Courseiva
hardMultiple Select

CS0-003 Practice Question: A security analyst has identified a critical…

A security analyst has identified a critical vulnerability that affects multiple systems. The analyst needs to report the vulnerability to management. Which THREE elements should be included in the vulnerability report? (Choose three.)

⚠ Common exam trap

CompTIA often tests the distinction between management-level reporting and technical operational details, causing candidates to mistakenly include granular patch dates (Option B) instead of focusing on the elements that drive decision-making.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Number of affected systems and their criticality

A vulnerability report must convey the scope and business impact of the issue. Including the number of affected systems and their criticality (e.g., system classification, data sensitivity, or role in the network) allows management to prioritize remediation based on risk exposure. Without this context, management cannot assess the urgency or allocate resources effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Number of affected systems and their criticality

    Why this is correct

    Reporting how many systems are affected and how business-critical they are gives management the scope needed to weigh urgency, because a critical flaw on 50 domain controllers demands immediate emergency change approval, while the identical CVE on a handful of low-value test machines can reasonably wait for the next scheduled maintenance window.

  • ✗

    Specific patch installation dates for each system

    Why it's wrong here

    Listing the exact patch installation date for every individual system produces operational-level minutiae that belongs in a change management ticket or patch tracking system, not a management report; executives need a summarized remediation timeline and status, not a per-asset audit log that obscures the bigger risk picture they must act on.

  • ✗

    Organizational risk appetite

    Why it's wrong here

    Organizational risk appetite is a pre-existing policy input that management itself defines and applies when deciding how to respond to the report, not a data point the analyst generates or includes within the vulnerability report; conflating the two roles would have the analyst dictating a governance decision that belongs to leadership.

  • ✓

    Recommended remediation steps and timeline

    Why this is correct

    Recommended remediation steps paired with a realistic timeline transform the report from a passive severity notice into an actionable plan management can approve, resource, and hold the team accountable to, which is essential because a report that only states a problem exists without proposing next steps forces management to guess at the appropriate response.

  • ✓

    CVSS score and vector string

    Why this is correct

    The CVSS score and its vector string give management a standardized, industry-recognized severity rating and the specific exploitability conditions behind it, such as whether the attack requires network access, authentication, or user interaction, allowing consistent prioritization against other vulnerabilities in the queue rather than relying on subjective severity descriptions.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.