mediumMultiple Choice
CS0-003 Practice Question: A vulnerability programme wants to show whether…
A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is SOC manager, which content choice is most appropriate?
⚠ Common exam trap
The CS0-004 exam often tests the distinction between a report that merely lists findings (like sorted by plugin ID) versus one that demonstrates compliance with a policy timeline, and candidates may confuse a technical sort with a business-oriented SLA report.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SLA compliance by severity, asset owner, and business unit
The vulnerability program needs to demonstrate that critical findings are remediated within policy timelines, which requires a report showing SLA compliance. For a SOC manager, the most appropriate content includes severity, asset owner, and business unit breakdowns, enabling them to track accountability and prioritize remediation efforts across the organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A report sorted only by scanner plugin ID
Why it's wrong here
Sorting solely by scanner plugin ID groups findings by detection tooling, giving no view of remediation dates against policy timelines. It is tempting because plugin ID ordering helps engineers triage scanner coverage, which would be correct for a vulnerability analyst audience rather than a SOC manager tracking SLA compliance.
- ✓
SLA compliance by severity, asset owner, and business unit
Why this is correct
SLA compliance by severity, asset owner, and business unit directly evidences whether critical findings were remediated inside policy timelines, and its grouping by owner and unit gives the SOC manager the accountability view they need.
- ✗
A list of all closed tickets with no dates
Why it's wrong here
A list of closed tickets without dates cannot demonstrate whether fixes met policy timelines, since no remediation or closure timestamps are shown. It is tempting because closed-ticket volume suggests remediation activity, which would be correct for a workload or throughput report rather than SLA compliance evidence.
- ✗
A vendor price comparison
Why it's wrong here
A vendor price comparison lists licensing costs, not remediation performance against policy timelines, so it cannot evidence whether critical findings were fixed on time. It is tempting because procurement data supports budget planning, and it would be the right choice when the audience needs cost analysis rather than SOC remediation metrics.
Go deeper
Related to this question
Learn chapter
Patch and Remediation Workflows
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.