hardMultiple Select
CS0-003 Practice Question: A vulnerability dashboard for executives should…
A vulnerability dashboard for executives should avoid raw technical overload. Which views are useful? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between raw technical data (useful for analysts) and summarized business-contextual views (useful for executives), trapping candidates who think any vulnerability data is appropriate for all audiences.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Critical exposure trend by business service
Executive dashboards must communicate risk in business terms, not technical raw data. A trend of critical exposures by business service translates vulnerability severity into operational impact, enabling prioritization of remediation resources without requiring technical expertise. This aligns with the Reporting and Communication domain's emphasis on tailoring information to the audience.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of scanner process IDs
Why it's wrong here
A list of scanner process IDs (PIDs) represents low-level operational details, identifying specific instances of running software on a system. While crucial for system administrators troubleshooting scanner operations, PIDs provide no context regarding the identified vulnerabilities, their severity, or their potential business impact. Executives require aggregated, risk-centric metrics that inform strategic decisions, not granular system diagnostics.
- ✗
Unfiltered plugin-output text
Why it's wrong here
Unfiltered plugin-output text from vulnerability scanners contains highly technical, verbose details such as specific CVEs, configuration errors, and raw scan results. This raw data is essential for security engineers to understand and remediate vulnerabilities but is overwhelming and lacks the necessary business context for executive decision-making. Executives need summarized, prioritized information that highlights critical risks and their implications, not a technical data dump.
- ✓
Critical exposure trend by business service
Why this is correct
Presenting critical exposure trends, specifically categorized by business service, offers executives a strategic and actionable view of the organization's evolving risk posture. This metric indicates whether the most severe risks are increasing or decreasing within specific operational areas, directly linking security posture to business impact. Such trends enable informed resource allocation and strategic decision-making to mitigate risks affecting critical business functions.
- ✓
SLA compliance and overdue remediation by owner
Why this is correct
Reporting on Service Level Agreement (SLA) compliance for vulnerability remediation, along with overdue items attributed to specific owners, directly addresses accountability and operational effectiveness. This metric allows executives to assess the efficiency of the remediation process, identify performance gaps, and hold responsible parties accountable for timely risk mitigation. It provides a clear picture of the organization's adherence to its risk management policies and operational commitments.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.