Courseiva
Reporting and CommunicationhardMultiple ChoiceObjective-mapped

CS0-003 Reporting and Communication Practice Question

A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Describe the potential financial loss, reputational damage, and regulatory fines

Translating technical risk to business impact (financial, reputational, regulatory) is key for non-technical stakeholders.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Provide a list of all current vulnerabilities

    Why it's wrong here

    A raw vulnerabilities list lacks the prioritization and context needed for executive decision-making, overwhelming the board with details that do not indicate which threats pose the most urgent business risk. Without filtering by exploitability, asset criticality, or potential impact, the analysis hides the most dangerous exposures behind low-severity noise. This approach fails because effective risk communication requires presenting a focused set of risks tied to business harm, not a comprehensive enumeration of every technical issue.

  • Present the CVSS score and affected systems

    Why it's wrong here

    A CVSS score and affected systems list is a technical snapshot that measures severity in isolation, ignoring how organizational controls, threat actor activity, or business process dependency influence actual risk. Board members cannot interpret a raw 9.1 score as a dollar amount, legal exposure, or operational impact, so it leaves them without a rational basis for prioritizing investments or accepting risk. This still lives firmly in the technician's view, failing to translate the vulnerability into the financial, regulatory, or reputational terms that belong in board-level risk reporting.

  • Describe the potential financial loss, reputational damage, and regulatory fines

    Why this is correct

    Describing potential financial loss, reputational damage, and regulatory fines directly maps the risk onto the board's fiduciary duties, giving them the essential information needed for risk tolerance and resource allocation. This approach quantifies or estimates impact in the same units executives use to evaluate business decisions, such as ERM frameworks and insurance. It lets the CISO argue for security investment as a business trade-off, which is the only frame that produces meaningful discussion and sign-off.

  • Explain the technical details of the exploit chain

    Why it's wrong here

    Walking through an exploit chain—such as command injection, privilege escalation, or lateral movement—explains how an attack unfolds but not why the board should care, since it focuses on mechanics rather than consequence. It is written for security operations staff who need to reproduce, detect, or patch the flaw; the board has no action on that level. This briefing would bury the headline business exposure under technical forensics, leading to confusion or risk acceptance due to inability to weigh the impact.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.