Courseiva

CCNA Reporting and Communication Questions

8 of 83 questions · Page 2/2 · Reporting and Communication · Answers revealed

76
MCQeasy

Which of the following is a key performance indicator (KPI) for measuring the efficiency of patch management?

A.Mean time to respond (MTTR)
B.Number of open vulnerabilities
C.Phishing simulation click rate
D.Patch SLA compliance %
AnswerD

Patch SLA compliance percentage is a primary key performance indicator (KPI) because it directly measures how effectively the IT and security teams meet established service-level agreement deadlines for deploying updates. By tracking the percentage of systems patched within the mandated window (e.g., critical patches within 72 hours), organizations can quantitatively evaluate the efficiency and consistency of their vulnerability management lifecycle.

Why this answer

Patch SLA compliance % directly measures how efficiently the patch management process meets its defined service-level targets — the percentage of patches applied within the agreed remediation window. This is a process-efficiency KPI because it evaluates the speed and consistency of the patching workflow against a defined benchmark. MTTR measures incident response, not patch throughput, and open vulnerability count reflects exposure rather than process efficiency.

Exam trap

CS0-004 often tests the distinction between process-efficiency KPIs (SLA compliance, patch cycle time) and outcome/risk metrics (open vulnerabilities, MTTR), so candidates who grab the most 'security-sounding' metric pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because MTTR (mean time to respond) is an incident-response metric that measures how quickly security teams react to incidents, not how efficiently patches are deployed. Option B is wrong because the number of open vulnerabilities is a risk/exposure metric — it can rise or fall for reasons unrelated to patch process efficiency (new scans, new CVEs, false positives). Option C is wrong because phishing simulation click rate measures security awareness training effectiveness, which is unrelated to patch management.

77
MCQeasy

A security analyst needs to communicate the business impact of a newly discovered critical vulnerability to the executive team. Which of the following is the BEST approach?

A.Send the raw vulnerability scan report.
B.Explain the vulnerability in layman's terms and estimate potential financial loss.
C.Recommend immediate patching without further context.
D.Provide a detailed CVSS score and exploit code.
AnswerB

This is the correct approach because it strips out jargon and instead frames the exposure as a concrete estimate of financial loss, which is the currency executives use to weigh competing priorities. Plain-language framing paired with a dollar figure lets leadership approve remediation resources without needing a technical background.

Why this answer

Translating technical risk into business terms (financial, reputational, regulatory) helps executives understand the impact and make informed decisions.

78
MCQhard

During an incident, the SOC team identifies indicators of compromise (IoCs) that may affect partners. According to best practices, what should the analyst do first?

A.Follow the incident response communication plan
B.Wait until the incident is fully resolved
C.Post the IoCs on a public threat sharing platform
D.Directly notify all affected partners
AnswerA

Adhering to the pre-established incident response communication plan ensures that all internal and external stakeholders are notified in a controlled, legally compliant, and authorized manner. This plan defines specific roles, escalation paths, and approved channels, preventing unauthorized disclosures that could compromise the active investigation or violate regulatory requirements.

Why this answer

An incident response plan should define communication procedures; typically, the team should escalate internally to leadership who can authorize external notifications.

79
MCQmedium

A security analyst is preparing a vulnerability report for the IT operations team. Which section should provide a high-level overview of the organization's risk posture?

A.Risk acceptance
B.Executive summary
C.Remediation timeline
D.Findings by severity
AnswerB

The executive summary condenses findings into a high-level view of overall risk posture, enabling the IT operations team to grasp severity and priorities without reading technical detail. It satisfies the stem's requirement for a high-level overview, whereas detailed vulnerability listings and remediation steps are granular.

Why this answer

The executive summary provides a concise overview of key findings and risk posture for management.

80
Multi-Selecthard

A threat intelligence analyst has produced a report containing specific Indicators of Compromise (IoCs) such as IP addresses, domain names, and file hashes. Which TWO audiences are most appropriate for this type of intelligence? (Select TWO.)

Select 2 answers
A.Board of directors
B.SOC analysts
C.Executive leadership
D.Incident responders
E.Network engineers
AnswersB, D

SOC analysts are the primary consumers for a report consisting of technical IoCs, as they operationalize these indicators into detection logic such as SIEM signatures and alert rules. The report should be structured to support correlation with telemetry, enabling prioritization and investigation of matching events. For the SOC, IoCs serve as the foundational input for proactive threat detection and ongoing security monitoring.

Why this answer

SOC analysts (B) are a primary consumer of tactical IoCs because they monitor SIEM alerts, tune detection rules, and hunt for the listed IP addresses, domains, and file hashes in day-to-day security operations. Incident responders (D) also need these atomic indicators to scope and contain active compromises, for example by searching endpoints for the specified file hashes or blocking the malicious domains and IPs at the perimeter. Both roles operate at the tactical level where concrete, machine-readable indicators drive immediate detection and response actions.

By contrast, the board of directors (A) and executive leadership (C) consume strategic intelligence such as risk trends, business impact, and threat landscape summaries, not raw IoCs. Network engineers (E) focus on routing, switching, and infrastructure availability, so while they may implement blocks, they are not a primary audience for interpreting threat intelligence reports.

Exam trap

CS0-004 often tests the confusion between tactical and strategic intelligence audiences, tempting candidates to select 'executive leadership' or 'board' because those roles sound authoritative, when in fact they consume strategic, not atomic, intelligence.

81
MCQmedium

During a security incident, the incident response team has identified that a phishing email led to credential theft and lateral movement. Which component of the incident report should detail the sequence of events from initial compromise to containment?

A.Root cause analysis
B.Impact assessment
C.Lessons learned
D.Timeline
AnswerD

A timeline is a critical incident response artifact that chronologically documents the exact sequence of events, including initial vector detection, lateral movement, containment actions, and system restoration. Maintaining an accurate timeline is essential for correlating disparate log sources, establishing a clear chain of custody, and providing a structured narrative for forensic analysis, legal compliance, and stakeholder reporting.

Why this answer

The correct answer is D because the timeline component of an incident report details the chronological sequence of events from initial compromise to containment, including the phishing email, credential theft, and lateral movement. This provides a clear narrative for understanding the incident's progression. The timeline is specifically designed to capture the sequence of events.

Exam trap

CS0-004 often tests the confusion between timeline and root cause analysis; candidates may think root cause analysis includes the sequence of events, but the timeline is the component that details the chronological progression.

How to eliminate wrong answers

Option A is wrong because root cause analysis identifies the underlying cause of the incident, not the sequence of events; it answers 'why' rather than 'when' and 'what happened next.' Option B is wrong because impact assessment quantifies the damage or business impact, such as data loss or downtime, not the chronological sequence. Option C is wrong because lessons learned focuses on improvements and recommendations for future prevention, not the detailed sequence of events.

82
Multi-Selectmedium

An incident responder is documenting the root cause of a data breach. Which THREE components are essential to include in the root cause analysis section of the incident report? (Select THREE.)

Select 3 answers
A.The technical vulnerability exploited
B.The number of records affected
C.The name of the employee who clicked the phishing email
D.Human factors, such as lack of training
E.Process failures that allowed the vulnerability to exist
AnswersA, D, E

Documenting the technical vulnerability exploited is central to root cause analysis because it identifies the specific weakness—such as an unpatched CVE, SQL injection, or misconfigured S3 bucket—that allowed the initial compromise. Without this technical detail, the response team cannot prescribe a targeted fix (e.g., patch, configuration change, or WAF rule) to prevent recurrence. The root cause is inseparable from the exact flaw that made the attack viable.

Why this answer

Option A is correct because the root cause analysis must identify the specific technical vulnerability that was exploited, such as an unpatched CVE, misconfigured service, or weak authentication mechanism, since this is the direct technical weakness enabling the breach. Option D is correct because human factors like insufficient security awareness training or failure to follow procedures are legitimate root causes that explain why the initial compromise succeeded. Option E is correct because process failures, such as missing patch management, inadequate access reviews, or absent change control, describe the systemic conditions that allowed the vulnerability to persist and are central to root cause analysis.

Option B is not part of root cause analysis; the number of records affected is an impact or scope metric reported elsewhere in the incident report. Option C is not essential to root cause analysis; naming the specific employee who clicked the phishing email assigns individual blame rather than identifying the underlying human-factor or process cause, and may raise privacy concerns.

Exam trap

CS0-004 often tests the distinction between impact metrics (records affected) and causal factors — candidates pick 'number of records affected' because it feels important, but RCA is about why, not how much.

83
Multi-Selecthard

A financial services organization experienced a ransomware incident that encrypted several file servers. The CISO must deliver a post-incident report to the board of directors and the audit committee. The report must communicate both the business impact and the effectiveness of the response. Which of the following should be included in this executive-level report? (Choose two.)

Select 2 answers
A.The complete raw packet capture from the initial compromise vector
B.A timeline of key response actions and the measured effectiveness of containment, eradication, and recovery
C.A quantified estimate of financial loss, including downtime, recovery costs, and regulatory exposure
D.The full malware binary hash list and YARA rule syntax used during triage
E.A detailed list of every file that was encrypted, including full directory paths
AnswersB, C

An executive report should demonstrate how well the organization responded and where improvements are needed. A concise timeline with effectiveness metrics for containment, eradication, and recovery shows whether controls worked and where gaps exist. This helps leadership assess resilience and prioritize investments. It is a standard component of post-incident reporting for senior stakeholders.

Why this answer

Executive-level post-incident reports must translate technical events into business language. Quantifying financial loss and presenting a timeline with response effectiveness give the board the information they need to evaluate risk, resilience, and investment priorities. Technical artifacts like packet captures, hashes, and file lists belong in operational reports, not board communications.

Exam trap

The trap here is assuming that more technical detail always makes a report more credible, when executive audiences actually need summarized business impact and response effectiveness.

← PreviousPage 2 of 2 · 83 questions total

Ready to test yourself?

Try a timed practice session using only Reporting and Communication questions.