CS0-004 · domain
Reporting and Communication
This domain covers how cybersecurity analysts communicate findings to technical peers, management, and regulators. On CS0-004 it is tested through scenario questions on incident notification order, choosing the right report type for the audience, breach notification timelines, and after-action reporting that drives remediation. Expect judgment-based items rather than tool configuration.
Focused practice
Practice Reporting and Communication questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Reporting and Communication
Know who to notify first internally, which report type fits each audience, and the regulatory clock for breach notification. The single most important skill is tailoring the same incident facts to technical, executive, and regulatory audiences accurately and on time.
Selecting the first internal notification during an incident, typically the incident response team or management chain
Matching threat intelligence report types to audiences, such as strategic reports for executives versus tactical for analysts
Applying regulatory breach notification timelines, including GDPR supervisory authority deadlines
Building after-action reports that capture root cause, timeline, and corrective actions to prevent recurrence
Watch out for
Common Reporting and Communication exam traps
- ▸Notifying external parties or the media before internal stakeholders, reversing the correct escalation order during an active incident
- ▸Sending technical indicators of compromise to executives instead of a strategic, risk-focused summary they can act on
- ▸Treating the after-action report as a narrative of events without root cause analysis or assigned corrective actions
Question index
All Reporting and Communication questions (83)
Click any question to see the full explanation, or start a practice session above.
An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?
Hard2A company experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum time frame to notify the supervisory authority?
Medium3Which of the following BEST describes the purpose of a risk register in the context of reporting and communication?
Medium4Which metric would best indicate the effectiveness of an organization's patch management program?
Easy5A phishing simulation is conducted, and the click rate is reported to management. What does a high click rate indicate?
Medium6An analyst is evaluating the performance of the security operations center (SOC). Which metric best indicates the team's ability to contain an active threat?
Hard7During a security incident, a cybersecurity analyst must communicate with various stakeholders. Which TWO are appropriate internal escalation paths? (Select TWO.)
Medium8A security analyst is creating metrics for a security dashboard aimed at executive leadership. Which THREE metrics are most appropriate for this audience? (Select THREE.)
Easy9After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?
Medium10Which metric is commonly used to measure the average time it takes to identify that a security incident has occurred?
Easy11After a phishing simulation, the security team wants to report the results to management. Which metric is most appropriate to include in the report?
Easy12A cybersecurity analyst is building a compliance dashboard for an upcoming audit. Which TWO metrics are most relevant for demonstrating effective patch management? (Select TWO.)
Easy13A cybersecurity analyst is presenting risk findings to the board of directors. Which THREE types of impact should be emphasized to effectively communicate business risk? (Select THREE.)
Hard14During a security incident, a CySA+ analyst needs to communicate the status to the CISO. Which type of report is most appropriate for this purpose?
Medium15Which of the following is the best example of a Key Performance Indicator (KPI) for patch management?
Easy16A security analyst must present a risk assessment to the board of directors. Which approach is most effective for communicating technical risks?
Medium17During a compliance audit, the auditor requests evidence of access reviews. Which of the following would be the MOST appropriate evidence to provide?
Medium18A security analyst is preparing an incident report after a ransomware attack. Which two components must be included in the report? (Select TWO.)
Medium19During a security incident, which of the following should be the FIRST communication to internal stakeholders?
Medium20Which type of threat intelligence report is most appropriate for communicating long-term trends and strategic risks to senior executives?
Hard21A vulnerability report includes a risk acceptance section. Which of the following scenarios is most appropriate to include in this section?
Medium22Which component of an incident report describes the sequence of events from detection to resolution?
Easy23An organization is preparing evidence for an audit of access controls. Which THREE types of evidence should be collected? (Select THREE.)
Medium24During an incident, the security team discovers that customer personally identifiable information (PII) was exfiltrated. Which of the following notifications must be made according to GDPR?
Hard25A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)
Medium26After a ransomware incident, the incident report includes lessons learned. Which of the following is the BEST example of a lesson learned?
Medium27An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)
Hard28A security analyst is preparing a compliance report for an upcoming audit. The auditor has requested evidence of access controls. Which TWO of the following would provide appropriate evidence? (Select TWO.)
Medium29An organization has a risk acceptance process for vulnerabilities that cannot be remediated immediately. Which of the following should be documented in the risk acceptance paperwork?
Hard30A security analyst discovers a critical vulnerability in a web application that stores customer payment data. The analyst needs to report this to the CISO. Which type of report is most appropriate for communicating the business impact of this vulnerability?
Medium31A cybersecurity analyst needs to communicate the risk of a newly discovered vulnerability in a legacy system to the executive leadership. Which approach best translates the technical risk into business risk?
Medium32During an incident, which of the following should be the FIRST priority when communicating with law enforcement?
Medium33Which metric measures the average time it takes for an organization to identify a security incident from the moment it occurs?
Easy34Which type of threat intelligence report is MOST appropriate for a Chief Information Security Officer (CISO) to understand the overall threat landscape and make strategic decisions?
Easy35A security analyst is preparing an after-action report for a phishing incident. Which component is MOST critical to include to prevent recurrence?
Medium36During an audit, the compliance team needs to provide evidence that access reviews are performed regularly. Which of the following is the BEST evidence?
Hard37A cybersecurity analyst is preparing a report for the executive leadership team. Which type of report is most appropriate for communicating high-level security posture and risk to non-technical stakeholders?
Easy38A cybersecurity analyst is preparing a vulnerability report for the IT manager. Which section should summarize the most critical risks for the organization?
Easy39A security analyst is preparing a vulnerability report for management. Which TWO elements should be included in the executive summary? (Select TWO.)
Medium40A security analyst needs to present a risk register to a non-technical board. Which of the following formats is most appropriate?
Medium41Which metric measures the average time it takes to identify a security incident from the moment it occurs?
Easy42After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)
Hard43Which metric measures the average time taken to fix a vulnerability after it is identified?
Easy44A vulnerability report is presented to the IT manager. The report lists 15 critical, 40 high, 100 medium, and 200 low vulnerabilities. The IT manager asks which vulnerabilities should be prioritized for remediation. According to the vulnerability report structure, which section should the analyst reference?
Medium45An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?
Hard46A security analyst is creating a risk register. Which of the following is the most important element to include for each risk?
Medium47A security analyst is selecting Key Performance Indicators (KPIs) for a security operations dashboard. Which THREE metrics are most relevant for measuring incident response effectiveness? (Select THREE.)
Medium48A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)
Hard49A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?
Hard50During an incident, the security team needs to preserve evidence for potential litigation. Which of the following actions is most critical to ensure the admissibility of digital evidence?
Hard51A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?
Hard52A vulnerability report is being prepared for an organization's management. Which of the following is the MOST appropriate structure for this report?
Hard53An organization is preparing for a compliance audit. Which TWO of the following are essential pieces of evidence to demonstrate effective vulnerability management?
Hard54An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the supervisory authority?
Hard55A security analyst needs to present the risk of an unpatched critical vulnerability to the board of directors. Which of the following is the most effective way to communicate the risk?
Hard56Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?
Medium57Which of the following metrics measures the average time it takes to identify a security incident after it occurs?
Easy58During a security incident involving a potential data breach, the CISO asks you to prepare a communication for the board of directors. What is the MOST important aspect to emphasize in this communication?
Medium59Which three metrics are commonly used to measure the effectiveness of a security operations center (SOC)? (Select THREE.)
Medium60An organization's compliance dashboard shows a control effectiveness score of 85%. Which type of evidence best supports this score?
Hard61An incident report includes a section that details the sequence of events from initial compromise to containment. Which component of the incident report does this describe?
Medium62Which of the following is the primary audience for a strategic threat intelligence report?
Easy63An organization is preparing for an audit to demonstrate compliance with GDPR. The compliance officer needs to provide evidence of data protection controls. Which of the following would be the BEST evidence to include?
Medium64An analyst is preparing a vulnerability report for management. Which THREE sections should be included to effectively communicate findings and remediation? (Select THREE.)
Medium65An analyst is creating a compliance dashboard for management. Which of the following is the most relevant metric to include regarding patch management?
Medium66A security analyst is drafting a communication plan for a suspected data breach involving customer personally identifiable information. Legal counsel advises that notification may be required under multiple regulations. Which of the following should the analyst do FIRST to ensure the communication plan meets regulatory obligations?
Easy67Which of the following is a key component of a vulnerability report that provides a high-level overview for management?
Medium68During an incident response, the SOC team identifies a data breach involving customer PII. Under GDPR, what is the maximum time frame to notify the supervisory authority?
Medium69During a security incident, the SOC team identifies indicators of compromise (IoCs) related to a new malware strain. Which type of threat intelligence report should be produced for the SOC team to enhance detection?
Medium70An analyst needs to collect evidence for a compliance audit. Which type of evidence is most appropriate to demonstrate that access reviews are performed regularly?
Medium71During a security incident, a SOC analyst identifies that customer PII has been exfiltrated. The company operates in multiple states and processes EU residents' data. Which of the following is the MOST critical immediate communication requirement?
Hard72A security analyst is preparing a quarterly vulnerability management report for IT operations managers. The report must help them prioritize remediation efforts across a large environment. Which metric is MOST useful to include for this audience?
Medium73A security analyst receives a threat intelligence report containing detailed Indicators of Compromise (IoCs) such as IP addresses, file hashes, and domain names. What is the MOST appropriate audience for distributing this type of report?
Medium74A security analyst needs to provide threat intelligence to different audiences. Which TWO of the following are appropriate dissemination approaches?
Medium75A vulnerability report for a critical application shows that a high-risk vulnerability has been accepted by the business owner. What should the analyst include in the report to document this decision?
Medium76Which of the following is a key performance indicator (KPI) for measuring the efficiency of patch management?
Easy77A security analyst needs to communicate the business impact of a newly discovered critical vulnerability to the executive team. Which of the following is the BEST approach?
Easy78During an incident, the SOC team identifies indicators of compromise (IoCs) that may affect partners. According to best practices, what should the analyst do first?
Hard79A security analyst is preparing a vulnerability report for the IT operations team. Which section should provide a high-level overview of the organization's risk posture?
Medium80A threat intelligence analyst has produced a report containing specific Indicators of Compromise (IoCs) such as IP addresses, domain names, and file hashes. Which TWO audiences are most appropriate for this type of intelligence? (Select TWO.)
Hard81During a security incident, the incident response team has identified that a phishing email led to credential theft and lateral movement. Which component of the incident report should detail the sequence of events from initial compromise to containment?
Medium82An incident responder is documenting the root cause of a data breach. Which THREE components are essential to include in the root cause analysis section of the incident report? (Select THREE.)
Medium83A financial services organization experienced a ransomware incident that encrypted several file servers. The CISO must deliver a post-incident report to the board of directors and the audit committee. The report must communicate both the business impact and the effectiveness of the response. Which of the following should be included in this executive-level report? (Choose two.)
HardOther domains
All CS0-004 exam domains
Frequently asked questions
- What does the Reporting and Communication domain cover on the CS0-004 exam?
- Know who to notify first internally, which report type fits each audience, and the regulatory clock for breach notification. The single most important skill is tailoring the same incident facts to technical, executive, and regulatory audiences accurately and on time.
- How many questions are in this domain?
- This page lists all 83 Reporting and Communication questions in the CS0-004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Reporting and Communication questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.