Skip to content

Reporting and Communication Questions

Practice questions for Reporting and Communication topic in CompTIA CySA+. 16 questions covering this domain.

16 questions4 easy8 medium4 hard
Q1
medium

A security analyst must communicate the results of a vulnerability assessment to a non-technical business unit manager. Which approach best aligns wit...

Q2
medium

After a significant security incident, the incident response team must formally notify senior leadership and potentially regulators. Which reporting e...

Q3
hard

An organization's security team has completed a vulnerability assessment and found that 30% of critical vulnerabilities remain unpatched beyond the SL...

Q4
easy

Which term describes the measurable values used to evaluate how effectively an organization is achieving its security objectives?

Q5
hard

Following a major ransomware incident affecting critical infrastructure, the CISO must present a lessons learned briefing to the board of directors. W...

Q6
medium

A compliance report for a financial services organization indicates a vulnerability remediation inhibitor due to a legacy system that cannot be patche...

Q7
easy

What is the primary purpose of a vulnerability management report provided to executive stakeholders?

Q8
medium

During a post-incident review, the team identifies that the initial detection time was significantly longer than expected due to missing log sources i...

Q9
medium

A security analyst must produce a compliance report for a PCI DSS audit showing the organization's vulnerability management posture. Which metrics and...

Q10
medium

An organization's vulnerability management program produces reports showing that the mean time to remediate (MTTR) for critical vulnerabilities has in...

Q11
easy

What is the purpose of an incident response 'lessons learned' report?

Q12
easy

Which metric measures the average time from when an incident is detected to when it is fully resolved?

Q13
hard

A security analyst is preparing an action plan for a stakeholder after completing a vulnerability assessment. The stakeholder asks how to prioritize r...

Q14
hard

An organization's security team has improved its MTTD (mean time to detect) from 30 days to 4 days over two quarters by improving log ingestion covera...

Q15
medium

After a data breach, an organization must notify affected customers per regulatory requirements. Which communication principle should guide the conten...

Q16
medium

A security analyst must prepare a vulnerability management action plan for a business unit that owns a customer-facing e-commerce application with thr...

Sign in to see all 16 questions

Create a free account to browse all questions — completely free during our launch phase.