Courseiva
easyMultiple ChoiceObjective-mapped

CS0-003 Practice Question: A security analyst has identified a critical…

A security analyst has identified a critical vulnerability in a customer-facing web application. The analyst needs to communicate this to senior management. Which of the following is the best approach for this communication?

⚠ Common exam trap

CompTIA often tests the distinction between technical reporting (for engineers) and business-risk communication (for management), trapping candidates who overemphasize technical detail or assume management needs exploit-level information.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Summarize the vulnerability in terms of business risk, potential financial impact, and recommended mitigation timeline.

Communicating a critical vulnerability to senior management requires translating technical risk into business impact. Security analysts must present findings in terms of potential financial loss, regulatory consequences, and a clear mitigation timeline, enabling informed decision-making without requiring deep technical expertise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send a brief email stating that a critical vulnerability exists and ask management to schedule a meeting.

    Why it's wrong here

    Sending a brief, vague email to management about a critical vulnerability without specific details is insufficient for effective decision-making. Management requires actionable intelligence, including the vulnerability's severity, scope, potential business impact, and urgency, to properly assess the risk and prepare for a productive discussion. This approach delays the necessary understanding and resource allocation required to address the issue promptly.

  • Notify the development team only and have them fix it before informing management.

    Why it's wrong here

    Notifying only the development team to fix a critical vulnerability before informing management constitutes a serious violation of established incident response and vulnerability management policies. Executive leadership must be immediately apprised of significant risks that could impact organizational assets, reputation, or compliance posture, regardless of ongoing remediation efforts. This ensures proper oversight, strategic decision-making, and transparent communication with all relevant stakeholders.

  • Provide a detailed technical analysis of the vulnerability, including exploit code.

    Why it's wrong here

    Presenting a detailed technical analysis, including raw exploit code, to management is generally counterproductive and can cause confusion. While such technical depth is essential for security engineers and developers, management primarily needs to understand the business implications, not the intricate technical mechanics of the vulnerability. Overwhelming them with highly technical jargon obscures the actual risk and hinders their ability to make timely, informed strategic decisions.

  • Summarize the vulnerability in terms of business risk, potential financial impact, and recommended mitigation timeline.

    Why this is correct

    Summarizing the vulnerability in terms of its business risk, potential financial impact, and a recommended mitigation timeline is the most effective communication strategy for management. This approach translates complex technical issues into terms that resonate with their strategic priorities, such as potential revenue loss, regulatory fines, or reputational damage. Providing a clear action plan and timeline empowers them to understand the urgency, allocate necessary resources, and make informed decisions regarding risk acceptance or mitigation.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.