mediumMultiple Select
CS0-003 Practice Question: A security analyst needs to communicate the…
A security analyst needs to communicate the results of a vulnerability scan to different stakeholders. Which TWO of the following are appropriate reporting formats for executive-level stakeholders?
⚠ Common exam trap
CompTIA often tests the distinction between stakeholder-appropriate reporting formats, and the trap here is that candidates mistakenly choose technical options (like CVSS scores or raw scanner output) because they focus on the data's accuracy rather than the audience's need for actionable, non-technical summaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A one-page executive summary with risk ratings and business impact
Executive-level stakeholders require high-level, business-focused information to make strategic decisions. A one-page executive summary with risk ratings and business impact (Option A) provides a concise overview of the most critical vulnerabilities, their potential effect on operations, and recommended actions without technical jargon. A dashboard showing trend analysis and high-level metrics (Option B) allows executives to quickly assess the organization's security posture over time, track remediation progress, and identify emerging risks through visual data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A one-page executive summary with risk ratings and business impact
Why this is correct
This document translates complex technical vulnerabilities into business risk and financial impact, which is essential for executive decision-making. By keeping it to a single page, it ensures that leadership can quickly grasp the organization's current risk posture and allocate resources effectively without getting bogged down in technical minutiae.
- ✓
A dashboard showing trend analysis and high-level metrics
Why this is correct
Visual dashboards provide executives with a macro-level view of security posture trends, illustrating whether vulnerability management efforts are succeeding over time. This high-level reporting helps leadership track key performance indicators (KPIs) and understand systemic risk trajectories without needing to analyze individual CVEs.
- ✗
A detailed remediation checklist for system administrators
Why it's wrong here
While highly valuable for the technical teams responsible for patching, a step-by-step remediation checklist contains operational details that are too granular for an executive audience. Executives require strategic risk assessments rather than tactical instructions on registry modifications or package updates.
- ✗
A raw output from the vulnerability scanner
Why it's wrong here
Raw scanner outputs, such as Nessus or Qualys XML/CSV files, contain thousands of lines of unparsed data, false positives, and duplicate entries. Presenting this unformatted data to executives is ineffective because it lacks context, prioritization, and business-level analysis.
- ✗
A technical report listing CVSS scores and exploit details
Why it's wrong here
This type of report focuses on CVSS vectors, exploitability metrics, and proof-of-concept code, which are critical for security analysts but irrelevant to executive-level governance. Executives need to understand the business implications of vulnerabilities, not the specific mechanics of how a buffer overflow or remote code execution vulnerability is executed.
Go deeper
Related to this question
Learn chapter
Risk Register and Vulnerability Register
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.