CS0-003 Reporting and Communication Practice Question
A security analyst is creating metrics for a security dashboard aimed at executive leadership. Which THREE metrics are most appropriate for this audience? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Phishing simulation click rates
Executives prefer high-level metrics that show overall security posture, trends, and business impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Phishing simulation click rates
Why this is correct
Phishing simulation click rates are a leading indicator of user resilience to social engineering attacks, directly measuring the effectiveness of security awareness training. A high click rate signals elevated human risk, while declining clicks over successive campaigns demonstrate improved workforce behavior. This metric is strategic because it quantifies a primary attack vector—email—and supports data-driven adjustments to training content and cadence.
- ✓
Number of security incidents by category
Why this is correct
Categorizing incidents by type—such as malware, credential theft, insider misuse, or denial-of-service—reveals threat trends and identifies weak controls, allowing leadership to prioritize security investments and adjust policies. This metric supports strategic decision-making by showing where the organization is most frequently attacked or where incident counts are rising, rather than focusing on isolated events. It also establishes a baseline for measuring the effectiveness of new defenses over time.
- ✓
Mean time to detect (MTTD)
Why this is correct
Mean time to detect (MTTD) measures how quickly an organization's detection tools, SIEM correlations, and analysts identify a security breach from the moment of initial compromise. It is a key performance indicator for visibility and monitoring coverage; a shrinking MTTD indicates faster incident response and reduced dwell time, which directly limits an attacker's opportunity to move laterally or exfiltrate data. This is an executive-level KPI because prolonged dwell time strongly correlates with higher breach costs.
- ✗
Vulnerability scan details for individual hosts
Why it's wrong here
Reporting vulnerability scan details for individual hosts, such as specific CVEs and CVSS scores for particular servers, floods the dashboard with operational noise. Executives need aggregate risk trends, not per-host patch status, because individual host details do not inform strategic priorities and can obscure broader systemic issues. This level of granularity belongs in IT and security operations ticketing workflows, not on a leadership-focused security dashboard.
- ✗
Firewall rule change request logs
Why it's wrong here
Firewall rule change request logs are routine change-management workflow artifacts that track approvals, implementations, and audits of access control modifications. They are not strategic metrics because they measure administrative activity rather than security outcomes or residual risk; a high volume of changes may simply reflect normal business operations. These logs are valuable for compliance, troubleshooting, and audit evidence, but they lack the aggregate, risk-focused context required for an executive dashboard.
Go deeper
Related to this question
Learn chapter
Security Metrics and KPIs
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.