Courseiva
mediumMultiple Choice

CS0-003 Practice Question: A vulnerability programme wants to show whether…

A vulnerability programme wants to show whether critical findings are fixed within policy timelines. Which report is best? If the primary audience is SOC manager, which content choice is most appropriate?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between a report that merely lists findings (like sorted by plugin ID) versus one that demonstrates compliance with a policy timeline, and candidates may confuse a technical sort with a business-oriented SLA report.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SLA compliance by severity, asset owner, and business unit

The vulnerability program needs to demonstrate that critical findings are remediated within policy timelines, which requires a report showing SLA compliance. For a SOC manager, the most appropriate content includes severity, asset owner, and business unit breakdowns, enabling them to track accountability and prioritize remediation efforts across the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A report sorted only by scanner plugin ID

    Why it's wrong here

    Sorting solely by scanner plugin ID groups findings by detection tooling, giving no view of remediation dates against policy timelines. It is tempting because plugin ID ordering helps engineers triage scanner coverage, which would be correct for a vulnerability analyst audience rather than a SOC manager tracking SLA compliance.

  • ✓

    SLA compliance by severity, asset owner, and business unit

    Why this is correct

    SLA compliance by severity, asset owner, and business unit directly evidences whether critical findings were remediated inside policy timelines, and its grouping by owner and unit gives the SOC manager the accountability view they need.

  • ✗

    A list of all closed tickets with no dates

    Why it's wrong here

    A list of closed tickets without dates cannot demonstrate whether fixes met policy timelines, since no remediation or closure timestamps are shown. It is tempting because closed-ticket volume suggests remediation activity, which would be correct for a workload or throughput report rather than SLA compliance evidence.

  • ✗

    A vendor price comparison

    Why it's wrong here

    A vendor price comparison lists licensing costs, not remediation performance against policy timelines, so it cannot evidence whether critical findings were fixed on time. It is tempting because procurement data supports budget planning, and it would be the right choice when the audience needs cost analysis rather than SOC remediation metrics.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.