mediumMultiple Choice
CS0-003 Practice Question: A vulnerability programme wants to show whether…
A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is business service owner, which content choice is most appropriate?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between technical raw data (e.g., plugin ID sort) and business-oriented, decision-support reports (e.g., SLA compliance by business unit) to see if candidates understand that reporting must be tailored to the audience's role and responsibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SLA compliance by severity, asset owner, and business unit
An SLA compliance report by severity, asset owner, and business unit directly maps to the requirement of showing whether critical findings are fixed within policy timelines. This report allows the vulnerability program to track remediation against defined service-level agreements (SLAs), and the breakdown by business unit and asset owner provides the business service owner with actionable, ownership-specific data to drive accountability and resource allocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SLA compliance by severity, asset owner, and business unit
Why this is correct
SLA compliance by severity, asset owner, and business unit provides the most comprehensive view for a vulnerability program. It directly measures the timeliness of critical vulnerability remediation against established service level agreements, broken down by the responsible parties and their organizational context. This granular reporting enables accountability, highlights areas of non-compliance, and effectively demonstrates whether critical risks are being addressed promptly, aligning security efforts with business objectives.
- ✗
A report sorted only by scanner plugin ID
Why it's wrong here
A report sorted only by scanner plugin ID offers insufficient context for a vulnerability program aiming to demonstrate effective critical vulnerability remediation. While technical, plugin IDs lack crucial information regarding asset ownership, business impact, or the severity of the vulnerability in a business context. This narrow focus prevents proper risk prioritization and fails to assign accountability for remediation efforts, making it ineffective for strategic vulnerability management.
- ✗
A vendor price comparison
Why it's wrong here
A vendor price comparison is entirely irrelevant to assessing a vulnerability program's effectiveness in addressing critical vulnerabilities. This financial metric focuses solely on procurement costs and does not provide any insight into the timeliness, quality, or completion status of vulnerability remediation activities. It fails to measure the program's core objective: reducing risk by promptly fixing critical security flaws.
- ✗
A list of all closed tickets with no dates
Why it's wrong here
A list of all closed tickets with no dates offers a superficial and incomplete view of remediation progress, making it impossible to measure SLA performance. Without associated dates for ticket creation, assignment, and closure, there is no way to determine the duration of remediation or assess timeliness against critical vulnerability SLAs. This data lacks the necessary temporal context to evaluate accountability or identify bottlenecks in the remediation workflow.
Go deeper
Related to this question
Learn chapter
Continuous Compliance Monitoring
Key term
SLA
A Service Level Agreement (SLA) is a contract between a service provider and a customer that defines the level of service expected, including metrics like uptime, response time, and penalties for non-compliance.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.