Courseiva

CS0-004 · domain

Reporting and Communication

This domain covers how cybersecurity analysts communicate findings to technical peers, management, and regulators. On CS0-004 it is tested through scenario questions on incident notification order, choosing the right report type for the audience, breach notification timelines, and after-action reporting that drives remediation. Expect judgment-based items rather than tool configuration.

83 questions18 easy42 medium23 hard

Focused practice

Practice Reporting and Communication questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Reporting and Communication

Know who to notify first internally, which report type fits each audience, and the regulatory clock for breach notification. The single most important skill is tailoring the same incident facts to technical, executive, and regulatory audiences accurately and on time.

Selecting the first internal notification during an incident, typically the incident response team or management chain

Matching threat intelligence report types to audiences, such as strategic reports for executives versus tactical for analysts

Applying regulatory breach notification timelines, including GDPR supervisory authority deadlines

Building after-action reports that capture root cause, timeline, and corrective actions to prevent recurrence

Watch out for

Common Reporting and Communication exam traps

  • ▸Notifying external parties or the media before internal stakeholders, reversing the correct escalation order during an active incident
  • ▸Sending technical indicators of compromise to executives instead of a strategic, risk-focused summary they can act on
  • ▸Treating the after-action report as a narrative of events without root cause analysis or assigned corrective actions

Question index

All Reporting and Communication questions (83)

Click any question to see the full explanation, or start a practice session above.

1

An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?

Hard
2

A company experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum time frame to notify the supervisory authority?

Medium
3

Which of the following BEST describes the purpose of a risk register in the context of reporting and communication?

Medium
4

Which metric would best indicate the effectiveness of an organization's patch management program?

Easy
5

A phishing simulation is conducted, and the click rate is reported to management. What does a high click rate indicate?

Medium
6

An analyst is evaluating the performance of the security operations center (SOC). Which metric best indicates the team's ability to contain an active threat?

Hard
7

During a security incident, a cybersecurity analyst must communicate with various stakeholders. Which TWO are appropriate internal escalation paths? (Select TWO.)

Medium
8

A security analyst is creating metrics for a security dashboard aimed at executive leadership. Which THREE metrics are most appropriate for this audience? (Select THREE.)

Easy
9

After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?

Medium
10

Which metric is commonly used to measure the average time it takes to identify that a security incident has occurred?

Easy
11

After a phishing simulation, the security team wants to report the results to management. Which metric is most appropriate to include in the report?

Easy
12

A cybersecurity analyst is building a compliance dashboard for an upcoming audit. Which TWO metrics are most relevant for demonstrating effective patch management? (Select TWO.)

Easy
13

A cybersecurity analyst is presenting risk findings to the board of directors. Which THREE types of impact should be emphasized to effectively communicate business risk? (Select THREE.)

Hard
14

During a security incident, a CySA+ analyst needs to communicate the status to the CISO. Which type of report is most appropriate for this purpose?

Medium
15

Which of the following is the best example of a Key Performance Indicator (KPI) for patch management?

Easy
16

A security analyst must present a risk assessment to the board of directors. Which approach is most effective for communicating technical risks?

Medium
17

During a compliance audit, the auditor requests evidence of access reviews. Which of the following would be the MOST appropriate evidence to provide?

Medium
18

A security analyst is preparing an incident report after a ransomware attack. Which two components must be included in the report? (Select TWO.)

Medium
19

During a security incident, which of the following should be the FIRST communication to internal stakeholders?

Medium
20

Which type of threat intelligence report is most appropriate for communicating long-term trends and strategic risks to senior executives?

Hard
21

A vulnerability report includes a risk acceptance section. Which of the following scenarios is most appropriate to include in this section?

Medium
22

Which component of an incident report describes the sequence of events from detection to resolution?

Easy
23

An organization is preparing evidence for an audit of access controls. Which THREE types of evidence should be collected? (Select THREE.)

Medium
24

During an incident, the security team discovers that customer personally identifiable information (PII) was exfiltrated. Which of the following notifications must be made according to GDPR?

Hard
25

A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)

Medium
26

After a ransomware incident, the incident report includes lessons learned. Which of the following is the BEST example of a lesson learned?

Medium
27

An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)

Hard
28

A security analyst is preparing a compliance report for an upcoming audit. The auditor has requested evidence of access controls. Which TWO of the following would provide appropriate evidence? (Select TWO.)

Medium
29

An organization has a risk acceptance process for vulnerabilities that cannot be remediated immediately. Which of the following should be documented in the risk acceptance paperwork?

Hard
30

A security analyst discovers a critical vulnerability in a web application that stores customer payment data. The analyst needs to report this to the CISO. Which type of report is most appropriate for communicating the business impact of this vulnerability?

Medium
31

A cybersecurity analyst needs to communicate the risk of a newly discovered vulnerability in a legacy system to the executive leadership. Which approach best translates the technical risk into business risk?

Medium
32

During an incident, which of the following should be the FIRST priority when communicating with law enforcement?

Medium
33

Which metric measures the average time it takes for an organization to identify a security incident from the moment it occurs?

Easy
34

Which type of threat intelligence report is MOST appropriate for a Chief Information Security Officer (CISO) to understand the overall threat landscape and make strategic decisions?

Easy
35

A security analyst is preparing an after-action report for a phishing incident. Which component is MOST critical to include to prevent recurrence?

Medium
36

During an audit, the compliance team needs to provide evidence that access reviews are performed regularly. Which of the following is the BEST evidence?

Hard
37

A cybersecurity analyst is preparing a report for the executive leadership team. Which type of report is most appropriate for communicating high-level security posture and risk to non-technical stakeholders?

Easy
38

A cybersecurity analyst is preparing a vulnerability report for the IT manager. Which section should summarize the most critical risks for the organization?

Easy
39

A security analyst is preparing a vulnerability report for management. Which TWO elements should be included in the executive summary? (Select TWO.)

Medium
40

A security analyst needs to present a risk register to a non-technical board. Which of the following formats is most appropriate?

Medium
41

Which metric measures the average time it takes to identify a security incident from the moment it occurs?

Easy
42

After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)

Hard
43

Which metric measures the average time taken to fix a vulnerability after it is identified?

Easy
44

A vulnerability report is presented to the IT manager. The report lists 15 critical, 40 high, 100 medium, and 200 low vulnerabilities. The IT manager asks which vulnerabilities should be prioritized for remediation. According to the vulnerability report structure, which section should the analyst reference?

Medium
45

An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?

Hard
46

A security analyst is creating a risk register. Which of the following is the most important element to include for each risk?

Medium
47

A security analyst is selecting Key Performance Indicators (KPIs) for a security operations dashboard. Which THREE metrics are most relevant for measuring incident response effectiveness? (Select THREE.)

Medium
48

A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)

Hard
49

A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?

Hard
50

During an incident, the security team needs to preserve evidence for potential litigation. Which of the following actions is most critical to ensure the admissibility of digital evidence?

Hard
51

A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?

Hard
52

A vulnerability report is being prepared for an organization's management. Which of the following is the MOST appropriate structure for this report?

Hard
53

An organization is preparing for a compliance audit. Which TWO of the following are essential pieces of evidence to demonstrate effective vulnerability management?

Hard
54

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the supervisory authority?

Hard
55

A security analyst needs to present the risk of an unpatched critical vulnerability to the board of directors. Which of the following is the most effective way to communicate the risk?

Hard
56

Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?

Medium
57

Which of the following metrics measures the average time it takes to identify a security incident after it occurs?

Easy
58

During a security incident involving a potential data breach, the CISO asks you to prepare a communication for the board of directors. What is the MOST important aspect to emphasize in this communication?

Medium
59

Which three metrics are commonly used to measure the effectiveness of a security operations center (SOC)? (Select THREE.)

Medium
60

An organization's compliance dashboard shows a control effectiveness score of 85%. Which type of evidence best supports this score?

Hard
61

An incident report includes a section that details the sequence of events from initial compromise to containment. Which component of the incident report does this describe?

Medium
62

Which of the following is the primary audience for a strategic threat intelligence report?

Easy
63

An organization is preparing for an audit to demonstrate compliance with GDPR. The compliance officer needs to provide evidence of data protection controls. Which of the following would be the BEST evidence to include?

Medium
64

An analyst is preparing a vulnerability report for management. Which THREE sections should be included to effectively communicate findings and remediation? (Select THREE.)

Medium
65

An analyst is creating a compliance dashboard for management. Which of the following is the most relevant metric to include regarding patch management?

Medium
66

A security analyst is drafting a communication plan for a suspected data breach involving customer personally identifiable information. Legal counsel advises that notification may be required under multiple regulations. Which of the following should the analyst do FIRST to ensure the communication plan meets regulatory obligations?

Easy
67

Which of the following is a key component of a vulnerability report that provides a high-level overview for management?

Medium
68

During an incident response, the SOC team identifies a data breach involving customer PII. Under GDPR, what is the maximum time frame to notify the supervisory authority?

Medium
69

During a security incident, the SOC team identifies indicators of compromise (IoCs) related to a new malware strain. Which type of threat intelligence report should be produced for the SOC team to enhance detection?

Medium
70

An analyst needs to collect evidence for a compliance audit. Which type of evidence is most appropriate to demonstrate that access reviews are performed regularly?

Medium
71

During a security incident, a SOC analyst identifies that customer PII has been exfiltrated. The company operates in multiple states and processes EU residents' data. Which of the following is the MOST critical immediate communication requirement?

Hard
72

A security analyst is preparing a quarterly vulnerability management report for IT operations managers. The report must help them prioritize remediation efforts across a large environment. Which metric is MOST useful to include for this audience?

Medium
73

A security analyst receives a threat intelligence report containing detailed Indicators of Compromise (IoCs) such as IP addresses, file hashes, and domain names. What is the MOST appropriate audience for distributing this type of report?

Medium
74

A security analyst needs to provide threat intelligence to different audiences. Which TWO of the following are appropriate dissemination approaches?

Medium
75

A vulnerability report for a critical application shows that a high-risk vulnerability has been accepted by the business owner. What should the analyst include in the report to document this decision?

Medium
76

Which of the following is a key performance indicator (KPI) for measuring the efficiency of patch management?

Easy
77

A security analyst needs to communicate the business impact of a newly discovered critical vulnerability to the executive team. Which of the following is the BEST approach?

Easy
78

During an incident, the SOC team identifies indicators of compromise (IoCs) that may affect partners. According to best practices, what should the analyst do first?

Hard
79

A security analyst is preparing a vulnerability report for the IT operations team. Which section should provide a high-level overview of the organization's risk posture?

Medium
80

A threat intelligence analyst has produced a report containing specific Indicators of Compromise (IoCs) such as IP addresses, domain names, and file hashes. Which TWO audiences are most appropriate for this type of intelligence? (Select TWO.)

Hard
81

During a security incident, the incident response team has identified that a phishing email led to credential theft and lateral movement. Which component of the incident report should detail the sequence of events from initial compromise to containment?

Medium
82

An incident responder is documenting the root cause of a data breach. Which THREE components are essential to include in the root cause analysis section of the incident report? (Select THREE.)

Medium
83

A financial services organization experienced a ransomware incident that encrypted several file servers. The CISO must deliver a post-incident report to the board of directors and the audit committee. The report must communicate both the business impact and the effectiveness of the response. Which of the following should be included in this executive-level report? (Choose two.)

Hard

Frequently asked questions

What does the Reporting and Communication domain cover on the CS0-004 exam?
Know who to notify first internally, which report type fits each audience, and the regulatory clock for breach notification. The single most important skill is tailoring the same incident facts to technical, executive, and regulatory audiences accurately and on time.
How many questions are in this domain?
This page lists all 83 Reporting and Communication questions in the CS0-004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Reporting and Communication questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cysa-plus CYSA-PLUS cysa reporting communication Practice Questions