CS0-003 Reporting and Communication Practice Question
A security analyst needs to present the risk of an unpatched critical vulnerability to the board of directors. Which of the following is the most effective way to communicate the risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Explain the potential financial loss and reputational damage.
Boards care about business impact, not technical details. Quantifying financial exposure helps them understand urgency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Explain the potential financial loss and reputational damage.
Why this is correct
Quantifying the unpatched vulnerability in terms of potential financial loss—such as breach response costs, regulatory fines, or lost revenue from downtime—and reputational damage, like customer churn or erosion of brand trust, directly aligns the technical risk with the board's fiduciary responsibilities. This translation reassures executives that their decision allocates resources to protect shareholder value and market standing, not just IT infrastructure.
- ✗
Show the CVSS score and exploit complexity.
Why it's wrong here
A CVSS score and exploit complexity, while useful for internal prioritization, are abstract metrics that fail to convey how the vulnerability affects the company's bottom line or strategic objectives. Board members without a security background cannot translate a 'high' severity score into dollars lost or customer impact, so this approach leaves them unable to make an informed risk acceptance or mitigation decision.
- ✗
Recommend immediate patching without details.
Why it's wrong here
Simply urging immediate patching without explaining the underlying risk fails to justify the expenditure, downtime, or potential compatibility issues to a board that must balance security against other business priorities. Executives need a cost-benefit analysis and a clear articulation of what could happen if the patch is delayed, or they will likely defer action and leave the organization exposed.
- ✗
Describe the vulnerability in technical terms.
Why it's wrong here
Describing the technical nature of the vulnerability—such as buffer overflows, injection flaws, or misconfigurations—says nothing about the potential operational, legal, or competitive consequences that matter to business leaders. Non-technical board members will struggle to see why mitigation is necessary, and the inability to frame the risk in business terms can undermine the security team's credibility and the urgency of the request.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.