Courseiva
mediumMultiple Select

CS0-003 Practice Question: A security analyst needs to communicate the…

A security analyst needs to communicate the findings of a penetration test to the IT operations team and the CISO. Which three of the following actions best support effective reporting and communication? (Choose three.)

⚠ Common exam trap

CompTIA often tests the misconception that including all raw technical data in the executive summary is thorough, when in fact it violates audience-specific communication best practices and can overwhelm non-technical readers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customize the level of detail in the report for each audience

Customizing the level of detail for each audience ensures that technical teams receive the operational depth they need (e.g., raw findings, exploit paths) while executives get a high-level summary focused on business risk and strategic impact. This aligns with the principle of audience-aware reporting in penetration testing, where the CISO requires risk context and the IT operations team needs actionable technical details.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Customize the level of detail in the report for each audience

    Why this is correct

    Tailoring the report's depth to each recipient means the CISO receives a business-risk-framed executive summary while IT operations receives the detailed technical findings and reproduction steps they need to actually implement fixes, ensuring each audience gets information they can act on.

  • ✗

    Include raw command outputs and exploit code in the executive summary

    Why it's wrong here

    Placing raw command output and exploit code in the executive summary buries the business-relevant risk narrative under material a CISO cannot parse, and it also creates unnecessary exposure of exploit details in a document that circulates more broadly than the technical appendix should.

  • ✓

    Prioritize findings based on risk to the organization’s mission

    Why this is correct

    Ranking findings by their actual risk to organizational mission, rather than by raw CVSS score alone, ensures remediation effort is directed first at vulnerabilities that threaten critical business functions, giving stakeholders a defensible basis for sequencing limited remediation resources.

  • ✓

    Provide actionable remediation steps with ownership assignments

    Why this is correct

    Pairing each finding with a concrete remediation step and a named owner closes the loop between identifying a vulnerability and actually fixing it, since findings left without assigned accountability frequently stall in backlog and never get resolved by any specific team.

  • ✗

    Delay the report until all findings are fully verified with no uncertainty

    Why it's wrong here

    Withholding the entire report until every finding is verified with absolute certainty delays remediation of already-confirmed critical vulnerabilities and contradicts the timeliness expectation of penetration test reporting, where interim or phased communication of high-confidence findings is preferred over a single delayed release.

  • ✗

    Submit the report as a confidential document without any verbal briefing

    Why it's wrong here

    Submitting only a written document without a verbal briefing removes the opportunity for stakeholders to ask clarifying questions, discuss prioritization tradeoffs in real time, and confirm that technical findings were correctly understood, which is why effective reporting practice pairs the written report with a presentation.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.