CS0-003 Reporting and Communication Practice Question
During a security incident involving a potential data breach, the CISO asks you to prepare a communication for the board of directors. What is the MOST important aspect to emphasize in this communication?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The financial impact, reputational risk, and potential regulatory penalties
Board members are non-technical stakeholders who need to understand the business impact. The communication should translate technical details into financial, reputational, and regulatory consequences.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The specific malware used and its technical attributes
Why it's wrong here
The board of directors requires a strategic overview of an incident's implications, not granular technical details like specific malware names or their attributes. Such information is critical for the Security Operations Center (SOC) and incident responders to analyze, contain, and eradicate the threat effectively. Presenting highly technical data to the board would obscure the overarching business risks and divert focus from strategic decision-making regarding organizational resilience and risk posture.
- ✗
The names of the IT staff who first detected the incident
Why it's wrong here
Identifying the specific IT staff members who initially detected the incident is an operational detail relevant for internal team recognition or post-incident review, but it holds no strategic value for a board of directors. The board's focus is on the overall organizational response, the effectiveness of security controls, and the leadership's handling of the crisis, not on individual personnel's initial actions. Presenting individual names would distract from the collective organizational accountability and the strategic oversight responsibilities of the board.
- ✗
A step-by-step timeline of the incident response actions taken so far
Why it's wrong here
A detailed, step-by-step timeline of incident response actions is an operational report crucial for incident responders, forensic analysts, and post-incident review teams to understand the sequence of events and validate response efficacy. However, for a board of directors, such granular detail is excessive and can obscure the high-level status and strategic progress of the incident management efforts. The board primarily needs an executive summary of the incident's current status, the overall strategy for containment and recovery, and the projected impact, rather than a minute-by-minute account.
- ✓
The financial impact, reputational risk, and potential regulatory penalties
Why this is correct
For a board of directors, information regarding the financial impact, potential reputational damage, and regulatory penalties is paramount because these directly relate to their fiduciary duties and the long-term strategic health of the organization. Understanding the monetary losses, the erosion of public trust, and the legal ramifications enables the board to assess the overall business risk effectively. This critical information guides their strategic decisions on resource allocation, risk mitigation strategies, and governance improvements to protect shareholder value and ensure compliance.
Go deeper
Related to this question
Learn chapter
Incident Categories and Severity
Key term
Impact
Impact is the measure of the potential damage or harm that a risk event could cause to an organization's assets, operations, or reputation.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.