Courseiva
Reporting and Communication →mediumMultiple Choice

CS0-003 Reporting and Communication Practice Question

A vulnerability report for a critical application shows that a high-risk vulnerability has been accepted by the business owner. What should the analyst include in the report to document this decision?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A formal risk acceptance form signed by the business owner with a justification

Proper risk acceptance documentation requires a formal sign-off by the risk owner, typically including a justification and acceptance date.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A formal risk acceptance form signed by the business owner with a justification

    Why this is correct

    Formal risk acceptance requires accountability and explicit authorization from the asset owner who bears the ultimate business risk. This document must detail the business justification for not remediating the flaw, alongside compensating controls, to satisfy regulatory compliance and internal governance frameworks.

  • ✗

    The technical details of the vulnerability only

    Why it's wrong here

    While technical details such as CVE identifiers and CVSS scores are necessary for assessing risk, they do not constitute a formal risk decision. Without documented business context, formal sign-off, and an explicit decision-making trail, the organization cannot demonstrate due diligence or establish accountability for leaving the vulnerability unpatched.

  • ✗

    An automatic closure of the vulnerability ticket

    Why it's wrong here

    Automatically closing a ticket bypasses critical security review processes and creates a blind spot in the vulnerability management lifecycle. Risk acceptance must be actively tracked, periodically reviewed, and kept open or marked with a specific 'accepted risk' status rather than being silently closed, which falsely implies remediation has occurred.

  • ✗

    A note that the vulnerability is low priority

    Why it's wrong here

    Simply downgrading or noting a vulnerability as low priority does not legally or operationally transfer or accept the risk. Formal risk acceptance is a governance action requiring explicit sign-off from a designated business authority, whereas a priority note is merely a scheduling or triage classification that leaves the vulnerability unaddressed without formal accountability.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.