CS0-003 Reporting and Communication Practice Question
A security analyst is preparing a quarterly vulnerability management report for IT operations managers. The report must help them prioritize remediation efforts across a large environment. Which metric is MOST useful to include for this audience?
⚠ Common exam trap
The trap here is focusing on volume or process metrics like total counts or scan completions, when operational audiences need outcome-based, accountability-driven metrics to prioritize work.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Percentage of critical vulnerabilities remediated within the defined SLA, segmented by business unit
IT operations managers need actionable metrics that tie remediation performance to accountability and risk reduction. The percentage of critical vulnerabilities remediated within SLA, broken down by business unit, provides clear visibility into which teams are meeting targets and where intervention is needed. This drives prioritization far better than raw counts, averages, or process metrics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Number of vulnerability scans completed successfully each month
Why it's wrong here
Scan completion is a process metric, not an outcome metric. It shows that scanning occurred, but not whether identified vulnerabilities were remediated. IT operations managers need to understand remediation performance and risk reduction, not just scanning coverage. This metric could be useful for the security team's internal process monitoring, but it does not help prioritize remediation work across business units.
- ✗
Average CVSS base score of all open vulnerabilities across the enterprise
Why it's wrong here
A single average CVSS score obscures distribution and critical outliers. A high average could be driven by many medium findings while critical vulnerabilities remain unaddressed. IT operations managers need to know which specific high-risk issues are overdue, not a blended score. This metric does not support prioritization or accountability, making it ineffective for driving remediation decisions.
- ✗
Total count of vulnerabilities discovered, grouped by severity rating
Why it's wrong here
Simply counting vulnerabilities by severity does not help IT operations prioritize effectively. A large number of low-severity findings may be less urgent than a few critical ones on internet-facing systems. This metric lacks context about exploitability, asset criticality, and business impact, so managers cannot easily determine where to focus limited remediation resources. It is a common but insufficient reporting approach.
- ✓
Percentage of critical vulnerabilities remediated within the defined SLA, segmented by business unit
Why this is correct
This metric combines severity, timeliness, and organizational accountability. IT operations managers can see which business units are meeting remediation targets and which are falling behind, enabling targeted action. It directly reflects the effectiveness of the vulnerability management process and aligns with common SLA-driven remediation programs. This makes it highly actionable for operational prioritization and performance management.
Go deeper
Related to this question
Learn chapter
Zero-Day Vulnerability Response
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.