Courseiva

CCNA Reporting and Communication Questions

75 of 83 questions · Page 1/2 · Reporting and Communication · Answers revealed

1
MCQhard

An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?

A.A screenshot of the control configuration
B.A policy document describing the control
C.A control effectiveness report with test results and metrics
D.An email from the system owner stating the control is working
AnswerC

A control effectiveness report supplies measured test results and metrics, giving auditors objective proof that the control operates as intended rather than merely existing. This directly satisfies the stem's requirement to demonstrate effectiveness, since design documentation or policy statements alone cannot evidence actual performance.

Why this answer

A control effectiveness report with test results and metrics provides objective, measurable evidence that the control actually works as intended, which is what auditors require. Configuration screenshots and policy documents only show intent or design, not operational effectiveness.

Exam trap

CS0-004 often tests the difference between design evidence (policies, screenshots) and operating effectiveness evidence (test results, metrics), tempting candidates to pick a configuration screenshot because it 'shows' the control.

How to eliminate wrong answers

Option A is wrong because a screenshot of the configuration shows the control was set up but not that it functions correctly or is enforced over time. Option B is wrong because a policy document describes what should be done, which is design evidence, not proof of operating effectiveness. Option D is wrong because an email assertion from the system owner is subjective, unverified, and lacks the test data auditors need to conclude the control is effective.

2
MCQmedium

A company experiences a data breach involving personal data of EU citizens. Under GDPR, what is the maximum time frame to notify the supervisory authority?

A.7 days
B.24 hours
C.48 hours
D.72 hours
AnswerD

Under Article 33 of the GDPR, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is delayed beyond this window, the controller must provide a reasoned justification for the delay.

Why this answer

GDPR Article 33 requires notification within 72 hours of becoming aware of a breach.

3
MCQmedium

Which of the following BEST describes the purpose of a risk register in the context of reporting and communication?

A.To document vulnerabilities found during scans
B.To record all security incidents and their outcomes
C.To list compliance requirements and deadlines
D.To provide a structured way to track identified risks, their likelihood, impact, and mitigation actions
AnswerD

A risk register is the central governance artifact that catalogs identified risks alongside their likelihood, potential impact, assigned owner, and planned or in-progress mitigation actions, giving leadership a consistent, prioritized view for reporting and decision-making across the organization's entire risk landscape rather than any single risk source.

Why this answer

A risk register is a central document that captures identified risks, their assessments, mitigation plans, and status. It supports ongoing risk management and communication to stakeholders.

4
MCQeasy

Which metric would best indicate the effectiveness of an organization's patch management program?

A.Phishing simulation click rates
B.Open vulnerability counts by severity
C.Mean time to detect (MTTD)
D.Patch SLA compliance percentage
AnswerD

Patch SLA compliance percentage directly measures the proportion of patches applied within the stipulated timeframes, such as critical patches within 48 hours or high-severity within 30 days. It quantifies adherence to the patching policy and reflects the organization's ability to remediate known vulnerabilities on schedule. This is the most relevant benchmark because it captures timeliness, completeness, and scheduling discipline, which are the core factors of patch management effectiveness.

Why this answer

Patch SLA compliance percentage directly measures whether patches were applied within the organization's defined remediation windows (for example, critical patches within 14 days), which is the clearest indicator that the patch management program is working as designed. It ties patch deployment outcomes to policy requirements, making it the most direct effectiveness metric.

Exam trap

CS0-004 often tests the difference between metrics that measure patch program execution (SLA compliance) versus adjacent security metrics (MTTD, phishing click rate, vulnerability counts), so candidates who equate 'fewer vulnerabilities' with 'effective patching' choose the wrong answer.

How to eliminate wrong answers

Option A is wrong because phishing simulation click rates measure security awareness training effectiveness, not patch deployment. Option B is wrong because open vulnerability counts by severity show exposure but not whether the patch program is meeting its remediation timelines — counts can rise from new discoveries even when patching is effective. Option C is wrong because MTTD measures detection speed in incident response, not patch management performance.

5
MCQmedium

A phishing simulation is conducted, and the click rate is reported to management. What does a high click rate indicate?

A.Employees are well-trained in security
B.The phishing simulation was not realistic
C.The organization has strong technical controls
D.There is a need for more security awareness training
AnswerD

A high click rate during a phishing exercise serves as a key performance indicator (KPI) that employees are highly susceptible to social engineering attacks. To mitigate this risk, the organization must implement targeted, frequent security awareness training and follow-up simulations to educate users on identifying phishing indicators, thereby strengthening the human element of defense-in-depth.

Why this answer

A high click rate suggests that employees are susceptible to phishing, indicating a need for security awareness training.

6
MCQhard

An analyst is evaluating the performance of the security operations center (SOC). Which metric best indicates the team's ability to contain an active threat?

A.Mean time to detect (MTTD)
B.Patch SLA compliance %
C.Mean time to respond (MTTR)
D.Open vulnerability counts by severity
AnswerC

Mean time to respond (MTTR) is the definitive metric for evaluating the speed of incident containment and mitigation. It measures the average time elapsed from the moment an alert is detected to when the threat is successfully isolated or neutralized, directly reflecting SOC operational efficiency during active incidents.

Why this answer

Mean Time to Respond (MTTR) measures the average time taken to contain and remediate an incident, directly reflecting containment speed.

7
Multi-Selectmedium

During a security incident, a cybersecurity analyst must communicate with various stakeholders. Which TWO are appropriate internal escalation paths? (Select TWO.)

Select 2 answers
A.Legal and compliance department
B.Law enforcement
C.Customers
D.Incident response team
E.Media
AnswersA, D

The legal and compliance department is the correct first point of contact because it ensures the organization satisfies statutory and regulatory breach notification obligations (e.g., GDPR, HIPAA, SEC rules) before any public or external disclosure. They also provide legal counsel on preservation of evidence and attorney-client privilege, which directly influences containment and eradication actions. Engaging this internal team early prevents costly penalties and legal exposure from mishandled incident response.

Why this answer

Option A (Legal and compliance department) is correct because internal escalation during a security incident must include legal and compliance so they can assess regulatory notification duties (e.g., GDPR, HIPAA, PCI DSS), preserve legal privilege, and advise on breach disclosure obligations. Option D (Incident response team) is correct because the IR team is the core internal group that triages, contains, eradicates, and recovers from the incident, and it is the primary escalation path for technical and procedural coordination. Option B (Law enforcement) is not an internal path; it is an external authority engaged only when required or appropriate, often after legal review.

Option C (Customers) is external and typically notified only after legal/comms approval, not as an escalation path. Option E (Media) is external and handled through public relations or communications, not an internal escalation route.

Exam trap

CS0-004 often tests the boundary between internal and external stakeholders, tempting candidates to select law enforcement or customers because they are commonly involved in incident response overall.

8
Multi-Selecteasy

A security analyst is creating metrics for a security dashboard aimed at executive leadership. Which THREE metrics are most appropriate for this audience? (Select THREE.)

Select 3 answers
A.Phishing simulation click rates
B.Number of security incidents by category
C.Mean time to detect (MTTD)
D.Vulnerability scan details for individual hosts
E.Firewall rule change request logs
AnswersA, B, C

Phishing simulation click rates are a leading indicator of user resilience to social engineering attacks, directly measuring the effectiveness of security awareness training. A high click rate signals elevated human risk, while declining clicks over successive campaigns demonstrate improved workforce behavior. This metric is strategic because it quantifies a primary attack vector—email—and supports data-driven adjustments to training content and cadence.

Why this answer

Phishing simulation click rates (A) are appropriate because they express human-risk exposure as a simple percentage that executives can trend over time to judge the effectiveness of security awareness training. Number of security incidents by category (B) is right because it gives leadership a business-level view of what kinds of threats are materializing and where to direct risk-reduction investment. Mean time to detect (C) is right because it is a key operational KPI showing how quickly the security program identifies threats, which executives use to assess detection capability and response readiness.

The unmarked options do not belong: vulnerability scan details for individual hosts (D) are too granular and technical for an executive dashboard, and firewall rule change request logs (E) are operational change-management records rather than strategic risk metrics.

Exam trap

CS0-004 often tests audience-appropriate metrics — candidates pick detailed operational data (per-host vulns, firewall logs) because it is 'more security data,' but executives need aggregated, trend-based, business-relevant metrics.

9
MCQmedium

After a security incident, which component of the incident report provides a chronological sequence of events from detection to recovery?

A.Timeline
B.Lessons learned
C.Root cause
D.Impact assessment
AnswerA

The timeline is the chronological reconstruction of every observable event leading up to, during, and after the security incident. It consolidates artifacts like log entries, file system changes, network flows, and user actions into a coherent sequence. This component is foundational because it enables analysts to map the attack lifecycle and determine the exact order of compromise, which is essential for effective containment and eradication.

Why this answer

The Timeline section of an incident report presents a chronological sequence of events — detection, containment, eradication, recovery — with timestamps. It is specifically designed to reconstruct what happened and when, which is exactly what the question asks for.

Exam trap

CS0-004 often tests the confusion between Timeline (chronological sequence) and Root Cause (underlying cause) — candidates pick Root Cause because it sounds more analytical, but the question specifically asks for a chronological sequence.

How to eliminate wrong answers

Option B is wrong because Lessons Learned captures what went well, what didn't, and recommendations for improvement — it is forward-looking, not a chronological record. Option C is wrong because Root Cause identifies the underlying cause of the incident, not the sequence of events. Option D is wrong because Impact Assessment quantifies the scope, cost, and affected systems/users, not the timeline of events.

10
MCQeasy

Which metric is commonly used to measure the average time it takes to identify that a security incident has occurred?

A.MTTD (Mean Time to Detect)
B.MTTRem (Mean Time to Remediate)
C.MTTR (Mean Time to Respond)
D.Patch SLA Compliance %
AnswerA

Mean Time to Detect (MTTD) is the key security metric that quantifies the average duration between the initial occurrence of a security incident or compromise and its formal identification by security tools or analysts. Minimizing MTTD is critical for reducing attacker dwell time and limiting the potential blast radius of an intrusion.

Why this answer

Mean Time to Detect (MTTD) measures the average time between the start of an incident and its detection. It is a key metric for evaluating the effectiveness of monitoring and detection capabilities.

11
MCQeasy

After a phishing simulation, the security team wants to report the results to management. Which metric is most appropriate to include in the report?

A.Total number of employees
B.Number of phishing emails blocked at the gateway
C.Mean time to detect phishing emails
D.Phishing simulation click rate
AnswerD

The click rate is the primary metric for assessing user susceptibility during a controlled simulation, calculated by dividing the number of users who clicked the link by the total number of emails delivered. This directly measures the effectiveness of security awareness training and identifies high-risk groups requiring targeted remediation.

Why this answer

Phishing simulation click rate measures the percentage of users who clicked a simulated phishing link, a key metric for security awareness.

12
Multi-Selecteasy

A cybersecurity analyst is building a compliance dashboard for an upcoming audit. Which TWO metrics are most relevant for demonstrating effective patch management? (Select TWO.)

Select 2 answers
A.Open vulnerability counts by severity
B.Security incidents by category
C.Patch SLA compliance %
D.Mean time to detect (MTTD)
E.Phishing simulation click rates
AnswersA, C

Tracks the number of unresolved vulnerabilities broken down by CVSS severity level (e.g., critical, high, medium, low). This is a core patch-management metric because it directly reflects the current attack-surface exposure and backlog of unpatched systems, which compliance frameworks typically require to be monitored and reduced over time.

Why this answer

Option A (Open vulnerability counts by severity) is correct because it directly reflects the backlog of unpatched exposures, and breaking it down by severity (critical/high/medium/low) shows whether the most dangerous CVEs are being remediated promptly, which is a core evidence point for patch management effectiveness. Option C (Patch SLA compliance %) is correct because it measures the percentage of patches applied within the organization's defined remediation timeframes (e.g., critical within 7 days, high within 30 days), directly demonstrating the discipline and performance of the patch management process. Option B (Security incidents by category) is not specific to patching—it describes overall incident trends and could stem from phishing, misconfiguration, or insider activity rather than patch status.

Option D (Mean time to detect) measures detection capability (SOC/monitoring efficiency), not remediation of vulnerabilities. Option E (Phishing simulation click rates) is a security awareness metric and has no direct bearing on patch management.

Exam trap

CS0-004 often tests whether candidates can distinguish patch management metrics (open vulns, SLA compliance) from adjacent security metrics (MTTD, phishing click rate, incident categories) that sound security-related but measure different programs.

13
Multi-Selecthard

A cybersecurity analyst is presenting risk findings to the board of directors. Which THREE types of impact should be emphasized to effectively communicate business risk? (Select THREE.)

Select 3 answers
A.Operational impact
B.Financial impact
C.Technical impact
D.Regulatory penalties
E.Reputational impact
AnswersB, D, E

Financial impact directly quantifies risk in monetary terms, such as lost revenue, incident response costs, or diminished asset value. It is the most universally understood language for executive stakeholders, facilitating prioritization of risk mitigation based on return on investment. Presenting risk as financial exposure enables the board to make informed decisions about risk appetite and resource allocation.

Why this answer

Business risk communication should focus on financial impact, reputational impact, and regulatory penalties as these resonate with business leaders. Technical impact is too detailed.

14
MCQmedium

During a security incident, a CySA+ analyst needs to communicate the status to the CISO. Which type of report is most appropriate for this purpose?

A.Technical report with packet captures
B.Executive dashboard
C.Vulnerability scan report
D.Threat intelligence feed
AnswerB

An executive dashboard aggregates complex security metrics into high-level, visual, and actionable insights tailored for non-technical stakeholders. During an active incident, this format allows leadership to quickly grasp the overall business risk, containment status, and resource allocation needs without getting bogged down in technical minutiae.

Why this answer

An executive dashboard provides a high-level, real-time view of key metrics and incident status suitable for executive communication.

15
MCQeasy

Which of the following is the best example of a Key Performance Indicator (KPI) for patch management?

A.Patch SLA compliance percentage
B.Mean time to detect vulnerabilities
C.Number of security incidents
D.Number of vulnerabilities discovered
AnswerA

This metric directly measures the effectiveness and efficiency of the patch management process by tracking the percentage of vulnerabilities remediated within established Service Level Agreement (SLA) windows. It provides actionable insight into operational performance and compliance, making it an ideal Key Performance Indicator (KPI) for patch management.

Why this answer

Patch SLA compliance percentage measures how often patches are applied within the agreed timeline, a key performance indicator.

16
MCQmedium

A security analyst must present a risk assessment to the board of directors. Which approach is most effective for communicating technical risks?

A.Focus solely on CVSS scores
B.Provide raw log data
C.Translate technical risk into business impact
D.Use technical jargon to demonstrate expertise
AnswerC

Board members operate on strategic risk management, financial exposure, and regulatory compliance. Translating technical vulnerabilities into business impacts—such as potential downtime, reputational damage, or compliance penalties—enables executives to make informed decisions regarding risk acceptance, mitigation budgets, and strategic alignment.

Why this answer

Translating technical risks into business impact (e.g., financial, reputational) helps non-technical stakeholders understand and prioritize risks.

17
MCQmedium

During a compliance audit, the auditor requests evidence of access reviews. Which of the following would be the MOST appropriate evidence to provide?

A.Vulnerability scan reports
B.A list of all user accounts and their creation dates
C.Completed access review sign-off sheets with manager approvals
D.Logs of successful and failed login attempts
AnswerC

Completed sign-off sheets with formal manager approvals serve as definitive administrative evidence for compliance frameworks like SOC 2 or ISO 27001. This documentation explicitly proves that authorized personnel reviewed user privileges, validated the principle of least privilege, and formally authorized the continuation or revocation of access.

Why this answer

Access review documentation, such as sign-off sheets or reports showing review and approval of user access rights, directly demonstrates that periodic access reviews are conducted.

18
Multi-Selectmedium

A security analyst is preparing an incident report after a ransomware attack. Which two components must be included in the report? (Select TWO.)

Select 2 answers
A.Resume of the incident responder
B.Root cause analysis
C.Marketing department's budget
D.Timeline of the incident
E.Software license keys
AnswersB, D

Root cause analysis identifies the fundamental vulnerability or error that enabled the incident, forming the basis for remediation and preventive measures. An incident report is incomplete without it because understanding what went wrong is critical to preventing recurrence and fulfilling regulatory and organizational requirements.

Why this answer

Option B (Root cause analysis) is correct because an incident report must document how the ransomware gained initial access and spread, identifying the underlying vulnerability, misconfiguration, or human factor so that remediation and preventive controls can be applied. Option D (Timeline of the incident) is correct because a chronological record of detection, containment, eradication, and recovery events is essential for understanding the attack's progression, supporting forensic findings, and meeting compliance or legal reporting requirements. The remaining options do not belong: a responder's resume (A) is irrelevant personal information, the marketing department's budget (C) has no bearing on the technical or procedural facts of the incident, and software license keys (E) are sensitive credentials that should never be exposed in a report and are unrelated to documenting the attack.

Exam trap

CS0-004 often tests the inclusion of irrelevant or sensitive items (resumes, license keys, budgets) to see if candidates understand what constitutes a proper incident report.

19
MCQmedium

During a security incident, which of the following should be the FIRST communication to internal stakeholders?

A.Notification to law enforcement
B.Press release to customers
C.Update to the risk register
D.Internal escalation to the incident response team
AnswerD

This is the correct first step because incident response plans conventionally begin with detection and internal escalation, notifying personnel with the authority and expertise to manage the event. The IR team will lead subsequent actions such as containment, eradication, and recovery, and will serve as the central coordinator for all internal and external communications. Any other action—whether external notification, public statements, or documentation—must be authorized through this escalation path to maintain control and legal defensibility.

Why this answer

The first communication during a security incident must be the internal escalation to the incident response team, as this triggers the formal incident response process. The IR team is responsible for assessing the scope, containing the threat, and coordinating all subsequent actions, including any external notifications. Without this initial escalation, no coordinated response can occur, and other communications (legal, PR, risk) would lack the necessary technical context.

This aligns with the preparation and identification phases of the incident response lifecycle (e.g., NIST SP 800-61).

Exam trap

CS0-004 often tests the misconception that external notifications (law enforcement, customers) or documentation tasks (risk register) should occur first, confusing the order of incident response steps with communication priorities.

How to eliminate wrong answers

Option A is wrong because law enforcement notification is typically a later step, often required only for specific types of incidents (e.g., criminal activity, data breaches with legal implications) and should be coordinated through legal counsel after the IR team has assessed the situation. Option B is wrong because a press release to customers is an external communication that must be carefully timed and crafted after internal stakeholders and legal teams have been briefed; issuing it first could cause panic, misinformation, and legal liability. Option C is wrong because updating the risk register is a documentation and risk management activity that occurs after the incident has been assessed and possibly resolved; it is not a communication to internal stakeholders in the immediate sense and does not initiate response actions.

20
MCQhard

Which type of threat intelligence report is most appropriate for communicating long-term trends and strategic risks to senior executives?

A.Technical intelligence
B.Tactical intelligence
C.Operational intelligence
D.Strategic intelligence
AnswerD

Strategic intelligence reports synthesize the threat landscape, adversary motivations, and emerging trends into high-level analysis that executives can use to align cybersecurity with business objectives. They communicate risk in terms of financial impact, reputational damage, and regulatory exposure, with recommendations for security investments and policy direction. This is the correct type because it is tailored for executive decision-making, which requires clarity on overall risk posture rather than technical detail.

Why this answer

Strategic threat intelligence focuses on high-level, long-term trends, adversary motivations, and geopolitical or business risks — exactly what senior executives need for decision-making and risk budgeting. It is typically delivered as reports or briefings rather than raw indicators, and it informs strategic planning over quarters or years. Technical, tactical, and operational intelligence are all more granular and operational in nature.

Exam trap

CS0-004 often tests the audience-to-intelligence-type mapping; candidates confuse operational (imminent campaigns) with strategic (long-term trends) because both sound 'high-level'.

How to eliminate wrong answers

Option A (technical intelligence) is wrong because it deals with indicators of compromise (IOCs), malware signatures, and TTPs at a machine-readable level — useful to SOC analysts, not executives. Option B (tactical intelligence) is wrong because it covers adversary tactics, techniques, and procedures (TTPs) used in the near term to guide defensive countermeasures, which is operational for security teams rather than strategic for leadership. Option C (operational intelligence) is wrong because it concerns specific, imminent campaigns or attacks and is used for short-term operational decisions (e.g., blocking a specific C2 domain), not long-term trend analysis.

21
MCQmedium

A vulnerability report includes a risk acceptance section. Which of the following scenarios is most appropriate to include in this section?

A.A vulnerability that has been exploited in the wild
B.A critical vulnerability that has been patched
C.All open vulnerabilities regardless of severity
D.A medium-severity vulnerability with a compensating control that reduces risk to acceptable levels
AnswerD

This is the textbook risk acceptance scenario because the medium severity keeps residual exposure within a tolerable range, and the compensating control, such as network segmentation or restricted access, provides documented, measurable risk reduction that justifies formally accepting rather than remediating the underlying vulnerability.

Why this answer

Risk acceptance is documented when the organization decides not to remediate a vulnerability due to compensating controls or low risk.

22
MCQeasy

Which component of an incident report describes the sequence of events from detection to resolution?

A.Root cause
B.Impact assessment
C.Lessons learned
D.Timeline
AnswerD

Correct. The timeline is the section of an incident report that chronologically documents every key event, from initial detection through containment, eradication, and recovery, typically with precise timestamps, giving responders and auditors a clear record of how the incident unfolded and how quickly the team reacted.

Why this answer

The timeline (also called the chronology or sequence of events) is the section of an incident report that documents the chronological order of activities from initial detection through containment, eradication, recovery, and closure. It provides a factual, time-stamped record that allows responders and reviewers to reconstruct exactly what happened and when. This is distinct from root cause analysis, which explains why the incident occurred, and from impact assessment, which quantifies the damage or business effect.

Exam trap

CS0-004 often tests the distinction between the 'what/when' (timeline) and the 'why' (root cause) or 'so what' (impact assessment, lessons learned) sections of an incident report, causing candidates to confuse documentation of events with analysis of causes or outcomes.

How to eliminate wrong answers

Option A is wrong because root cause identifies the underlying vulnerability, misconfiguration, or failure that enabled the incident—it answers 'why,' not 'what happened when.' Option B is wrong because impact assessment quantifies the scope, financial cost, data loss, and operational disruption caused by the incident, not the chronological sequence. Option C is wrong because lessons learned captures post-incident recommendations, process improvements, and corrective actions to prevent recurrence, which is forward-looking rather than a historical record of events.

23
Multi-Selectmedium

An organization is preparing evidence for an audit of access controls. Which THREE types of evidence should be collected? (Select THREE.)

Select 3 answers
A.Network flow data
B.Access review documentation
C.Vulnerability scan reports
D.Log exports of user access events
E.Incident response reports
AnswersB, C, D

This is the strongest evidence because it demonstrates a formal, recurring process where managers or data owners explicitly certify which users have access to which systems and data, and whether that access remains appropriate. It shows that the organization systematically validates least privilege, detects orphaned accounts, and documents corrective actions after each review cycle. Auditors expect to see these review records to prove that access rights are not just assigned but continuously governed.

Why this answer

Access review documentation (B) is correct because periodic user access reviews are the primary artifact proving that entitlements are authorized, appropriate, and revoked when no longer needed, directly evidencing access control governance. Vulnerability scan reports (C) are correct because they show whether access-related weaknesses (e.g., missing patches, misconfigurations, default credentials) exist and are being remediated, supporting the audit's assessment of control effectiveness. Log exports of user access events (D) are correct because authentication and authorization logs (e.g., Windows Security event IDs 4624/4625, sudo/syslog entries, cloud trail records) provide the raw, timestamped proof that access controls actually operate as intended.

Network flow data (A) is not selected because flow records (NetFlow/IPFIX) show traffic patterns and volumes, not user identity or authorization decisions, so they do not directly evidence access control. Incident response reports (E) are not selected because they document security incidents and containment actions, which relate to incident management rather than the access control audit evidence requested.

Exam trap

The trap is selecting incident response reports or network flow data because they sound security-related, when the audit specifically demands evidence of access control design and operation.

24
MCQhard

During an incident, the security team discovers that customer personally identifiable information (PII) was exfiltrated. Which of the following notifications must be made according to GDPR?

A.Notify law enforcement within 48 hours
B.Notify all customers within 24 hours
C.Notify the supervisory authority within 72 hours and affected individuals without undue delay if high risk
D.Notify the data protection officer only
AnswerC

This option accurately reflects Article 33 and Article 34 of the GDPR. Organizations must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless it is unlikely to pose a risk. If the breach presents a high risk to individuals' rights and freedoms, those affected must also be notified without undue delay.

Why this answer

Under GDPR, if a breach is likely to result in a high risk to individuals, the organization must notify the affected data subjects without undue delay.

25
Multi-Selectmedium

A cybersecurity analyst is preparing an incident report after a data breach. Which TWO components are essential to include? (Select TWO.)

Select 2 answers
A.Root cause
B.Timeline
C.Budget forecast
D.Employee performance review
E.Marketing analysis
AnswersA, B

Root cause analysis identifies the fundamental underlying reason for the security incident, such as an unpatched vulnerability, misconfigured firewall rule, or successful phishing campaign. For an incident report, establishing the root cause is critical because it guides remediation efforts and prevents recurrence, and it satisfies regulatory and stakeholder requirements for understanding why the incident occurred. Without a root cause, the report is merely descriptive, not prescriptive.

Why this answer

Option A (Root cause) is correct because an incident report must document the underlying vulnerability or failure that enabled the breach, such as an unpatched CVE, misconfigured firewall rule, or successful phishing vector, so remediation can prevent recurrence. Option B (Timeline) is correct because a chronological sequence of events—initial compromise, detection, containment, and eradication timestamps—establishes scope, supports forensic reconstruction, and satisfies regulatory/audit requirements. The unmarked options do not belong: budget forecast (C) is a financial planning artifact, employee performance review (D) is an HR matter, and marketing analysis (E) is unrelated to security incident documentation.

Exam trap

CS0-004 often tests whether candidates can distinguish incident-report essentials (root cause, timeline, impact, IoCs) from unrelated business artifacts like budgets or HR reviews.

26
MCQmedium

After a ransomware incident, the incident report includes lessons learned. Which of the following is the BEST example of a lesson learned?

A.The ransomware encrypted 500 files.
B.The incident started at 2:00 AM.
C.The root cause was a phishing email.
D.Implement multi-factor authentication for remote access to reduce risk.
AnswerD

This is a concrete, actionable recommendation that directly addresses a common attack vector used in ransomware incidents, such as compromised VPN credentials. It specifies the control (MFA), the scope (remote access), and the goal (risk reduction), making it a proper lesson learned. Unlike observations or causes, it provides a clear implementation step that stakeholders can act on to harden their environment.

Why this answer

A lesson learned is a forward-looking recommendation that changes future posture, such as implementing MFA for remote access to reduce risk. It translates incident findings into actionable improvements. The other options are factual observations or analysis, not corrective recommendations.

Exam trap

CS0-004 often tests the difference between observations and recommendations; candidates pick root cause because it sounds analytical, but a lesson learned must be an actionable improvement.

How to eliminate wrong answers

Option A is wrong because stating that 500 files were encrypted is an impact metric, not a lesson or recommendation. Option B is wrong because the incident start time is a timeline fact, not a lesson learned. Option C is wrong because identifying the root cause is analysis; a lesson learned would be the resulting control change, such as adding email filtering or user training.

27
Multi-Selecthard

An organization has experienced a data breach involving personal information of EU residents. The incident response team is preparing communications. Which THREE of the following are mandatory actions under GDPR? (Select THREE.)

Select 3 answers
A.Notify all affected data subjects without undue delay if high risk
B.Document the breach and remediation actions
C.Publish a public notice in the local newspaper
D.Notify law enforcement within 24 hours
E.Notify the supervisory authority within 72 hours
AnswersA, B, E

GDPR Article 34 mandates that data controllers must notify affected data subjects without undue delay when a personal data breach is likely to result in a high risk to their rights and freedoms. This direct communication enables individuals to take necessary precautions to mitigate potential harm, such as identity theft or financial fraud. The 'without undue delay' clause emphasizes the urgency of informing those directly impacted by the breach.

Why this answer

GDPR requires notification to the supervisory authority within 72 hours, documentation of the breach, and notification to affected individuals if high risk.

28
Multi-Selectmedium

A security analyst is preparing a compliance report for an upcoming audit. The auditor has requested evidence of access controls. Which TWO of the following would provide appropriate evidence? (Select TWO.)

Select 2 answers
A.Recent access review reports
B.A network topology diagram
C.User account audit logs showing privilege changes
D.A list of all employees
E.The company's password policy
AnswersA, C

Access review reports are a direct artifact of an identity governance process, showing that the organization periodically re-certifies user entitlements against current roles and business need. Because the reports are generated from actual access decisions and reviews, they demonstrate that the access-control control is operating as intended, which is exactly the type of evidence a compliance auditor expects to see.

Why this answer

Option A (Recent access review reports) is correct because access reviews document the periodic recertification of user permissions, directly demonstrating that access controls are being enforced and validated, which is exactly the type of evidence an auditor seeks for access control compliance. Option C (User account audit logs showing privilege changes) is correct because audit logs provide a verifiable, timestamped record of when privileges were granted, modified, or revoked, serving as concrete technical evidence that access control mechanisms are functioning. Option B (A network topology diagram) is not correct because it illustrates infrastructure layout and data flows, not access control enforcement or user permissions.

Option D (A list of all employees) is not correct because it merely enumerates personnel and does not show how access is granted, restricted, or reviewed. Option E (The company's password policy) is not correct because a policy is a documented intent or requirement, not evidence that access controls are actually implemented or operating effectively.

Exam trap

CS0-004 often tests the difference between policy/design documents (which describe intent) and operational evidence (which proves controls actually ran) — candidates pick the password policy because it sounds security-relevant but it is not audit evidence of access control.

29
MCQhard

An organization has a risk acceptance process for vulnerabilities that cannot be remediated immediately. Which of the following should be documented in the risk acceptance paperwork?

A.The name of the person who discovered the vulnerability
B.Compensating controls, business justification, and expiration date
C.The patch details and installation instructions
D.The CVSS score and exploitability
AnswerB

Correct. A defensible risk acceptance record requires compensating controls that reduce residual risk, a documented business justification explaining why remediation is deferred, and an expiration or review date so the acceptance does not persist indefinitely without reassessment.

Why this answer

Risk acceptance documentation should include compensating controls, business justification, and an expiration date or review period.

30
MCQmedium

A security analyst discovers a critical vulnerability in a web application that stores customer payment data. The analyst needs to report this to the CISO. Which type of report is most appropriate for communicating the business impact of this vulnerability?

A.Compliance report showing PCI DSS control status
B.Technical vulnerability report with CVSS scores and proof of concept
C.Incident report detailing steps to exploit
D.Executive dashboard highlighting financial risk and regulatory penalties
AnswerD

A CISO operates at the executive level and must translate technical vulnerabilities into business risk to allocate resources and make strategic decisions. An executive dashboard that quantifies the vulnerability in terms of potential financial loss, operational downtime, and regulatory non-compliance penalties provides the exact high-level business context required for executive leadership.

Why this answer

An executive dashboard provides high-level metrics and business impact summaries suitable for non-technical stakeholders like the CISO.

31
MCQmedium

A cybersecurity analyst needs to communicate the risk of a newly discovered vulnerability in a legacy system to the executive leadership. Which approach best translates the technical risk into business risk?

A.Explain the vulnerability's potential impact on revenue, customer trust, and compliance penalties
B.Provide the CVSS score and technical exploit details
C.Recommend immediate patching without further justification
D.Describe the attack vector and required privileges
AnswerA

This approach is correct because it reframes a purely technical finding in terms executives already use to make decisions: revenue at risk, reputational damage from lost customer trust, and quantifiable regulatory fines. Framing risk this way lets leadership weigh remediation cost against concrete business consequences instead of abstract technical severity.

Why this answer

Executives care about business impact. Relating the vulnerability to potential financial loss, reputational damage, or regulatory penalties is the most effective way to communicate risk.

32
MCQmedium

During an incident, which of the following should be the FIRST priority when communicating with law enforcement?

A.Sharing the incident response plan
B.Requesting a warrant for internal investigation
C.Coordinating evidence collection and preservation
D.Providing a list of affected customers
AnswerC

Establishing a coordinated approach to evidence collection and preservation is the critical first step to ensure all digital forensics remain legally admissible. This collaboration prevents the organization from inadvertently altering or destroying volatile data, such as RAM or active network logs, which law enforcement needs to establish a proper chain of custody.

Why this answer

Law enforcement may need to preserve evidence for legal proceedings. Coordination ensures that evidence is handled properly and that the organization does not inadvertently destroy or compromise evidence.

33
MCQeasy

Which metric measures the average time it takes for an organization to identify a security incident from the moment it occurs?

A.Mean Time to Resolve (MTTR)
B.Patch SLA compliance percentage
C.Mean Time to Remediate (MTTRem)
D.Mean Time to Detect (MTTD)
AnswerD

Mean Time to Detect (MTTD) is the correct metric, as it measures the average elapsed time between the initial occurrence of a security incident—such as an intrusion or malware compromise—and the moment it is identified by monitoring tools or security personnel. Shorter MTTD directly reduces attacker dwell time and potential damage. This metric is specifically designed to gauge the speed and effectiveness of an organization's detection capabilities.

Why this answer

Mean Time to Detect (MTTD) is the average time to detect an incident.

34
MCQeasy

Which type of threat intelligence report is MOST appropriate for a Chief Information Security Officer (CISO) to understand the overall threat landscape and make strategic decisions?

A.Strategic intelligence
B.Operational intelligence
C.Technical intelligence
D.Tactical intelligence
AnswerA

Strategic intelligence provides high-level, non-technical insights into long-term threat landscapes, emerging risk trends, and geopolitical motivations. It is tailored specifically for C-level executives and board members to guide long-term financial planning, risk management, and organizational security posture alignment.

Why this answer

Strategic intelligence provides high-level analysis of threats, trends, and risks that impact business decisions. It is designed for senior management and executives.

35
MCQmedium

A security analyst is preparing an after-action report for a phishing incident. Which component is MOST critical to include to prevent recurrence?

A.Timeline of the incident
B.Lessons learned and recommendations
C.Impact assessment
D.Root cause analysis
AnswerB

This section is the primary driver of continuous improvement in the incident response lifecycle. It translates the findings of the post-incident review into actionable security controls, policy updates, and architectural modifications designed to eliminate vulnerabilities and prevent similar security incidents from recurring.

Why this answer

An after-action report exists to drive improvement, so the component that directly prevents recurrence is the lessons learned and recommendations section, which translates findings into concrete process, tooling, or training changes. While timeline, impact, and root cause feed into it, only lessons learned and recommendations prescribe the corrective actions that stop the same phishing incident from succeeding again.

Exam trap

CS0-004 often tests the confusion between root cause analysis and lessons learned — candidates pick D because 'root cause' sounds like the deepest answer, but the question asks what prevents recurrence, which is the recommendation output, not the diagnostic input.

How to eliminate wrong answers

Option A is wrong because a timeline documents what happened chronologically but does not by itself change controls or user behavior to prevent recurrence. Option C is wrong because an impact assessment quantifies damage (financial, data, reputational) but is descriptive, not prescriptive, and does not stop a repeat incident. Option D is wrong because root cause analysis identifies why the incident occurred but stops short of the actionable remediation steps — it is an input to lessons learned, not the preventive output itself.

36
MCQhard

During an audit, the compliance team needs to provide evidence that access reviews are performed regularly. Which of the following is the BEST evidence?

A.A list of user accounts with last login dates
B.A policy stating that access reviews should be done quarterly
C.Email reminders sent to managers to perform reviews
D.Signed and dated access review reports
AnswerD

Correct. Signed and dated reports establish accountability, a specific date of execution, and the reviewer's attestation that access was examined and adjudicated, which is the direct, verifiable artifact auditors require to confirm a control operated as designed.

Why this answer

Completed access review reports with timestamps and signatures provide clear evidence that reviews were conducted.

37
MCQeasy

A cybersecurity analyst is preparing a report for the executive leadership team. Which type of report is most appropriate for communicating high-level security posture and risk to non-technical stakeholders?

A.Threat intelligence feed
B.Technical vulnerability report
C.Executive dashboard
D.Incident response playbook
AnswerC

An executive dashboard aggregates complex security data into high-level key performance indicators (KPIs) and risk metrics, such as overall compliance posture and mean time to detect (MTTD). This visual format allows non-technical leadership to quickly grasp the organization's current security posture and make informed resource allocation decisions.

Why this answer

Executive dashboards provide a high-level overview of security posture, using metrics and visualizations that are easily understood by non-technical stakeholders. Technical reports are too detailed.

38
MCQeasy

A cybersecurity analyst is preparing a vulnerability report for the IT manager. Which section should summarize the most critical risks for the organization?

A.Remediation timeline
B.Risk acceptance
C.Findings by severity
D.Executive summary
AnswerD

This section is designed specifically for leadership and non-technical stakeholders, distilling complex technical findings into a high-level overview of critical risks, business impacts, and strategic recommendations. It provides the necessary context for resource allocation and risk management decisions without overwhelming the reader with granular vulnerability data.

Why this answer

The executive summary provides a high-level overview of the most critical risks and recommended actions for management.

39
Multi-Selectmedium

A security analyst is preparing a vulnerability report for management. Which TWO elements should be included in the executive summary? (Select TWO.)

Select 2 answers
A.Raw CVSS scores for all vulnerabilities
B.Detailed technical description of each vulnerability
C.Network topology diagrams
D.Overall risk posture summary
E.Key findings that require management attention
AnswersD, E

An overall risk posture summary aggregates findings into a concise, qualitative rating—such as high/medium/low—or a weighted risk score that reflects the organization's relative exposure. This gives management a rapid understanding of whether immediate attention is required and how the current risk compares to prior assessments or industry benchmarks. It directly enables informed, risk-based decisions about prioritizing remediation efforts and allocating resources.

Why this answer

The executive summary is written for management, so it must translate technical findings into business-relevant information. Option D (Overall risk posture summary) is correct because it gives leadership a high-level view of the organization's aggregate exposure and whether risk is increasing or decreasing. Option E (Key findings that require management attention) is correct because it highlights the critical issues that need decisions, resources, or remediation prioritization from leadership.

Options A and B are incorrect because raw CVSS scores and detailed technical descriptions belong in the technical body of the report, not the executive summary. Option C is also incorrect because network topology diagrams are supporting technical artifacts, not executive-level summary content.

Exam trap

CS0-004 often tests whether candidates can distinguish between technical report content (raw CVSS, detailed descriptions, topology diagrams) and executive-level content (risk posture, key findings) appropriate for management.

40
MCQmedium

A security analyst needs to present a risk register to a non-technical board. Which of the following formats is most appropriate?

A.A timeline of past incidents
B.A heat map with risk ratings and business impact descriptions
C.A list of CVEs with CVSS scores
D.A detailed network diagram with vulnerability locations
AnswerB

A heat map converts likelihood and impact into colour-coded bands, letting a non-technical board grasp relative exposure at a glance without interpreting raw scores. Pairing each rating with a business impact description satisfies the stem's constraint: communicating risk to an audience lacking technical background, so prioritisation and funding decisions can be made quickly.

Why this answer

A heat map with risk ratings and business impact descriptions is most appropriate for a non-technical board because it visually communicates risk severity and business consequences without requiring technical expertise. It translates technical risks into business terms, facilitating informed decision-making.

Exam trap

CS0-004 often tests the ability to tailor communication to different audiences, and candidates may choose technical formats like CVE lists or network diagrams that are inappropriate for non-technical stakeholders.

How to eliminate wrong answers

Option A is wrong because a timeline of past incidents is historical and does not provide a forward-looking risk assessment. Option C is wrong because a list of CVEs with CVSS scores is highly technical and not easily understood by non-technical audiences. Option D is wrong because a detailed network diagram with vulnerability locations is too technical and focuses on technical details rather than business impact.

41
MCQeasy

Which metric measures the average time it takes to identify a security incident from the moment it occurs?

A.MTTRem
B.MTTR
C.SLA compliance
D.MTTD
AnswerD

MTTD, Mean Time to Detect, is precisely the metric that measures the average elapsed time between when a security incident actually begins and when the security team becomes aware of it, making it the key indicator of detection capability and a primary driver of overall breach cost and dwell time.

Why this answer

MTTD (Mean Time to Detect) measures the average time to detect an incident.

42
Multi-Selecthard

After a security incident involving a ransomware attack, the organization needs to communicate with various stakeholders. Which THREE of the following are appropriate actions? (Select THREE.)

Select 3 answers
A.Place legal holds on relevant data
B.Delete all logs to prevent data leakage
C.Publish details on social media immediately
D.Coordinate with law enforcement
E.Notify affected customers as required by law
AnswersA, D, E

Placing a legal hold on relevant data is a legally binding directive that suspends all normal deletion, rotation, and destruction policies for potentially relevant information. In a ransomware incident, this preserves logs, endpoint artifacts, and backup copies, ensuring a complete forensic record for litigation or regulatory investigation. Without a legal hold, automated processes such as log rotation or archive purging could destroy evidence, leading to spoliation sanctions and undermining the ability to prove the scope of the breach.

Why this answer

Option A is correct because placing legal holds on relevant data preserves logs, backups, and affected systems as potential evidence for forensic investigation, regulatory inquiries, and possible litigation, preventing routine deletion or overwriting. Option D is correct because coordinating with law enforcement (e.g., FBI, Secret Service, or local cybercrime units) is a standard incident-response step that supports evidence handling, threat attribution, and may be legally required or beneficial for the organization. Option E is correct because notifying affected customers as required by law satisfies breach-notification obligations under regulations such as GDPR, HIPAA, or state data-breach statutes, which mandate timely disclosure when personal or protected data is compromised.

Option B is not appropriate because deleting logs destroys forensic evidence, violates legal-hold and retention requirements, and impedes incident investigation. Option C is not appropriate because publishing details on social media immediately can compromise the investigation, leak sensitive information, and should instead be handled through a coordinated, approved communications plan.

Exam trap

CS0-004 often tests the misconception that deleting logs or posting on social media is a valid containment or communication step, when both undermine legal and forensic obligations.

43
MCQeasy

Which metric measures the average time taken to fix a vulnerability after it is identified?

A.Mean time to remediate (MTTRem)
B.Mean time to detect (MTTD)
C.Mean time to respond (MTTR)
D.Patch SLA compliance %
AnswerA

Mean time to remediate is calculated as the average duration between when a vulnerability is identified and when it is actually fixed or closed, making it the direct metric for tracking remediation speed described in the question.

Why this answer

Mean time to remediate (MTTRem) is defined as the average elapsed time between when a vulnerability is identified and when it is fully remediated (patched, mitigated, or accepted with compensating controls). This matches the question's wording exactly — identification to fix.

Exam trap

CS0-004 often tests the MTTR vs MTTRem vs MTTD acronym collision — candidates pick C because MTTR is the more familiar term, but MTTR is response time, while MTTRem is specifically remediation time after identification.

How to eliminate wrong answers

Option B is wrong because MTTD measures the time from when a vulnerability or incident actually occurs (or is introduced) to when it is detected — it stops at detection, not remediation. Option C is wrong because MTTR (mean time to respond) measures time from detection to the start of response or containment, not to full remediation, and is more commonly used for incidents than vulnerabilities. Option D is wrong because patch SLA compliance % is a ratio of patches completed within a defined window, not an average time measurement, so it does not express 'average time taken to fix.'

44
MCQmedium

A vulnerability report is presented to the IT manager. The report lists 15 critical, 40 high, 100 medium, and 200 low vulnerabilities. The IT manager asks which vulnerabilities should be prioritized for remediation. According to the vulnerability report structure, which section should the analyst reference?

A.Findings by severity
B.Executive summary
C.Remediation timeline
D.Risk acceptance
AnswerA

The findings-by-severity section breaks the full vulnerability list down into the critical, high, medium, and low buckets shown in the manager's report, giving the analyst the exact grouped detail needed to identify which of the 15 critical and 40 high items must be remediated first.

Why this answer

The 'Findings by severity' section groups vulnerabilities by their severity ratings (critical, high, medium, low), which directly answers the manager's question about prioritization. Since the report lists counts per severity, this section provides the structured breakdown needed to identify which vulnerabilities to address first. The other sections serve different purposes: executive summary gives a high-level overview, remediation timeline outlines when fixes should occur, and risk acceptance documents decisions to accept certain risks.

Exam trap

CS0-004 often tests the distinction between report sections, and candidates may confuse the executive summary (which provides a high-level overview) with the detailed severity breakdown needed for prioritization.

How to eliminate wrong answers

Option B is wrong because the executive summary provides a high-level overview for management, not the detailed severity breakdown needed for prioritization. Option C is wrong because the remediation timeline specifies deadlines for fixing vulnerabilities, not which ones to prioritize based on severity. Option D is wrong because risk acceptance is a formal decision to accept certain risks, not a section that lists vulnerabilities by severity for prioritization.

45
MCQhard

An organization needs to report a data breach involving personal data of EU residents. Under GDPR, what is the maximum time allowed for notifying the supervisory authority after becoming aware of the breach?

A.48 hours
B.7 days
C.24 hours
D.72 hours
AnswerD

GDPR Article 33(1) mandates that a data controller notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours" after becoming aware of it. This 72-hour window is the exact compliance threshold explicitly written into the regulation, and failing to meet it without documented justification is a violation. The notification must include the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed to mitigate harm.

Why this answer

GDPR Article 33 mandates that a controller notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is the maximum; earlier notification is encouraged. If notification is not made within 72 hours, it must be accompanied by reasons for the delay.

Exam trap

CS0-004 often tests the 72-hour GDPR window against the 24-hour or 48-hour figures borrowed from other regulations; candidates who memorize 'fast notification' pick the shortest number.

How to eliminate wrong answers

Option A (48 hours) is wrong because it is not a GDPR-mandated timeframe — it may be confused with other regulatory deadlines or internal SLAs. Option B (7 days) is wrong because it reflects a common misconception that breach notification follows a weekly cycle; no GDPR provision allows a week. Option C (24 hours) is wrong because it is the stricter timeline used by some sector-specific regulations (e.g., certain NIS2 or financial rules) but not the GDPR baseline — candidates often conflate the two.

46
MCQmedium

A security analyst is creating a risk register. Which of the following is the most important element to include for each risk?

A.Likelihood and impact rating
B.The exact date the risk was identified
C.The name of the person who discovered the risk
D.The CVSS score of related vulnerabilities
AnswerA

A risk register must prioritize threats to allocate mitigation resources effectively. Calculating the likelihood of occurrence alongside the potential business impact allows analysts to derive a qualitative or quantitative risk rating, which is the foundational metric for risk-based decision-making.

Why this answer

A risk register should include risk owner, likelihood, impact, and mitigation status. Likelihood and impact help prioritize risks.

47
Multi-Selectmedium

A security analyst is selecting Key Performance Indicators (KPIs) for a security operations dashboard. Which THREE metrics are most relevant for measuring incident response effectiveness? (Select THREE.)

Select 3 answers
A.Number of employees
B.Mean time to detect (MTTD)
C.Mean time to remediate (MTTRem)
D.Revenue growth
E.Mean time to respond (MTTR)
AnswersB, C, E

Mean time to detect measures the average duration between when an incident or attack first occurs and when the security team actually becomes aware of it. A lower MTTD indicates stronger monitoring, alerting, and threat-hunting capabilities, allowing the organization to minimize the window in which attackers can operate undetected. It is specifically focused on the detection phase of the incident response lifecycle.

Why this answer

Option B, Mean time to detect (MTTD), is correct because it directly measures how quickly the security operations team identifies a potential incident from the moment it occurs, which is a core indicator of detection capability and monitoring effectiveness. Option C, Mean time to remediate (MTTRem), is correct because it quantifies the time required to fully resolve or contain an incident after detection, reflecting the team's ability to restore normal operations and limit business impact. Option E, Mean time to respond (MTTR), is correct because it measures the elapsed time from detection to the start of active response actions, showing how promptly analysts engage with and begin handling a confirmed incident.

Option A, Number of employees, is not a security operations performance metric and does not reflect incident response effectiveness. Option D, Revenue growth, is a business financial metric unrelated to the speed or quality of incident detection, response, or remediation.

Exam trap

The trap is selecting business or HR metrics (number of employees, revenue growth) because they appear on executive dashboards — but the question specifically asks for incident response effectiveness KPIs, which are time-based detection and remediation metrics.

48
Multi-Selecthard

A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)

Select 3 answers
A.Employee training attendance records
B.Access review documentation
C.Log exports from critical systems
D.Vulnerability scan reports
E.Marketing brochures
AnswersB, C, D

Access review documentation is primary audit evidence because it shows a periodic recertification of user entitlements against role definitions, least privilege, and separation of duties. It provides an auditable trail of who reviewed critical systems, what discrepancies were detected, and how they were remediated, directly satisfying access control compliance requirements. Auditors frequently cite missing or outdated access reviews as a material finding, so this documentation is a cornerstone of evidence collection.

Why this answer

Access review documentation (B) is required because compliance frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001 mandate periodic attestation that user access rights are appropriate and least-privilege, providing auditable proof of authorization control. Log exports from critical systems (C) are essential evidence because they demonstrate continuous monitoring, traceability of user and system activity, and support incident investigation and retention requirements under regulations like PCI DSS Req. 10 and HIPAA §164.312(b). Vulnerability scan reports (D) are required to prove that the organization identifies, tracks, and remediates technical weaknesses on a recurring basis, satisfying requirements such as PCI DSS Req. 11.2 and NIST SP 800-53 RA-5.

Employee training attendance records (A) are useful for awareness programs but are not one of the three evidence types typically demanded in this audit context, and marketing brochures (E) are promotional materials with no evidentiary value for compliance.

Exam trap

CS0-004 often tests the distinction between governance/awareness artifacts (training records) and technical/operational evidence (access reviews, logs, scan reports) — candidates over-select training records because they sound compliance-related but are not among the three required technical evidence types.

49
MCQhard

A security analyst is communicating a complex security risk about a new zero-day vulnerability to the board of directors. The board members have varying technical backgrounds. Which approach would be MOST effective?

A.Provide a list of all current vulnerabilities
B.Present the CVSS score and affected systems
C.Describe the potential financial loss, reputational damage, and regulatory fines
D.Explain the technical details of the exploit chain
AnswerC

Describing potential financial loss, reputational damage, and regulatory fines directly maps the risk onto the board's fiduciary duties, giving them the essential information needed for risk tolerance and resource allocation. This approach quantifies or estimates impact in the same units executives use to evaluate business decisions, such as ERM frameworks and insurance. It lets the CISO argue for security investment as a business trade-off, which is the only frame that produces meaningful discussion and sign-off.

Why this answer

Board members focus on business impact, so describing potential financial loss, reputational damage, and regulatory fines translates the technical risk into terms they understand and care about. This aligns with risk communication best practices for non-technical executives. It enables informed decision-making on risk acceptance or mitigation funding.

Exam trap

CS0-004 often tests the confusion between technical and business communication — candidates may pick CVSS scores thinking they are objective, but boards need business impact.

How to eliminate wrong answers

Option A is wrong because a list of all vulnerabilities is overwhelming and lacks prioritization or business context. Option B is wrong because CVSS scores and affected systems are technical metrics that may not convey business impact to a non-technical board. Option D is wrong because explaining the exploit chain is too technical and irrelevant to board-level decision-making.

50
MCQhard

During an incident, the security team needs to preserve evidence for potential litigation. Which of the following actions is most critical to ensure the admissibility of digital evidence?

A.Creating a bit-for-bit forensic image of affected systems
B.Immediately notifying law enforcement
C.Establishing and maintaining a chain of custody for all evidence
D.Encrypting all evidence files
AnswerC

Establishing a rigorous chain of custody is the foundational requirement for ensuring the integrity and legal admissibility of any collected evidence. This process meticulously documents who collected, accessed, transferred, and secured the evidence at every stage of the incident lifecycle. Without this continuous paper trail, the evidence can be easily challenged as tainted or manipulated.

Why this answer

Preserving the chain of custody is essential for evidence admissibility, as it documents who handled the evidence and when.

51
MCQhard

A cybersecurity analyst is preparing a threat intelligence report for the SOC team. Which type of intelligence should be included to provide actionable indicators of compromise (IoCs)?

A.Tactical intelligence
B.Strategic intelligence
C.Technical intelligence
D.Operational intelligence
AnswerA

Tactical threat intelligence focuses on the immediate, real-time indicators of compromise (IoCs) such as malicious IP addresses, domain names, and file hashes. Security analysts ingest this data directly into security information and event management (SIEM) systems and firewalls to automate threat detection and block active attacks.

Why this answer

Tactical intelligence includes IoCs such as IP addresses, domain names, and hashes that can be used for detection and blocking.

52
MCQhard

A vulnerability report is being prepared for an organization's management. Which of the following is the MOST appropriate structure for this report?

A.Charts showing open vulnerability counts over time, without any narrative
B.List of all vulnerabilities sorted by CVSS score, followed by detailed technical descriptions
C.Executive summary, findings by severity, risk acceptance, remediation timeline
D.Network diagram with vulnerability locations, patch status, and compliance checklists
AnswerC

This structure layers an executive summary for quick comprehension, findings grouped by severity for prioritization context, documented risk acceptances for transparency on deferred items, and a remediation timeline for accountability, matching exactly what management-level reporting requires to make informed risk and resourcing decisions without wading through raw technical scan output.

Why this answer

A standard vulnerability report includes an executive summary for high-level decision-makers, findings grouped by severity, risk acceptance decisions, and a remediation timeline.

53
Multi-Selecthard

An organization is preparing for a compliance audit. Which TWO of the following are essential pieces of evidence to demonstrate effective vulnerability management?

Select 2 answers
A.Network topology diagrams
B.Employee training logs
C.Vulnerability scan reports
D.Patch management reports
E.Incident response playbooks
AnswersC, D

Vulnerability scan reports are the primary evidence that an organization is actively discovering weaknesses, as they contain the scan timestamp, authenticated or unauthenticated scan type, CVEs, and CVSS severity scores. They allow auditors to correlate the identified vulnerabilities against the organization's asset inventory and check that coverage includes critical systems. A series of scan reports demonstrates the continuous, recurring nature of the program, which is a core requirement of many compliance frameworks.

Why this answer

Vulnerability scan reports (C) are essential evidence because they document the identification of vulnerabilities across the environment, showing when scans were performed, what hosts were assessed, and which CVEs or findings were detected, which is the core proof that a vulnerability management program is actively discovering weaknesses. Patch management reports (D) are equally essential because they demonstrate remediation—showing that identified vulnerabilities were addressed through applied updates, with dates, affected systems, and patch levels (e.g., KB numbers or package versions), closing the loop between detection and resolution. Together, C and D provide the audit trail of find-and-fix that auditors require to verify an effective vulnerability management process.

Network topology diagrams (A) describe architecture but do not evidence scanning or remediation activity. Employee training logs (B) support security awareness compliance, not vulnerability management specifically. Incident response playbooks (E) are documentation for handling incidents and do not demonstrate ongoing vulnerability identification or patching.

Exam trap

CS0-004 often tests whether candidates understand that vulnerability management requires both detection and remediation evidence — picking only scan reports or only patch reports misses half the lifecycle and is a common wrong answer.

54
MCQhard

An organization has experienced a data breach involving personal data of EU residents. Under GDPR, what is the maximum time frame within which the organization must notify the supervisory authority?

A.24 hours
B.7 days
C.48 hours
D.72 hours
AnswerD

The General Data Protection Regulation (GDPR), specifically Article 33, explicitly mandates that organizations must notify the relevant supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it." This precise timeframe is crucial for enabling authorities to promptly assess the breach's impact and for organizations to initiate appropriate mitigation actions and fulfill their accountability obligations.

Why this answer

GDPR Article 33 requires that data breaches be reported to the relevant supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

55
MCQhard

A security analyst needs to present the risk of an unpatched critical vulnerability to the board of directors. Which of the following is the most effective way to communicate the risk?

A.Explain the potential financial loss and reputational damage.
B.Show the CVSS score and exploit complexity.
C.Recommend immediate patching without details.
D.Describe the vulnerability in technical terms.
AnswerA

Quantifying the unpatched vulnerability in terms of potential financial loss—such as breach response costs, regulatory fines, or lost revenue from downtime—and reputational damage, like customer churn or erosion of brand trust, directly aligns the technical risk with the board's fiduciary responsibilities. This translation reassures executives that their decision allocates resources to protect shareholder value and market standing, not just IT infrastructure.

Why this answer

When communicating risk to a board of directors, the most effective approach is to translate the technical vulnerability into business impact—potential financial loss, regulatory fines, and reputational damage—because executives prioritize strategic and financial consequences over technical detail. This framing enables informed risk acceptance or remediation decisions at the governance level. CVSS scores and technical descriptions, while useful to security teams, do not resonate with non-technical leadership.

Exam trap

CS0-004 often tests audience-appropriate communication, so candidates who default to technical metrics (CVSS, CVE) instead of business impact (financial, reputational) pick the wrong answer for executive audiences.

How to eliminate wrong answers

Option B is wrong because CVSS scores and exploit complexity are technical metrics that mean little to a board; they inform severity but not business consequence. Option C is wrong because recommending immediate patching without context or justification undermines informed decision-making and fails to convey the risk's business impact. Option D is wrong because describing the vulnerability in technical terms (e.g., buffer overflow, CVE details) does not translate to the financial and reputational stakes that boards are accountable for.

56
MCQmedium

Which compliance reporting requirement under GDPR mandates that organizations notify the relevant supervisory authority within a specific timeframe after becoming aware of a personal data breach?

A.72 hours
B.7 days
C.24 hours
D.48 hours
AnswerA

GDPR Article 33(1) sets a hard, maximum deadline of 72 hours after the controller becomes aware of a personal data breach for notifying the supervisory authority, unless the breach is unlikely to result in a risk to individuals' rights and freedoms. The obligation is phrased as 'without undue delay and, where feasible, not later than 72 hours,' meaning 72 hours is the outer statutory limit, not a target. If notification is made after 72 hours, the controller must provide the reasons for the delay under Article 33(5). Thus, 72 hours is the correct and canonical compliance reporting requirement.

Why this answer

Under GDPR Article 33, organizations must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is a core GDPR compliance requirement. The other timeframes do not match the regulation.

Exam trap

CS0-004 often tests specific regulatory timeframes, so candidates who confuse GDPR's 72-hour rule with shorter windows from other breach notification laws (e.g., 24 hours) or internal SLAs pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because 7 days is not a GDPR notification timeframe; it may be confused with other regulatory or internal reporting periods. Option C is wrong because 24 hours is a common misconception, possibly borrowed from other breach notification regimes, but GDPR specifies 72 hours. Option D is wrong because 48 hours is not specified in GDPR Article 33; the regulation explicitly uses 72 hours.

57
MCQeasy

Which of the following metrics measures the average time it takes to identify a security incident after it occurs?

A.Patch SLA compliance percentage
B.Mean time to remediate (MTTRem)
C.Mean time to respond (MTTR)
D.Mean time to detect (MTTD)
AnswerD

Mean time to detect (MTTD) is the average elapsed time between the actual occurrence of a security incident or malicious activity and the moment it is recognized or flagged as suspicious by telemetry, analytics, or an analyst. It is the definitive metric for measuring detection velocity, because it captures the so-called "dwell time" before discovery, where the adversary may be operating unnoticed. Lower MTTD directly reduces the opportunity for attackers to achieve their objectives by limiting the window of undetected access.

Why this answer

Mean time to detect (MTTD) is the metric that measures the average elapsed time between when a security incident actually occurs and when it is identified/detected by the organization. It is a core SOC efficiency metric.

Exam trap

CS0-004 often tests the confusion between MTTD, MTTR (respond), and MTTRem (remediate) — candidates mix up 'detect' with 'respond' because both are abbreviated MTTR in some frameworks.

How to eliminate wrong answers

Option A is wrong because patch SLA compliance measures the percentage of patches applied within a defined timeframe — it is a vulnerability management metric, not an incident detection metric. Option B is wrong because MTTRem (mean time to remediate) measures how long it takes to fix/contain an incident after detection, not how long detection takes. Option C is wrong because MTTR (mean time to respond) measures the time from detection to response actions — it starts after detection, so it does not capture identification time.

58
MCQmedium

During a security incident involving a potential data breach, the CISO asks you to prepare a communication for the board of directors. What is the MOST important aspect to emphasize in this communication?

A.The specific malware used and its technical attributes
B.The names of the IT staff who first detected the incident
C.A step-by-step timeline of the incident response actions taken so far
D.The financial impact, reputational risk, and potential regulatory penalties
AnswerD

For a board of directors, information regarding the financial impact, potential reputational damage, and regulatory penalties is paramount because these directly relate to their fiduciary duties and the long-term strategic health of the organization. Understanding the monetary losses, the erosion of public trust, and the legal ramifications enables the board to assess the overall business risk effectively. This critical information guides their strategic decisions on resource allocation, risk mitigation strategies, and governance improvements to protect shareholder value and ensure compliance.

Why this answer

When communicating with the board of directors during a data breach, the most important aspects are the business impact: financial loss, reputational damage, and potential regulatory fines. Board members are concerned with strategic and financial implications, not technical details. Emphasizing these areas helps them make informed decisions and allocate resources appropriately.

Exam trap

The trap is focusing on technical details instead of business impact. Candidates might think the board wants to know how the breach happened, but they care more about the consequences and mitigation.

How to eliminate wrong answers

Option A is wrong because the specific malware and its technical attributes are too granular for a board-level audience; they need impact, not technical indicators. Option B is wrong because naming IT staff who detected the incident is irrelevant to the board's decision-making and could unfairly assign blame. Option C is wrong because a step-by-step timeline of response actions, while useful for operational reviews, is too detailed for a board communication; they need a high-level summary of impact and response effectiveness.

59
Multi-Selectmedium

Which three metrics are commonly used to measure the effectiveness of a security operations center (SOC)? (Select THREE.)

Select 3 answers
A.Number of firewall rules
B.Number of employees in the SOC
C.Mean Time to Respond (MTTR)
D.Mean Time to Remediate (MTTRem)
E.Mean Time to Detect (MTTD)
AnswersC, D, E

Mean Time to Respond (MTTR) quantifies how quickly a SOC team takes action to contain an incident after detection. It typically measures the interval between alert triage and the first mitigation step (e.g., isolating a host, blocking a C2 domain), directly reflecting the team's readiness and playbook efficiency. Lower MTTR indicates faster containment, which reduces the attacker's dwell time and prevents lateral movement.

Why this answer

Option C, Mean Time to Respond (MTTR), is correct because it measures how quickly the SOC reacts to a validated incident after detection, directly reflecting operational responsiveness. Option D, Mean Time to Remediate (MTTRem), is correct because it captures how long it takes to fully resolve or contain the threat, showing the SOC's effectiveness in restoring normal operations. Option E, Mean Time to Detect (MTTD), is correct because it measures the time from the initial compromise or event to detection, which is a core indicator of monitoring and detection capability.

Options A and B are not correct: the number of firewall rules is a configuration or hygiene metric rather than a SOC performance measure, and the number of SOC employees is a staffing/resource metric, not an effectiveness outcome.

Exam trap

CS0-004 often tests the confusion between SOC performance metrics (MTTD, MTTR, MTTRem) and vanity metrics (number of rules, staff count), tempting candidates to select operational or staffing counts as effectiveness measures.

60
MCQhard

An organization's compliance dashboard shows a control effectiveness score of 85%. Which type of evidence best supports this score?

A.Incident response logs
B.Employee training records
C.Vendor documentation
D.Penetration test results and audit reports
AnswerD

Penetration test results and formal audit reports offer objective, empirical validation of how controls perform under active duress or systematic evaluation. These assessments actively test defenses and verify regulatory compliance, providing the concrete evidence needed to populate a control effectiveness dashboard.

Why this answer

A control effectiveness score of 85% reflects how well implemented controls are actually performing against their intended objectives. Penetration test results and audit reports provide direct, independent evidence of whether controls are functioning as designed—pen tests actively attempt to bypass controls, while audits verify their operational status. These sources offer the most objective and comprehensive validation of control effectiveness, making them the best evidence to support such a score.

Exam trap

CS0-004 often tests the distinction between evidence of control existence versus evidence of control effectiveness, causing candidates to select training records or vendor documentation that only prove a control is in place, not that it works.

How to eliminate wrong answers

Option A is wrong because incident response logs only show events that triggered a response; they do not measure the overall effectiveness of preventive or detective controls across the environment. Option B is wrong because employee training records only indicate completion of awareness training, which is a single administrative control and does not provide evidence of technical or operational control effectiveness. Option C is wrong because vendor documentation describes what a product or service is supposed to do, not whether the organization's implemented controls are actually working effectively.

61
MCQmedium

An incident report includes a section that details the sequence of events from initial compromise to containment. Which component of the incident report does this describe?

A.Impact assessment
B.Root cause
C.Lessons learned
D.Timeline
AnswerD

A timeline is a chronological, time-stamped listing of events, actions, observations, and findings that occurred during an incident. It is a foundational component of incident documentation because it establishes the order and timing of events, supporting correlation of security events and response actions. In an incident report, the section 'detailing the sequence' directly maps to the timeline's purpose of recording events in sequence.

Why this answer

The timeline component of an incident report provides a chronological record of events, from the initial compromise through detection, response, and containment. It answers the 'when' and 'in what order' questions, which is exactly what the question describes. Other components like impact assessment, root cause, and lessons learned focus on consequences, underlying reasons, and improvements, respectively.

Exam trap

CS0-004 often tests the distinction between incident report components by using similar-sounding descriptions; candidates may confuse 'sequence of events' with 'root cause' or 'lessons learned' if they do not carefully map the definition to the component.

How to eliminate wrong answers

Option A is wrong because an impact assessment quantifies the damage or business effect (e.g., data loss, downtime cost), not the sequence of events. Option B is wrong because root cause analysis identifies the fundamental vulnerability or failure that allowed the incident, not the chronological progression. Option C is wrong because lessons learned capture recommendations and improvements after the incident, not the event sequence itself.

62
MCQeasy

Which of the following is the primary audience for a strategic threat intelligence report?

A.System administrators
B.SOC analysts
C.Executive leadership
D.Incident responders
AnswerC

Executive leadership is the primary audience for strategic intelligence because it informs high-level decisions about risk tolerance, resource allocation, and business continuity. This type of intelligence is written in non-technical language, summarizing geopolitical threats, industry-level trends, and potential impacts to the enterprise in a way that supports governance and investment choices. It helps the C-suite align cybersecurity with organizational objectives, not with day-to-day tactics.

Why this answer

Strategic intelligence is high-level and intended for executive leadership to inform business decisions.

63
MCQmedium

An organization is preparing for an audit to demonstrate compliance with GDPR. The compliance officer needs to provide evidence of data protection controls. Which of the following would be the BEST evidence to include?

A.The organization's risk register
B.Copies of recent vulnerability scan reports and access review logs
C.Email communications about security incidents
D.A summary of security policies and procedures
AnswerB

Vulnerability scan reports and access review logs serve as direct, empirical evidence of technical control implementation and operational effectiveness. These artifacts prove to auditors that vulnerability management processes are actively running and that identity and access management controls are being routinely monitored and enforced. This objective, system-generated data is crucial for validating compliance with frameworks like PCI-DSS, SOC 2, or ISO 27001.

Why this answer

Log exports, configuration reports, vulnerability scans, and access reviews are typical evidence for GDPR audits.

64
Multi-Selectmedium

An analyst is preparing a vulnerability report for management. Which THREE sections should be included to effectively communicate findings and remediation? (Select THREE.)

Select 3 answers
A.Executive summary
B.Incident response procedures
C.Network topology diagram
D.Findings by severity
E.Remediation timeline
AnswersA, D, E

The executive summary is the most critical section for management because it distills the entire vulnerability assessment into a concise, high-level overview of the organization's risk posture. It should highlight the total number of vulnerabilities, the most severe threats, and the recommended strategic actions without overwhelming readers with technical CVSS vectors or exploit details. Management needs this to make informed decisions on resource allocation and risk acceptance, making it a mandatory component of any vulnerability report.

Why this answer

The executive summary (A) is correct because it gives management a concise, non-technical overview of the assessment's scope, key risks, and overall risk posture, which is essential for decision-makers who need the bottom line without deep technical detail. Findings by severity (D) is correct because organizing vulnerabilities by severity ratings (e.g., CVSS scores or Critical/High/Medium/Low categories) lets management prioritize the most dangerous issues and allocate resources accordingly. Remediation timeline (E) is correct because it communicates when fixes will be applied, establishes accountability, and aligns remediation with business risk tolerance and operational constraints.

Incident response procedures (B) do not belong because they are operational playbooks for handling active incidents, not components of a vulnerability report. Network topology diagram (C) is not required because it is supporting technical documentation that may aid context but is not one of the core sections needed to communicate findings and remediation to management.

Exam trap

CS0-004 often tests the confusion between vulnerability report components and incident response documentation, tempting candidates to include IR procedures or topology diagrams that are not part of a standard management report.

65
MCQmedium

An analyst is creating a compliance dashboard for management. Which of the following is the most relevant metric to include regarding patch management?

A.Number of antivirus alerts
B.Phishing simulation click rate
C.Mean time to detect incidents
D.Patch SLA compliance %
AnswerD

Patch SLA compliance percentage directly measures whether systems are being patched within the timeframes the organization has committed to, for example critical patches within 14 days, which is precisely what a management-facing compliance dashboard needs to show for the patch management program. It ties directly to the process being audited rather than to an adjacent security function.

Why this answer

Patch SLA compliance percentage directly measures how well the organization meets patch deadlines, which is a key compliance metric.

66
MCQeasy

A security analyst is drafting a communication plan for a suspected data breach involving customer personally identifiable information. Legal counsel advises that notification may be required under multiple regulations. Which of the following should the analyst do FIRST to ensure the communication plan meets regulatory obligations?

A.Publish a press release on the corporate website to demonstrate transparency
B.Identify which regulations apply and their specific notification requirements, including timelines and recipients
C.Send an internal email to all employees describing the breach and instructing them not to discuss it
D.Immediately notify all affected customers via email with the details of the breach
AnswerB

Different regulations, such as GDPR, HIPAA, or state breach laws, have distinct notification triggers, timelines, and recipients. Before communicating, the analyst must determine which laws apply based on data type, location, and affected individuals. This ensures the organization meets its legal obligations and avoids penalties. It is the foundational step in building a compliant communication plan, as it dictates what, when, and to whom notifications must be sent.

Why this answer

When a data breach involves regulated data, the first step is to determine which laws apply and what they require. Notification timelines, recipients, and content vary by regulation. Identifying these obligations ensures the communication plan is legally compliant and avoids premature or inadequate disclosures.

Only after this analysis should customer, public, or internal communications be drafted.

Exam trap

The trap here is rushing to notify affected parties or the public before confirming which regulations apply, which can lead to legal penalties and inconsistent messaging.

67
MCQmedium

Which of the following is a key component of a vulnerability report that provides a high-level overview for management?

A.Remediation timeline
B.Executive summary
C.Findings by severity
D.Risk acceptance
AnswerB

The executive summary condenses technical findings into business risk and impact language, giving management a high-level overview without operational detail. It satisfies the audience-specific requirement, unlike the technical sections that enumerate vulnerabilities, affected assets, and remediation steps for practitioners.

Why this answer

The executive summary condenses findings for management to quickly understand the state of vulnerabilities.

68
MCQmedium

During an incident response, the SOC team identifies a data breach involving customer PII. Under GDPR, what is the maximum time frame to notify the supervisory authority?

A.96 hours
B.72 hours
C.24 hours
D.48 hours
AnswerB

72 hours is the correct timeframe under GDPR Article 33(1), which states that a data breach notification must be made to the competent supervisory authority 'without undue delay' and, where feasible, no later than 72 hours after the controller becomes aware of the breach. This period is a fixed regulatory deadline, and failure to meet it without a documented justification (e.g., complexity of investigation) can result in significant administrative fines.

Why this answer

GDPR Article 33 requires notification of the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is a hard regulatory deadline and applies to breaches involving customer PII. Failure to notify can trigger fines under Article 83.

Exam trap

CS0-004 often tests whether candidates confuse GDPR's 72-hour authority notification with the 'without undue delay' data-subject notification or with shorter sector-specific windows like 24 hours.

How to eliminate wrong answers

Option A is wrong because 96 hours exceeds the GDPR limit—no EU regulation uses a 96-hour breach notification window. Option C is wrong because 24 hours is the timeline used by some other regimes (e.g., certain NIS2 or sector-specific rules) but not GDPR. Option D is wrong because 48 hours is not specified in GDPR; it may be confused with internal escalation SLAs, not the regulatory deadline.

69
MCQmedium

During a security incident, the SOC team identifies indicators of compromise (IoCs) related to a new malware strain. Which type of threat intelligence report should be produced for the SOC team to enhance detection?

A.Tactical intelligence report with IoCs and detection signatures
B.Technical intelligence report on malware code analysis
C.Strategic intelligence report on global threat trends
D.Operational intelligence report on threat actor campaigns
AnswerA

Tactical threat intelligence focuses on the immediate, actionable technical details of an attack, such as IP addresses, file hashes, and specific YARA or Snort detection signatures. During an active security incident, SOC analysts rely on this real-time data to rapidly identify, scope, and contain malicious activity within the network.

Why this answer

Tactical threat intelligence focuses on immediate, actionable indicators such as file hashes, IP addresses, domain names, and YARA rules that SOC analysts can directly load into SIEM, IDS/IPS, or endpoint detection tools to enhance detection. Since the SOC team needs to detect the new malware strain, a tactical report with IoCs and detection signatures provides the specific technical artifacts required for signature-based and anomaly-based detection. This type of intelligence is consumed at the analyst level and is designed for machine-readable consumption, enabling rapid deployment of detection logic.

Exam trap

CS0-004 often tests the distinction between tactical, technical, operational, and strategic intelligence, and candidates frequently confuse tactical (IoCs for detection) with technical (malware analysis) or operational (campaign details) reports.

How to eliminate wrong answers

Option B is wrong because technical intelligence reports delve into malware reverse engineering, code analysis, and capabilities, which are more suited for threat researchers or malware analysts, not for immediate SOC detection enhancement. Option C is wrong because strategic intelligence reports address high-level trends, geopolitical risks, and long-term security posture for executives, lacking the granular IoCs needed for detection. Option D is wrong because operational intelligence reports cover threat actor campaigns, motivations, and upcoming attacks, which inform hunting and response planning but do not provide the direct detection signatures or IoCs that tactical intelligence does.

70
MCQmedium

An analyst needs to collect evidence for a compliance audit. Which type of evidence is most appropriate to demonstrate that access reviews are performed regularly?

A.Vulnerability scan reports
B.Access review reports
C.Configuration backups
D.Log exports of user activity
AnswerB

Access review reports provide direct, auditable evidence that an organization regularly evaluates user permissions against the principle of least privilege. These reports document the specific reviewers, the dates of the evaluations, and the formal decisions to approve or revoke access rights, satisfying strict compliance mandates.

Why this answer

Access review reports serve as direct evidence that reviews are conducted, showing dates and outcomes.

71
MCQhard

During a security incident, a SOC analyst identifies that customer PII has been exfiltrated. The company operates in multiple states and processes EU residents' data. Which of the following is the MOST critical immediate communication requirement?

A.Notify law enforcement within 24 hours
B.Notify affected customers within 48 hours
C.Notify the relevant data protection authority within 72 hours
D.Issue a press release within 24 hours
AnswerC

GDPR Article 33 explicitly mandates that in the event of a personal data breach, the controller must notify the competent supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to individuals' rights. This is a strict, legally binding timeline tested heavily on the CySA+ exam.

Why this answer

Notifying the relevant data protection authority within 72 hours is the most critical immediate communication requirement because the GDPR mandates that organizations report personal data breaches to the supervisory authority within 72 hours of becoming aware of the breach, especially when EU residents' data is involved. This is a legal obligation with strict timelines. Other notifications may be required but are not as immediately critical or universally mandated within that timeframe.

Exam trap

CS0-004 often tests the specific 72-hour GDPR notification requirement, while candidates may confuse it with other timelines like 24 or 48 hours for different notifications.

How to eliminate wrong answers

Option A is wrong because law enforcement notification is not universally required within 24 hours and varies by jurisdiction; it is not the primary immediate requirement under GDPR. Option B is wrong because notifying affected customers within 48 hours is not a specific GDPR requirement; the regulation requires notification to individuals without undue delay when high risk is present, but the 72-hour deadline applies to the authority. Option D is wrong because issuing a press release within 24 hours is not a legal requirement and could exacerbate the situation.

72
MCQmedium

A security analyst is preparing a quarterly vulnerability management report for IT operations managers. The report must help them prioritize remediation efforts across a large environment. Which metric is MOST useful to include for this audience?

A.Number of vulnerability scans completed successfully each month
B.Average CVSS base score of all open vulnerabilities across the enterprise
C.Total count of vulnerabilities discovered, grouped by severity rating
D.Percentage of critical vulnerabilities remediated within the defined SLA, segmented by business unit
AnswerD

This metric combines severity, timeliness, and organizational accountability. IT operations managers can see which business units are meeting remediation targets and which are falling behind, enabling targeted action. It directly reflects the effectiveness of the vulnerability management process and aligns with common SLA-driven remediation programs. This makes it highly actionable for operational prioritization and performance management.

Why this answer

IT operations managers need actionable metrics that tie remediation performance to accountability and risk reduction. The percentage of critical vulnerabilities remediated within SLA, broken down by business unit, provides clear visibility into which teams are meeting targets and where intervention is needed. This drives prioritization far better than raw counts, averages, or process metrics.

Exam trap

The trap here is focusing on volume or process metrics like total counts or scan completions, when operational audiences need outcome-based, accountability-driven metrics to prioritize work.

73
MCQmedium

A security analyst receives a threat intelligence report containing detailed Indicators of Compromise (IoCs) such as IP addresses, file hashes, and domain names. What is the MOST appropriate audience for distributing this type of report?

A.The Security Operations Center (SOC) team
B.External auditors
C.All employees in the organization
D.Senior executives and the board of directors
AnswerA

The Security Operations Center (SOC) team directly consumes tactical Indicators of Compromise (IoCs), such as malicious IP addresses, file hashes, and domain names, to update security monitoring tools. Integrating these feeds into SIEM, SOAR, and EDR platforms allows analysts to detect, investigate, and mitigate active threats in real time.

Why this answer

Tactical intelligence, such as IoCs, is most useful for frontline technical teams like the SOC, who can use it to detect and block threats. Executives typically receive strategic intelligence.

74
Multi-Selectmedium

A security analyst needs to provide threat intelligence to different audiences. Which TWO of the following are appropriate dissemination approaches?

Select 2 answers
A.Sending tactical intelligence with IoCs to the SOC team
B.Publishing operational intelligence on the company intranet
C.Discussing classified threat data in public forums
D.Sharing raw intelligence feeds with all employees
E.Providing strategic intelligence reports to executives
AnswersA, E

Tactical intelligence is time-sensitive, actionable data that directly supports day-to-day security operations. SOC teams require IoCs—such as malicious IPs, file hashes, and domain names—to detect and block immediate threats. By pushing this information to the SOC, analysts can operationalize it and update detection rules, SIEM queries, and EDR configurations in real time.

Why this answer

Option A is correct because tactical intelligence, which includes indicators of compromise (IoCs) such as IP addresses, hashes, and domains, is most actionable for the SOC team that monitors and responds to incidents in real time. Option E is correct because strategic intelligence reports are high-level, business-oriented summaries of threat trends and risks that help executives make informed decisions about security investments and risk posture. Option B is not appropriate because operational intelligence typically contains sensitive details about ongoing campaigns or adversary activity and should be shared only with authorized operational staff, not published broadly on the intranet.

Option C is wrong because discussing classified threat data in public forums would cause unauthorized disclosure and violate classification and confidentiality requirements. Option D is wrong because sharing raw intelligence feeds with all employees exposes unvetted, potentially sensitive data to people without the need or training to interpret it, increasing risk of misuse or leakage.

Exam trap

CS0-004 often tests the appropriate audience for different intelligence types, and candidates may incorrectly assume broader sharing is better, ignoring confidentiality and relevance.

75
MCQmedium

A vulnerability report for a critical application shows that a high-risk vulnerability has been accepted by the business owner. What should the analyst include in the report to document this decision?

A.A formal risk acceptance form signed by the business owner with a justification
B.The technical details of the vulnerability only
C.An automatic closure of the vulnerability ticket
D.A note that the vulnerability is low priority
AnswerA

Formal risk acceptance requires accountability and explicit authorization from the asset owner who bears the ultimate business risk. This document must detail the business justification for not remediating the flaw, alongside compensating controls, to satisfy regulatory compliance and internal governance frameworks.

Why this answer

Proper risk acceptance documentation requires a formal sign-off by the risk owner, typically including a justification and acceptance date.

Page 1 of 2 · 83 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Reporting and Communication questions.