CS0-003: Reporting & Communication
Reporting & Communication is one of the skill areas tested on the CySA+ (Cybersecurity Analyst) (CS0-003) exam. Below are free CS0-003 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of CS0-003 free, no signup.
The concept, in one picture
2 free CS0-003 Reporting & Communication questions
The security team at a regional hospital network is assembling its monthly vulnerability report for distribution to system owners. Which of the following should the team include in the report? (Choose two.)
- ✓ A list of the hosts and assets impacted by each finding
- The incident response playbook the SOC follows during breaches
- The service-level agreement terms negotiated with the scanning vendor
- ✓ A risk or severity score for each identified vulnerability
- Lessons learned from the organization's most recent incident
- A security awareness education plan for clinical staff
A vulnerability report exists so system owners can understand and act on scan results, which means it must identify which hosts are affected by each finding and how severe each finding is via a risk or severity score — together these drive remediation prioritization. An incident response playbook is an operational SOC procedure, not scan output. Vendor SLA terms belong in contract documentation, not a technical findings report. Lessons learned are produced during the post-incident phase of incident response, not vulnerability reporting. An awareness education plan is a training program deliverable and has nothing to do with communicating scan results.
A post-incident review at a manufacturing company finds that an attacker moved laterally through the environment for six weeks before exfiltrating design documents, and no alert fired during that period. The CISO wants the SOC to surface this kind of activity much sooner. Which of the following KPIs should the SOC prioritize improving?
- Mean time to remediate
- Service-level agreement compliance rate
- ✓ Mean time to detect
- Mean time to respond
The failure described is a detection gap: the intrusion ran for six weeks with no alert, so the metric that measures the interval between compromise and discovery — mean time to detect (MTTD) — is the one to drive down. Mean time to respond and mean time to remediate both start their clocks only after the activity has been detected, so improving them would not have shortened the six weeks of silence. SLA compliance rate measures whether operational commitments such as ticket-handling or uptime targets are met and says nothing about how quickly hidden attacker activity is discovered.
Practice CS0-003 free
The first 10 questions of every exam are free. No signup, no email wall.
Start practicing →Get a free CS0-003 study plan by email
A short plan to work through CS0-003 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.