mediumMultiple Choice
CS0-003 SLA compliance Practice Question
A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is legal/privacy stakeholder, which content choice is most appropriate?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that any list of closed tickets is sufficient for compliance reporting, but the trap here is that without date fields and severity-based SLA filtering, you cannot prove policy adherence—candidates overlook the need for time-bound, severity-specific metrics in legal/privacy contexts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SLA compliance by severity, asset owner, and business unit
B is correct because SLA compliance by severity, asset owner, and business unit directly maps to the requirement of showing whether critical findings are fixed within policy timelines. This report filters by severity (e.g., critical), includes time-bound metrics (SLA compliance), and can be broken down by asset owner and business unit to demonstrate accountability and policy adherence. For legal/privacy stakeholders, this content provides auditable evidence of remediation timelines, which is essential for regulatory compliance and risk management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of all closed tickets with no dates
Why it's wrong here
Closed tickets without dates cannot demonstrate whether remediation met policy timelines, since no closure or discovery timestamps exist to compare. It tempts because a closed-ticket inventory does evidence that findings were resolved, which suits general programme reporting rather than legal or privacy stakeholders needing timeline assurance.
- ✓
SLA compliance by severity, asset owner, and business unit
Why this is correct
SLA compliance by severity, asset owner and business unit directly evidences whether critical findings were remediated inside policy timelines, satisfying the programme's reporting goal. Grouping by owner and business unit also gives legal and privacy stakeholders accountability context without exposing raw vulnerability detail.
- ✗
A vendor price comparison
Why it's wrong here
Vendor pricing has no bearing on remediation timelines or privacy exposure, so it cannot evidence policy compliance. It tempts because cost analysis supports procurement and budget decisions, which is the right content when the audience is finance rather than legal or privacy stakeholders.
- ✗
A report sorted only by scanner plugin ID
Why it's wrong here
Sorting by scanner plugin ID groups findings by detection tooling, not by remediation age, so overdue critical items cannot be identified. It tempts because plugin IDs help engineers trace detection logic and reproduce findings, which suits technical triage rather than legal or privacy reporting.
Go deeper
Related to this question
Learn chapter
Patch and Remediation Workflows
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.