Courseiva
mediumMultiple ChoiceObjective-mapped

CS0-003 Practice Question: A security analyst needs to report a critical…

A security analyst needs to report a critical vulnerability to the executive team. The report should balance technical details with business impact. Which of the following is the BEST approach?

⚠ Common exam trap

CompTIA often tests the distinction between technical completeness and audience-appropriate communication, trapping candidates who choose Option D because they mistake 'full technical analysis' for the best approach, when the question explicitly requires balancing technical details with business impact for an executive audience.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Explain the vulnerability in terms of potential business impact and recommended risk treatment

It directly addresses the core requirement of balancing technical details with business impact. For a critical vulnerability, the executive team needs to understand the potential financial, operational, and reputational risks, not just the technical flaw. This approach aligns with the NIST risk management framework, which emphasizes communicating risk in terms of business context to enable informed decision-making on risk treatment (e.g., accept, mitigate, transfer, avoid).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Simply state the vulnerability exists and a patch is available

    Why it's wrong here

    Simply stating a vulnerability exists and a patch is available fails to provide the necessary context for a critical issue. This approach lacks details on the severity, exploitability, or potential consequences, making it difficult for stakeholders to grasp the urgency or allocate appropriate resources for remediation. Effective reporting requires quantifying risk, not just identifying a problem.

  • Write a 50-page report covering every technical detail and mitigation option

    Why it's wrong here

    A 50-page report, while exhaustive, is counterproductive for conveying critical information to executive leadership. Decision-makers require concise, high-level summaries that highlight key risks and actionable recommendations, not an overwhelming volume of technical minutiae. Such extensive documentation can obscure the most important points, delaying crucial strategic responses to the vulnerability.

  • Explain the vulnerability in terms of potential business impact and recommended risk treatment

    Why this is correct

    Explaining a critical vulnerability in terms of its potential business impact—such as financial loss, reputational damage, operational disruption, or regulatory non-compliance—directly addresses executive concerns. Coupled with recommended risk treatment strategies (e.g., mitigation, acceptance, transfer), this approach provides decision-makers with the necessary context to understand the strategic implications and approve appropriate resource allocation. This empowers informed risk management decisions aligned with organizational objectives.

  • Provide a full technical analysis of the vulnerability and remediation steps

    Why it's wrong here

    Providing a full technical analysis, including granular details of the vulnerability and exhaustive remediation steps, is often too detailed for executive-level reporting. While essential for technical teams implementing fixes, this level of detail can overwhelm non-technical stakeholders, obscuring the overarching business risk. The focus for executives should be on strategic implications and high-level treatment options, not the intricate mechanics of the exploit.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.