Courseiva
Reporting and Communication →mediumMultiple Choice

CS0-003 Reporting and Communication Practice Question

Which of the following BEST describes the purpose of a risk register in the context of reporting and communication?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To provide a structured way to track identified risks, their likelihood, impact, and mitigation actions

A risk register is a central document that captures identified risks, their assessments, mitigation plans, and status. It supports ongoing risk management and communication to stakeholders.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To document vulnerabilities found during scans

    Why it's wrong here

    Raw vulnerability findings from scan tools live in a vulnerability management system or ticketing platform where they are tracked through discovery, verification, and patching; a risk register operates at a higher governance level, capturing the business risk a vulnerability represents rather than serving as its scan-result repository.

  • ✗

    To record all security incidents and their outcomes

    Why it's wrong here

    Incident logs and after-action records documenting what happened during a security event and how it was resolved belong in incident management or SIEM case management systems; a risk register instead tracks forward-looking, potential risks and their treatment status, not a historical account of incidents that already occurred.

  • ✗

    To list compliance requirements and deadlines

    Why it's wrong here

    Compliance requirements and audit deadlines are typically maintained in a GRC (governance, risk, and compliance) tracker or compliance calendar; while specific compliance gaps can be entered as individual risk items, the register's core purpose is broader risk tracking, not serving as the master list of regulatory obligations.

  • ✓

    To provide a structured way to track identified risks, their likelihood, impact, and mitigation actions

    Why this is correct

    A risk register is the central governance artifact that catalogs identified risks alongside their likelihood, potential impact, assigned owner, and planned or in-progress mitigation actions, giving leadership a consistent, prioritized view for reporting and decision-making across the organization's entire risk landscape rather than any single risk source.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.