mediumMultiple Select
CS0-003 Practice Question: A security analyst must prepare a report on a…
A security analyst must prepare a report on a recent intrusion for a technical audience (IT staff and security engineers). Which TWO elements should be included?
⚠ Common exam trap
CompTIA often tests the distinction between audience-appropriate content, where candidates mistakenly include business impact or exploit code for a technical audience, overlooking that technical staff need actionable forensic data like IoCs and clear remediation steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Indicators of compromise (IoCs)
Indicators of Compromise (IoCs) are essential for a technical audience because they provide the forensic artifacts—such as IP addresses, file hashes, registry keys, and domain names—that security engineers need to detect, contain, and eradicate the intrusion. Including IoCs enables the IT staff to update detection signatures, block malicious infrastructure, and perform host-based threat hunting, directly supporting incident response and future prevention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Estimated financial cost of the incident
Why it's wrong here
Estimated financial cost quantifies losses, insurance claims, and remediation budget, which is data business stakeholders and executives use for risk decisions and reporting obligations, but IT and security engineers cannot act on a dollar figure to detect, contain, or remediate the intrusion, so it does not belong in a technical audience report.
- ✓
Indicators of compromise (IoCs)
Why this is correct
Indicators of compromise such as malicious IP addresses, file hashes, registry keys, and C2 domains give engineers concrete, actionable artifacts they can load into SIEM correlation rules, EDR block lists, or YARA signatures to hunt for the same threat elsewhere in the environment and confirm the intrusion has been fully eradicated.
- ✓
Mitigation steps and remediation actions taken
Why this is correct
Documenting which mitigation and remediation steps were already executed, such as patching, credential resets, or network isolation, prevents duplicate or conflicting work, helps engineers verify closure of each attack vector, and provides a technical audit trail confirming the incident response lifecycle was completed correctly rather than left partially remediated.
- ✗
Full exploit code used in the attack
Why it's wrong here
Distributing the full working exploit code creates unnecessary risk of misuse or accidental release beyond the response team, and most technical staff performing detection and remediation need the IoCs and attack behavior, not a weaponized proof-of-concept; sensitive exploit details are typically restricted to the specific engineers doing root-cause analysis, not published broadly in the incident report.
- ✗
Executive summary explaining business impact
Why it's wrong here
An executive summary framed around business impact, such as reputational damage or regulatory exposure, is written for leadership decision-making and lacks the granular forensic detail engineers require; including it in a technical report wastes space that should instead cover attack timeline, affected systems, and IoCs relevant to hands-on defenders.
Go deeper
Related to this question
Learn chapter
SIGMA and YARA Detection Rules
Key term
Detection
Detection is the process of identifying potential security incidents or anomalies by analyzing system data, logs, and network traffic.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.