hardMultiple Select
CS0-003 Practice Question: A security analyst has identified a critical…
A security analyst has identified a critical vulnerability that affects multiple systems. The analyst needs to report the vulnerability to management. Which THREE elements should be included in the vulnerability report? (Choose three.)
⚠ Common exam trap
CompTIA often tests the distinction between management-level reporting and technical operational details, causing candidates to mistakenly include granular patch dates (Option B) instead of focusing on the elements that drive decision-making.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Number of affected systems and their criticality
A vulnerability report must convey the scope and business impact of the issue. Including the number of affected systems and their criticality (e.g., system classification, data sensitivity, or role in the network) allows management to prioritize remediation based on risk exposure. Without this context, management cannot assess the urgency or allocate resources effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Number of affected systems and their criticality
Why this is correct
Reporting how many systems are affected and how business-critical they are gives management the scope needed to weigh urgency, because a critical flaw on 50 domain controllers demands immediate emergency change approval, while the identical CVE on a handful of low-value test machines can reasonably wait for the next scheduled maintenance window.
- ✗
Specific patch installation dates for each system
Why it's wrong here
Listing the exact patch installation date for every individual system produces operational-level minutiae that belongs in a change management ticket or patch tracking system, not a management report; executives need a summarized remediation timeline and status, not a per-asset audit log that obscures the bigger risk picture they must act on.
- ✗
Organizational risk appetite
Why it's wrong here
Organizational risk appetite is a pre-existing policy input that management itself defines and applies when deciding how to respond to the report, not a data point the analyst generates or includes within the vulnerability report; conflating the two roles would have the analyst dictating a governance decision that belongs to leadership.
- ✓
Recommended remediation steps and timeline
Why this is correct
Recommended remediation steps paired with a realistic timeline transform the report from a passive severity notice into an actionable plan management can approve, resource, and hold the team accountable to, which is essential because a report that only states a problem exists without proposing next steps forces management to guess at the appropriate response.
- ✓
CVSS score and vector string
Why this is correct
The CVSS score and its vector string give management a standardized, industry-recognized severity rating and the specific exploitability conditions behind it, such as whether the attack requires network access, authentication, or user interaction, allowing consistent prioritization against other vulnerabilities in the queue rather than relying on subjective severity descriptions.
Go deeper
Related to this question
Learn chapter
Risk Register and Vulnerability Register
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.