CS0-003 Reporting and Communication Practice Question
A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Describe the potential financial loss, reputational damage, and regulatory fines
Translating technical risk to business impact (financial, reputational, regulatory) is key for non-technical stakeholders.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provide a list of all current vulnerabilities
Why it's wrong here
A raw vulnerabilities list lacks the prioritization and context needed for executive decision-making, overwhelming the board with details that do not indicate which threats pose the most urgent business risk. Without filtering by exploitability, asset criticality, or potential impact, the analysis hides the most dangerous exposures behind low-severity noise. This approach fails because effective risk communication requires presenting a focused set of risks tied to business harm, not a comprehensive enumeration of every technical issue.
- ✗
Present the CVSS score and affected systems
Why it's wrong here
A CVSS score and affected systems list is a technical snapshot that measures severity in isolation, ignoring how organizational controls, threat actor activity, or business process dependency influence actual risk. Board members cannot interpret a raw 9.1 score as a dollar amount, legal exposure, or operational impact, so it leaves them without a rational basis for prioritizing investments or accepting risk. This still lives firmly in the technician's view, failing to translate the vulnerability into the financial, regulatory, or reputational terms that belong in board-level risk reporting.
- ✓
Describe the potential financial loss, reputational damage, and regulatory fines
Why this is correct
Describing potential financial loss, reputational damage, and regulatory fines directly maps the risk onto the board's fiduciary duties, giving them the essential information needed for risk tolerance and resource allocation. This approach quantifies or estimates impact in the same units executives use to evaluate business decisions, such as ERM frameworks and insurance. It lets the CISO argue for security investment as a business trade-off, which is the only frame that produces meaningful discussion and sign-off.
- ✗
Explain the technical details of the exploit chain
Why it's wrong here
Walking through an exploit chain—such as command injection, privilege escalation, or lateral movement—explains how an attack unfolds but not why the board should care, since it focuses on mechanics rather than consequence. It is written for security operations staff who need to reproduce, detect, or patch the flaw; the board has no action on that level. This briefing would bury the headline business exposure under technical forensics, leading to confusion or risk acceptance due to inability to weigh the impact.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Zero-day
A zero-day is a software security flaw that is unknown to the vendor and has no patch available, making it extremely dangerous because attackers can exploit it before anyone knows it exists.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.