusion. While such technical depth is essential for security engineers and developers, management primarily needs to understand the business implications, not the intricate technical mechanics of the vulnerability. Overwhelming them with highly technical jargon obscures the actual risk and hinders their ability to make timely, informed strategic decisions.
- ✓
Summarize the vulnerability in terms of business risk, potential financial impact, and recommended mitigation timeline.
Why this is correct
Summarizing the vulnerability in terms of its business risk, potential financial impact, and a recommended mitigation timeline is the most effective communication strategy for management. This approach translates complex technical issues into terms that resonate with their strategic priorities, such as potential revenue loss, regulatory fines, or reputational damage. Providing a clear action plan and timeline empowers them to understand the urgency, allocate necessary resources, and make informed decisions regarding risk acceptance or mitigation.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.