Courseiva

CCNA Reporting and Communication Questions

39 questions · Reporting and Communication · All types, answers revealed

1
MCQeasy

Which metric would best indicate the effectiveness of an organization's patch management program?

A.Phishing simulation click rates
B.Open vulnerability counts by severity
C.Mean time to detect (MTTD)
D.Patch SLA compliance percentage
AnswerD

Patch SLA compliance percentage directly measures the proportion of patches applied within the stipulated timeframes, such as critical patches within 48 hours or high-severity within 30 days. It quantifies adherence to the patching policy and reflects the organization's ability to remediate known vulnerabilities on schedule. This is the most relevant benchmark because it captures timeliness, completeness, and scheduling discipline, which are the core factors of patch management effectiveness.

Why this answer

Patch SLA compliance percentage directly measures how often patches are applied within required timeframes.

2
Multi-Selectmedium

During a security incident, which THREE elements are critical to include in the incident report for a compliance review?

Select 3 answers
A.Lessons learned
B.Impact assessment
C.Remediation timeline
D.Timeline of events
E.Root cause analysis
AnswersB, D, E

This quantifies the degradation to confidentiality, integrity, and availability, including data exfiltration volume, systems compromised, financial losses, and regulatory exposure. It is critical because it drives the severity classification, escalations, and short-term mitigation priorities such as isolating affected hosts or activating business continuity plans. Impact assessment also provides stakeholders with the information needed to decide on legal reporting and customer notifications.

Why this answer

Timeline, impact assessment, and root cause are essential for understanding the incident and meeting compliance requirements. Lessons learned are important for improvement but not always mandatory for compliance; remediation timeline may be separate.

3
Multi-Selectmedium

During a security incident, a cybersecurity analyst must communicate with various stakeholders. Which TWO are appropriate internal escalation paths? (Select TWO.)

Select 2 answers
A.Legal and compliance department
B.Law enforcement
C.Customers
D.Incident response team
E.Media
AnswersA, D

The legal and compliance department is the correct first point of contact because it ensures the organization satisfies statutory and regulatory breach notification obligations (e.g., GDPR, HIPAA, SEC rules) before any public or external disclosure. They also provide legal counsel on preservation of evidence and attorney-client privilege, which directly influences containment and eradication actions. Engaging this internal team early prevents costly penalties and legal exposure from mishandled incident response.

Why this answer

Internal escalation typically goes to the incident response team for technical handling and to legal/compliance for regulatory and liability issues. Law enforcement is external, and customers are external as well.

4
Multi-Selecteasy

A security analyst is creating metrics for a security dashboard aimed at executive leadership. Which THREE metrics are most appropriate for this audience? (Select THREE.)

Select 3 answers
A.Phishing simulation click rates
B.Number of security incidents by category
C.Mean time to detect (MTTD)
D.Vulnerability scan details for individual hosts
E.Firewall rule change request logs
AnswersA, B, C

Phishing simulation click rates are a leading indicator of user resilience to social engineering attacks, directly measuring the effectiveness of security awareness training. A high click rate signals elevated human risk, while declining clicks over successive campaigns demonstrate improved workforce behavior. This metric is strategic because it quantifies a primary attack vector—email—and supports data-driven adjustments to training content and cadence.

Why this answer

Executives prefer high-level metrics that show overall security posture, trends, and business impact.

5
MCQmedium

After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?

A.Timeline
B.Lessons learned
C.Root cause
D.Impact assessment
AnswerA

The timeline is the chronological reconstruction of every observable event leading up to, during, and after the security incident. It consolidates artifacts like log entries, file system changes, network flows, and user actions into a coherent sequence. This component is foundational because it enables analysts to map the attack lifecycle and determine the exact order of compromise, which is essential for effective containment and eradication.

Why this answer

The timeline is a critical component that shows the order of events during an incident.

6
Multi-Selecteasy

A cybersecurity analyst is building a compliance dashboard for an upcoming audit. Which TWO metrics are most relevant for demonstrating effective patch management? (Select TWO.)

Select 2 answers
A.Open vulnerability counts by severity
B.Security incidents by category
C.Patch SLA compliance %
D.Mean time to detect (MTTD)
E.Phishing simulation click rates
AnswersA, C

Tracks the number of unresolved vulnerabilities broken down by CVSS severity level (e.g., critical, high, medium, low). This is a core patch-management metric because it directly reflects the current attack-surface exposure and backlog of unpatched systems, which compliance frameworks typically require to be monitored and reduced over time.

Why this answer

Patch SLA compliance % shows adherence to patching timelines, and open vulnerability counts by severity show the current risk posture. Mean time to remediate is also relevant but not listed as an option; here the two best are patch SLA compliance and open vulnerabilities.

7
Multi-Selecthard

A cybersecurity analyst is presenting risk findings to the board of directors. Which THREE types of impact should be emphasized to effectively communicate business risk? (Select THREE.)

Select 3 answers
A.Operational impact
B.Financial impact
C.Technical impact
D.Regulatory penalties
E.Reputational impact
AnswersB, D, E

Financial impact directly quantifies risk in monetary terms, such as lost revenue, incident response costs, or diminished asset value. It is the most universally understood language for executive stakeholders, facilitating prioritization of risk mitigation based on return on investment. Presenting risk as financial exposure enables the board to make informed decisions about risk appetite and resource allocation.

Why this answer

Business risk communication should focus on financial impact, reputational impact, and regulatory penalties as these resonate with business leaders. Technical impact is too detailed.

8
Multi-Selectmedium

A security analyst is preparing an incident report after a ransomware attack. Which two components must be included in the report? (Select TWO.)

Select 2 answers
A.Resume of the incident responder
B.Root cause analysis
C.Marketing department's budget
D.Timeline of the incident
E.Software license keys
AnswersB, D

Root cause analysis identifies the fundamental vulnerability or error that enabled the incident, forming the basis for remediation and preventive measures. An incident report is incomplete without it because understanding what went wrong is critical to preventing recurrence and fulfilling regulatory and organizational requirements.

Why this answer

An incident report should include a timeline of events, impact assessment, root cause, lessons learned, and recommendations. Timeline and root cause are essential.

9
MCQmedium

During a security incident, which of the following should be the FIRST communication to internal stakeholders?

A.Notification to law enforcement
B.Press release to customers
C.Update to the risk register
D.Internal escalation to the incident response team
AnswerD

This is the correct first step because incident response plans conventionally begin with detection and internal escalation, notifying personnel with the authority and expertise to manage the event. The IR team will lead subsequent actions such as containment, eradication, and recovery, and will serve as the central coordinator for all internal and external communications. Any other action—whether external notification, public statements, or documentation—must be authorized through this escalation path to maintain control and legal defensibility.

Why this answer

Internal escalation procedures dictate notifying the incident response team and relevant management first.

10
MCQhard

Which type of threat intelligence report is most appropriate for communicating long-term trends and strategic risks to senior executives?

A.Technical intelligence
B.Tactical intelligence
C.Operational intelligence
D.Strategic intelligence
AnswerD

Strategic intelligence reports synthesize the threat landscape, adversary motivations, and emerging trends into high-level analysis that executives can use to align cybersecurity with business objectives. They communicate risk in terms of financial impact, reputational damage, and regulatory exposure, with recommendations for security investments and policy direction. This is the correct type because it is tailored for executive decision-making, which requires clarity on overall risk posture rather than technical detail.

Why this answer

Strategic intelligence reports provide high-level analysis of threats, trends, and risks for decision-makers.

11
Multi-Selectmedium

An organization is preparing evidence for an audit of access controls. Which THREE types of evidence should be collected? (Select THREE.)

Select 3 answers
A.Network flow data
B.Access review documentation
C.Vulnerability scan reports
D.Log exports of user access events
E.Incident response reports
AnswersB, C, D

This is the strongest evidence because it demonstrates a formal, recurring process where managers or data owners explicitly certify which users have access to which systems and data, and whether that access remains appropriate. It shows that the organization systematically validates least privilege, detects orphaned accounts, and documents corrective actions after each review cycle. Auditors expect to see these review records to prove that access rights are not just assigned but continuously governed.

Why this answer

Audit evidence for access controls includes log exports (showing access events), access reviews (certifying user permissions), and vulnerability scan reports (identifying misconfigurations). Incident reports are not directly relevant.

12
Multi-Selectmedium

A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)

Select 2 answers
A.Root cause
B.Timeline
C.Budget forecast
D.Employee performance review
E.Marketing analysis
AnswersA, B

Root cause analysis identifies the fundamental underlying reason for the security incident, such as an unpatched vulnerability, misconfigured firewall rule, or successful phishing campaign. For an incident report, establishing the root cause is critical because it guides remediation efforts and prevents recurrence, and it satisfies regulatory and stakeholder requirements for understanding why the incident occurred. Without a root cause, the report is merely descriptive, not prescriptive.

Why this answer

Root cause and timeline are standard components of incident reports.

13
MCQmedium

After a ransomware incident, the incident report includes lessons learned. Which of the following is the BEST example of a lesson learned?

A.The ransomware encrypted 500 files.
B.The incident started at 2:00 AM.
C.The root cause was a phishing email.
D.Implement multi-factor authentication for remote access to reduce risk.
AnswerD

This is a concrete, actionable recommendation that directly addresses a common attack vector used in ransomware incidents, such as compromised VPN credentials. It specifies the control (MFA), the scope (remote access), and the goal (risk reduction), making it a proper lesson learned. Unlike observations or causes, it provides a clear implementation step that stakeholders can act on to harden their environment.

Why this answer

Lessons learned should be actionable recommendations to prevent recurrence.

14
Multi-Selecthard

An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)

Select 3 answers
A.Notify all affected data subjects without undue delay if high risk
B.Document the breach and remediation actions
C.Publish a public notice in the local newspaper
D.Notify law enforcement within 24 hours
E.Notify the supervisory authority within 72 hours
AnswersA, B, E

GDPR Article 34 mandates that data controllers must notify affected data subjects without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms. This direct communication enables individuals to take necessary precautions to mitigate potential harm, such as identity theft or financial fraud. The 'without undue delay' clause emphasizes the urgency of informing those directly impacted by the breach.

Why this answer

GDPR requires notification to the supervisory authority within 72 hours, documentation of the breach, and notification to affected individuals if high risk.

15
Multi-Selectmedium

A security analyst is preparing a compliance report for an upcoming audit. The auditor has requested evidence of access controls. Which TWO of the following would provide appropriate evidence? (Select TWO.)

Select 2 answers
A.Recent access review reports
B.A network topology diagram
C.User account audit logs showing privilege changes
D.A list of all employees
E.The company's password policy
AnswersA, C

Access review reports are a direct artifact of an identity governance process, showing that the organization periodically re-certifies user entitlements against current roles and business need. Because the reports are generated from actual access decisions and reviews, they demonstrate that the access-control control is operating as intended, which is exactly the type of evidence a compliance auditor expects to see.

Why this answer

Access review reports and user account audit logs directly demonstrate access control implementation.

16
MCQeasy

Which metric measures the average time it takes for an organization to identify a security incident from the moment it occurs?

A.Mean Time to Resolve (MTTR)
B.Patch SLA compliance percentage
C.Mean Time to Remediate (MTTRem)
D.Mean Time to Detect (MTTD)
AnswerD

Mean Time to Detect (MTTD) is the correct metric, as it measures the average elapsed time between the initial occurrence of a security incident—such as an intrusion or malware compromise—and the moment it is identified by monitoring tools or security personnel. Shorter MTTD directly reduces attacker dwell time and potential damage. This metric is specifically designed to gauge the speed and effectiveness of an organization's detection capabilities.

Why this answer

Mean Time to Detect (MTTD) is the average time to detect an incident.

17
Multi-Selectmedium

A security analyst is preparing a vulnerability report for management. Which TWO elements should be included in the executive summary? (Select TWO.)

Select 2 answers
A.Raw CVSS scores for all vulnerabilities
B.Detailed technical description of each vulnerability
C.Network topology diagrams
D.Overall risk posture summary
E.Key findings that require management attention
AnswersD, E

An overall risk posture summary aggregates findings into a concise, qualitative rating—such as high/medium/low—or a weighted risk score that reflects the organization's relative exposure. This gives management a rapid understanding of whether immediate attention is required and how the current risk compares to prior assessments or industry benchmarks. It directly enables informed, risk-based decisions about prioritizing remediation efforts and allocating resources.

Why this answer

The executive summary should provide a high-level overview, including the overall risk posture and key findings that require management attention. Detailed technical descriptions are better left for the main body.

18
Multi-Selecthard

After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)

Select 3 answers
A.Place legal holds on relevant data
B.Delete all logs to prevent data leakage
C.Publish details on social media immediately
D.Coordinate with law enforcement
E.Notify affected customers as required by law
AnswersA, D, E

Placing a legal hold on relevant data is a legally binding directive that suspends all normal deletion, rotation, and destruction policies for potentially relevant information. In a ransomware incident, this preserves logs, endpoint artifacts, and backup copies, ensuring a complete forensic record for litigation or regulatory investigation. Without a legal hold, automated processes such as log rotation or archive purging could destroy evidence, leading to spoliation sanctions and undermining the ability to prove the scope of the breach.

Why this answer

Customer notification, law enforcement coordination, and legal holds are key communication steps during incidents.

19
MCQhard

An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?

A.48 hours
B.7 days
C.24 hours
D.72 hours
AnswerD

GDPR Article 33(1) mandates that a data controller notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours" after becoming aware of it. This 72-hour window is the exact compliance threshold explicitly written into the regulation, and failing to meet it without documented justification is a violation. The notification must include the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed to mitigate harm.

Why this answer

GDPR Article 33 requires notification within 72 hours of becoming aware of a personal data breach.

20
Multi-Selectmedium

A security analyst is selecting Key Performance Indicators (KPIs) for a security operations dashboard. Which THREE metrics are most relevant for measuring incident response effectiveness? (Select THREE.)

Select 3 answers
A.Number of employees
B.Mean time to detect (MTTD)
C.Mean time to remediate (MTTRem)
D.Revenue growth
E.Mean time to respond (MTTR)
AnswersB, C, E

Mean time to detect measures the average duration between when an incident or attack first occurs and when the security team actually becomes aware of it. A lower MTTD indicates stronger monitoring, alerting, and threat-hunting capabilities, allowing the organization to minimize the window in which attackers can operate undetected. It is specifically focused on the detection phase of the incident response lifecycle.

Why this answer

MTTR measures response time, MTTD measures detection time, and MTTRem measures remediation time. These are key incident response metrics.

21
Multi-Selecthard

A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)

Select 3 answers
A.Employee training attendance records
B.Access review documentation
C.Log exports from critical systems
D.Vulnerability scan reports
E.Marketing brochures
AnswersB, C, D

Access review documentation is primary audit evidence because it shows a periodic recertification of user entitlements against role definitions, least privilege, and separation of duties. It provides an auditable trail of who reviewed critical systems, what discrepancies were detected, and how they were remediated, directly satisfying access control compliance requirements. Auditors frequently cite missing or outdated access reviews as a material finding, so this documentation is a cornerstone of evidence collection.

Why this answer

Auditors typically require log exports, vulnerability scan reports, and access reviews to verify controls.

22
MCQhard

A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?

A.Provide a list of all current vulnerabilities
B.Present the CVSS score and affected systems
C.Describe the potential financial loss, reputational damage, and regulatory fines
D.Explain the technical details of the exploit chain
AnswerC

Describing potential financial loss, reputational damage, and regulatory fines directly maps the risk onto the board's fiduciary duties, giving them the essential information needed for risk tolerance and resource allocation. This approach quantifies or estimates impact in the same units executives use to evaluate business decisions, such as ERM frameworks and insurance. It lets the CISO argue for security investment as a business trade-off, which is the only frame that produces meaningful discussion and sign-off.

Why this answer

Translating technical risk to business impact (financial, reputational, regulatory) is key for non-technical stakeholders.

23
Multi-Selecthard

An organization is preparing for a compliance audit. Which TWO of the following are essential pieces of evidence to demonstrate effective vulnerability management?

Select 2 answers
A.Network topology diagrams
B.Employee training logs
C.Vulnerability scan reports
D.Patch management reports
E.Incident response playbooks
AnswersC, D

Vulnerability scan reports are the primary evidence that an organization is actively discovering weaknesses, as they contain the scan timestamp, authenticated or unauthenticated scan type, CVEs, and CVSS severity scores. They allow auditors to correlate the identified vulnerabilities against the organization's asset inventory and check that coverage includes critical systems. A series of scan reports demonstrates the continuous, recurring nature of the program, which is a core requirement of many compliance frameworks.

Why this answer

Vulnerability scan reports show identified vulnerabilities, and patch management reports show remediation efforts, together demonstrating the vulnerability management lifecycle.

24
MCQhard

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the supervisory authority?

A.24 hours
B.7 days
C.48 hours
D.72 hours
AnswerD

The General Data Protection Regulation (GDPR), specifically Article 33, explicitly mandates that organizations must notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it." This precise timeframe is crucial for enabling authorities to promptly assess the breach's impact and for organizations to initiate appropriate mitigation actions and fulfill their accountability obligations.

Why this answer

GDPR Article 33 requires that data breaches be reported to the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

25
MCQhard

A security analyst needs to present the risk of an unpatched critical vulnerability to the board of directors. Which of the following is the most effective way to communicate the risk?

A.Explain the potential financial loss and reputational damage.
B.Show the CVSS score and exploit complexity.
C.Recommend immediate patching without details.
D.Describe the vulnerability in technical terms.
AnswerA

Quantifying the unpatched vulnerability in terms of potential financial loss—such as breach response costs, regulatory fines, or lost revenue from downtime—and reputational damage, like customer churn or erosion of brand trust, directly aligns the technical risk with the board's fiduciary responsibilities. This translation reassures executives that their decision allocates resources to protect shareholder value and market standing, not just IT infrastructure.

Why this answer

Boards care about business impact, not technical details. Quantifying financial exposure helps them understand urgency.

26
MCQmedium

Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?

A.72 hours
B.7 days
C.24 hours
D.48 hours
AnswerA

GDPR Article 33(1) sets a hard, maximum deadline of 72 hours after the controller becomes aware of a personal data breach for notifying the supervisory authority, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The obligation is phrased as 'without undue delay and, where feasible, not later than 72 hours,' meaning 72 hours is the outer statutory limit, not a target. If notification is made after 72 hours, the controller must provide the reasons for the delay under Article 33(5). Thus, 72 hours is the correct and canonical compliance reporting requirement.

Why this answer

GDPR Article 33 requires notification to the supervisory authority within 72 hours of awareness.

27
MCQeasy

Which of the following metrics measures the average time it takes to identify a security incident after it occurs?

A.Patch SLA compliance percentage
B.Mean time to remediate (MTTRem)
C.Mean time to respond (MTTR)
D.Mean time to detect (MTTD)
AnswerD

Mean time to detect (MTTD) is the average elapsed time between the actual occurrence of a security incident or malicious activity and the moment it is recognized or flagged as suspicious by telemetry, analytics, or an analyst. It is the definitive metric for measuring detection velocity, because it captures the so-called "dwell time" before discovery, where the adversary may be operating unnoticed. Lower MTTD directly reduces the opportunity for attackers to achieve their objectives by limiting the window of undetected access.

Why this answer

MTTD is specifically defined as the average time to detect an incident.

28
MCQmedium

During a security incident involving a potential data breach, the CISO asks you to prepare a communication for the board of directors. What is the MOST important aspect to emphasize in this communication?

A.The specific malware used and its technical attributes
B.The names of the IT staff who first detected the incident
C.A step-by-step timeline of the incident response actions taken so far
D.The financial impact, reputational risk, and potential regulatory penalties
AnswerD

For a board of directors, information regarding the financial impact, potential reputational damage, and regulatory penalties is paramount because these directly relate to their fiduciary duties and the long-term strategic health of the organization. Understanding the monetary losses, the erosion of public trust, and the legal ramifications enables the board to assess the overall business risk effectively. This critical information guides their strategic decisions on resource allocation, risk mitigation strategies, and governance improvements to protect shareholder value and ensure compliance.

Why this answer

Board members are non-technical stakeholders who need to understand the business impact. The communication should translate technical details into financial, reputational, and regulatory consequences.

29
Multi-Selectmedium

Which three metrics are commonly used to measure the effectiveness of a security operations center (SOC)? (Select THREE.)

Select 3 answers
A.Number of firewall rules
B.Number of employees in the SOC
C.Mean Time to Respond (MTTR)
D.Mean Time to Remediate (MTTRem)
E.Mean Time to Detect (MTTD)
AnswersC, D, E

Mean Time to Respond (MTTR) quantifies how quickly a SOC team takes action to contain an incident after detection. It typically measures the interval between alert triage and the first mitigation step (e.g., isolating a host, blocking a C2 domain), directly reflecting the team's readiness and playbook efficiency. Lower MTTR indicates faster containment, which reduces the attacker's dwell time and prevents lateral movement.

Why this answer

MTTD, MTTR, and MTTRem are standard SOC metrics to measure detection and response effectiveness.

30
MCQmedium

An incident report includes a section that details the sequence of events from initial compromise to containment. Which component of the incident report does this describe?

A.Impact assessment
B.Root cause
C.Lessons learned
D.Timeline
AnswerD

A timeline is a chronological, time-stamped listing of events, actions, observations, and findings that occurred during an incident. It is a foundational component of incident documentation because it establishes the order and timing of events, supporting correlation of security events and response actions. In an incident report, the section 'detailing the sequence' directly maps to the timeline's purpose of recording events in sequence.

Why this answer

The timeline component chronologically documents the incident's progression.

31
MCQeasy

Which of the following is the primary audience for a strategic threat intelligence report?

A.System administrators
B.SOC analysts
C.Executive leadership
D.Incident responders
AnswerC

Executive leadership is the primary audience for strategic intelligence because it informs high-level decisions about risk tolerance, resource allocation, and business continuity. This type of intelligence is written in non-technical language, summarizing geopolitical threats, industry-level trends, and potential impacts to the enterprise in a way that supports governance and investment choices. It helps the C-suite align cybersecurity with organizational objectives, not with day-to-day tactics.

Why this answer

Strategic intelligence is high-level and intended for executive leadership to inform business decisions.

32
Multi-Selectmedium

An analyst is preparing a vulnerability report for management. Which THREE sections should be included to effectively communicate findings and remediation? (Select THREE.)

Select 3 answers
A.Executive summary
B.Incident response procedures
C.Network topology diagram
D.Findings by severity
E.Remediation timeline
AnswersA, D, E

The executive summary is the most critical section for management because it distills the entire vulnerability assessment into a concise, high-level overview of the organization's risk posture. It should highlight the total number of vulnerabilities, the most severe threats, and the recommended strategic actions without overwhelming readers with technical CVSS vectors or exploit details. Management needs this to make informed decisions on resource allocation and risk acceptance, making it a mandatory component of any vulnerability report.

Why this answer

A vulnerability report typically includes an executive summary for leadership, findings by severity to prioritize, and a remediation timeline for action. Risk acceptance may be part of findings but not always a separate section; here the three essential sections are those listed.

33
MCQmedium

An analyst is creating a compliance dashboard for management. Which of the following is the most relevant metric to include regarding patch management?

A.Number of antivirus alerts
B.Phishing simulation click rate
C.Mean time to detect incidents
D.Patch SLA compliance %
AnswerD

Patch SLA compliance percentage directly measures whether systems are being patched within the timeframes the organization has committed to, for example critical patches within 14 days, which is precisely what a management-facing compliance dashboard needs to show for the patch management program. It ties directly to the process being audited rather than to an adjacent security function.

Why this answer

Patch SLA compliance percentage directly measures how well the organization meets patch deadlines, which is a key compliance metric.

34
MCQmedium

During an incident response, the SOC team identifies a data breach involving customer PII. Under GDPR, what is the maximum time frame to notify the supervisory authority?

A.96 hours
B.72 hours
C.24 hours
D.48 hours
AnswerB

72 hours is the correct timeframe under GDPR Article 33(1), which states that a data breach notification must be made to the competent supervisory authority 'without undue delay' and, where feasible, no later than 72 hours after the controller becomes aware of the breach. This period is a fixed regulatory deadline, and failure to meet it without a documented justification (e.g., complexity of investigation) can result in significant administrative fines.

Why this answer

GDPR Article 33 requires notification within 72 hours of becoming aware of a personal data breach.

35
Multi-Selecthard

A security analyst is creating a compliance dashboard for a PCI DSS audit. Which THREE metrics should be included to demonstrate compliance with access control requirements? (Select THREE.)

Select 3 answers
A.Number of failed login attempts in the last 24 hours
B.Number of critical vulnerabilities in network devices
C.Number of active user accounts with privileged access
D.Percentage of accounts that have been inactive for more than 90 days
E.Percentage of accounts that have undergone access review in the last quarter
AnswersC, D, E

The number of active user accounts with privileged access is a direct measure of the privileged access attack surface and is explicitly required to be tracked by many compliance frameworks. For instance, PCI DSS Requirement 10.8 mandates logging and monitoring of access to privileged accounts, and knowing the exact count is essential for access recertification and segregation of duties. This metric enables auditors to verify that privileged access is controlled, monitored, and limited to authorized personnel.

Why this answer

PCI DSS requires strict access controls, including unique IDs, timely deactivation, and periodic reviews. Failed login attempts and vulnerability scan results are not direct access control metrics.

36
Multi-Selectmedium

A security analyst needs to provide threat intelligence to different audiences. Which TWO of the following are appropriate dissemination approaches?

Select 2 answers
A.Sending tactical intelligence with IoCs to the SOC team
B.Publishing operational intelligence on the company intranet
C.Discussing classified threat data in public forums
D.Sharing raw intelligence feeds with all employees
E.Providing strategic intelligence reports to executives
AnswersA, E

Tactical intelligence is time-sensitive, actionable data that directly supports day-to-day security operations. SOC teams require IoCs—such as malicious IPs, file hashes, and domain names—to detect and block immediate threats. By pushing this information to the SOC, analysts can operationalize it and update detection rules, SIEM queries, and EDR configurations in real time.

Why this answer

Strategic intelligence for executives helps them understand the threat landscape, while tactical intelligence for SOC teams provides IoCs for detection.

37
MCQeasy

Which of the following best describes the purpose of a threat intelligence report at the operational level?

A.Offer detailed analysis of threat actor TTPs for specific campaigns
B.Deliver technical indicators like IoCs to SOC analysts
C.Provide high-level trends to executive leadership
D.Summarize geopolitical risks affecting the organization
AnswerA

Operational intelligence is the level of threat intelligence that examines threat actor TTPs (tactics, techniques, and procedures) within the context of a specific campaign or intrusion set. Unlike raw indicators, it provides defenders with the behavioral playbook of an adversary—such as initial access vectors, lateral movement methods, and command-and-control patterns—enabling proactive threat hunting, detection engineering, and tailored mitigation strategies. This type of analysis directly informs defensive actions by revealing not just what to block, but how to anticipate and disrupt an adversary's next move.

Why this answer

Operational intelligence focuses on specific campaigns, tools, and techniques to inform defenders' actions.

38
Multi-Selecthard

A threat intelligence analyst has produced a report containing specific Indicators of Compromise (IoCs) such as IP addresses, domain names, and file hashes. Which TWO audiences are most appropriate for this type of intelligence? (Select TWO.)

Select 2 answers
A.Board of directors
B.SOC analysts
C.Executive leadership
D.Incident responders
E.Network engineers
AnswersB, D

SOC analysts are the primary consumers for a report consisting of technical IoCs, as they operationalize these indicators into detection logic such as SIEM signatures and alert rules. The report should be structured to support correlation with telemetry, enabling prioritization and investigation of matching events. For the SOC, IoCs serve as the foundational input for proactive threat detection and ongoing security monitoring.

Why this answer

Tactical intelligence (IoCs) is most useful for the SOC team and incident responders who can use them for detection and response. Executives need strategic intelligence, and network engineers need operational intelligence.

39
Multi-Selectmedium

An incident responder is documenting the root cause of a data breach. Which THREE components are essential to include in the root cause analysis section of the incident report? (Select THREE.)

Select 3 answers
A.The technical vulnerability exploited
B.The number of records affected
C.The name of the employee who clicked the phishing email
D.Human factors, such as lack of training
E.Process failures that allowed the vulnerability to exist
AnswersA, D, E

Documenting the technical vulnerability exploited is central to root cause analysis because it identifies the specific weakness—such as an unpatched CVE, SQL injection, or misconfigured S3 bucket—that allowed the initial compromise. Without this technical detail, the response team cannot prescribe a targeted fix (e.g., patch, configuration change, or WAF rule) to prevent recurrence. The root cause is inseparable from the exact flaw that made the attack viable.

Why this answer

Root cause analysis should identify the underlying causes, not just the symptoms. It should include the technical failure, the process failure, and the human or organizational factors that contributed.

Ready to test yourself?

Try a timed practice session using only Reporting and Communication questions.