CS0-003 Reporting and Communication Practice Question
A security analyst needs to present a risk register to a non-technical board. Which of the following formats is most appropriate?
⚠ Common exam trap
CS0-004 often tests the ability to tailor communication to different audiences, and candidates may choose technical formats like CVE lists or network diagrams that are inappropriate for non-technical stakeholders.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A heat map with risk ratings and business impact descriptions
A heat map with risk ratings and business impact descriptions is most appropriate for a non-technical board because it visually communicates risk severity and business consequences without requiring technical expertise. It translates technical risks into business terms, facilitating informed decision-making.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A timeline of past incidents
Why it's wrong here
A timeline of past incidents shows historical events, not forward-looking risk exposure, likelihood or treatment ownership, so it omits the register's core content. It is tempting because incident history illustrates security posture, and would suit a post-incident review rather than a risk register presentation.
- ✓
A heat map with risk ratings and business impact descriptions
Why this is correct
A heat map converts likelihood and impact into colour-coded bands, letting a non-technical board grasp relative exposure at a glance without interpreting raw scores. Pairing each rating with a business impact description satisfies the stem's constraint: communicating risk to an audience lacking technical background, so prioritisation and funding decisions can be made quickly.
- ✗
A list of CVEs with CVSS scores
Why it's wrong here
A CVE list with CVSS scores presents raw technical identifiers and severity metrics that non-technical directors cannot translate into business risk. It is tempting because CVSS quantifies severity, and would suit a vulnerability management review with security practitioners rather than a board.
- ✗
A detailed network diagram with vulnerability locations
Why it's wrong here
A network diagram with vulnerability locations conveys topology and technical placement, not risk severity, likelihood or business impact, which a board needs to prioritise. It is tempting because it visualises exposure, and would be the right choice for a technical remediation planning session with engineers.
Go deeper
Related to this question
Learn chapter
Risk Scoring and Heat Maps
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.