A security analyst needs to present vulnerability scan results to a non-technical manager. Which of the following is MOST important to include?
A non-technical manager needs business context, not raw technical detail. Summarising critical vulnerabilities alongside their business risk and recommended remediation actions translates scanner output into decision-ready information, satisfying the stem's requirement to communicate findings effectively to a non-technical audience.
Why this answer
When presenting vulnerability scan results to a non-technical manager, the most important information is a summary of critical vulnerabilities with associated business risk and recommended actions. This approach translates technical details into business impact, enabling the manager to understand the urgency and make informed decisions about resource allocation. Options B and C are too technical, while Option D lacks context and prioritization.