CS0-003 Reporting and Communication Practice Question
A vulnerability report for a critical application shows that a high-risk vulnerability has been accepted by the business owner. What should the analyst include in the report to document this decision?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A formal risk acceptance form signed by the business owner with a justification
Proper risk acceptance documentation requires a formal sign-off by the risk owner, typically including a justification and acceptance date.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A formal risk acceptance form signed by the business owner with a justification
Why this is correct
Formal risk acceptance requires accountability and explicit authorization from the asset owner who bears the ultimate business risk. This document must detail the business justification for not remediating the flaw, alongside compensating controls, to satisfy regulatory compliance and internal governance frameworks.
- ✗
The technical details of the vulnerability only
Why it's wrong here
While technical details such as CVE identifiers and CVSS scores are necessary for assessing risk, they do not constitute a formal risk decision. Without documented business context, formal sign-off, and an explicit decision-making trail, the organization cannot demonstrate due diligence or establish accountability for leaving the vulnerability unpatched.
- ✗
An automatic closure of the vulnerability ticket
Why it's wrong here
Automatically closing a ticket bypasses critical security review processes and creates a blind spot in the vulnerability management lifecycle. Risk acceptance must be actively tracked, periodically reviewed, and kept open or marked with a specific 'accepted risk' status rather than being silently closed, which falsely implies remediation has occurred.
- ✗
A note that the vulnerability is low priority
Why it's wrong here
Simply downgrading or noting a vulnerability as low priority does not legally or operationally transfer or accept the risk. Formal risk acceptance is a governance action requiring explicit sign-off from a designated business authority, whereas a priority note is merely a scheduling or triage classification that leaves the vulnerability unaddressed without formal accountability.
Go deeper
Related to this question
Learn chapter
Remediation SLAs and Risk Acceptance
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.