mediumMultiple ChoiceObjective-mapped
CS0-003 Practice Question: A security analyst needs to report a critical…
A security analyst needs to report a critical vulnerability to the executive team. The report should balance technical details with business impact. Which of the following is the BEST approach?
⚠ Common exam trap
CompTIA often tests the distinction between technical completeness and audience-appropriate communication, trapping candidates who choose Option D because they mistake 'full technical analysis' for the best approach, when the question explicitly requires balancing technical details with business impact for an executive audience.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Explain the vulnerability in terms of potential business impact and recommended risk treatment
It directly addresses the core requirement of balancing technical details with business impact. For a critical vulnerability, the executive team needs to understand the potential financial, operational, and reputational risks, not just the technical flaw. This approach aligns with the NIST risk management framework, which emphasizes communicating risk in terms of business context to enable informed decision-making on risk treatment (e.g., accept, mitigate, transfer, avoid).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Simply state the vulnerability exists and a patch is available
Why it's wrong here
Simply stating a vulnerability exists and a patch is available fails to provide the necessary context for a critical issue. This approach lacks details on the severity, exploitability, or potential consequences, making it difficult for stakeholders to grasp the urgency or allocate appropriate resources for remediation. Effective reporting requires quantifying risk, not just identifying a problem.
- ✗
Write a 50-page report covering every technical detail and mitigation option
Why it's wrong here
A 50-page report, while exhaustive, is counterproductive for conveying critical information to executive leadership. Decision-makers require concise, high-level summaries that highlight key risks and actionable recommendations, not an overwhelming volume of technical minutiae. Such extensive documentation can obscure the most important points, delaying crucial strategic responses to the vulnerability.
- ✓
Explain the vulnerability in terms of potential business impact and recommended risk treatment
Why this is correct
Explaining a critical vulnerability in terms of its potential business impact—such as financial loss, reputational damage, operational disruption, or regulatory non-compliance—directly addresses executive concerns. Coupled with recommended risk treatment strategies (e.g., mitigation, acceptance, transfer), this approach provides decision-makers with the necessary context to understand the strategic implications and approve appropriate resource allocation. This empowers informed risk management decisions aligned with organizational objectives.
- ✗
Provide a full technical analysis of the vulnerability and remediation steps
Why it's wrong here
Providing a full technical analysis, including granular details of the vulnerability and exhaustive remediation steps, is often too detailed for executive-level reporting. While essential for technical teams implementing fixes, this level of detail can overwhelm non-technical stakeholders, obscuring the overarching business risk. The focus for executives should be on strategic implications and high-level treatment options, not the intricate mechanics of the exploit.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.