19 Vulnerability Reporting & Communication Practice Questions & Answers
Every Vulnerability Reporting & Communication practice question from the CompTIA CySA+ Practice Test, with the correct answer and a short explanation.
Start practice test →1. A validated finding must be written up for the team that owns WEB-PUB-04, an internet-facing reporting server running an outdated web server build that a working exploit reached during testing. Which set of elements makes the write-up actionable for that team?
- A.The scanner plugin identifier, the raw plugin output, the scan start time, the credential profile used and the scanner version.
- B.The business unit's risk appetite, the mapped framework control, the audit cycle affected and the current compliance status.
- C.The affected host and service, the condition found, what the test demonstrated, the recommended fix and the risk of inaction.✓ Answer
- D.The catalogue identifier, the numeric severity rating, a link to the vendor advisory and the count of affected hosts.
A finding is actionable when it tells the owning team what is affected, what is wrong, what the evidence actually proves, what to change, and what happens if nothing changes. Scanner metadata, catalogue numbers and framework mappings may travel with a finding, but none of them tell the team which action to take or why it matters.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — vulnerability management reporting and communication (affected hosts, recommendations and remediation, impact)Report a problem with this question
2. An analyst emails a 400-page raw scanner export to an application team and nothing is remediated; the team replies that it cannot use the file. What MOST distinguishes a vulnerability report from that export?
- A.A report attaches the full raw plugin text for every finding so the receiving team never needs to query the scanner itself.
- B.A report validates and de-duplicates the findings, groups them by owner and asset, and states the action and priority for each group.✓ Answer
- C.A report converts the export into a spreadsheet, sorts every row by severity and colours the rows so the highest ratings appear first in the file.
- D.A report appends the scan configuration, credential profile and plugin feed date so any reader can reproduce each result exactly.
A raw export is evidence, not a report: it is unvalidated, duplicated across hosts and addressed to nobody. The reporting work is validation, de-duplication, assignment to an owner and a stated priority and action, which is what converts data into something a team can schedule.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — vulnerability report content and stakeholder-focused communicationReport a problem with this question
3. A risk committee has fifteen minutes on an internet-facing flaw in the payments path affecting 40 hosts; the fix needs a maintenance window that pauses settlement for two hours. Which content BEST fits that audience?
- A.A host-by-host list with target patch versions, proposed maintenance windows and the engineer assigned to each of the 40 hosts.
- B.A control-by-control mapping of the flaw to the framework, with the audit finding that each uncovered control would generate.
- C.The business exposure, the decision the committee must make about the settlement pause, the cost and the risk of deferring.✓ Answer
- D.The CVE identifiers, the affected build numbers and the scanner output that first surfaced the flaw on each of the 40 hosts.
Executive and committee audiences are being asked to decide, fund or accept something, so the report must carry impact, options, cost and residual risk. Identifiers, host lists and control mappings are correct content for the owner, the engineer and the auditor respectively, which is why they are tempting and still wrong here.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — stakeholder identification and communication; executive summary contentReport a problem with this question
4. The same payments-path flaw must now be written as a remediation ticket for the platform team that owns the 40 hosts. Which content BEST fits that audience?
- A.The indicators of compromise and the log queries the security operations centre would use to detect exploitation attempts.
- B.The estimated financial impact, the organisation's risk appetite and the committee that will decide whether to fund the work.
- C.The quarter-by-quarter trend of open critical findings for the business unit, with a comparison against peer business units.
- D.The exact hosts, the version to install, the agreed change window, the accountable owner and how the fix is verified.✓ Answer
The owning team needs to change something, so the communication must say which hosts, which version, in which window, under whose name and how success is checked. Financial framing belongs to the committee, trend charts to management and detection content to the operations centre, so each of those is the right artifact aimed at the wrong reader.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — action plans and audience-appropriate communication to asset ownersReport a problem with this question
5. For a year an analyst has labelled almost every finding 'critical — remediate immediately', including findings on isolated hosts with no known exploit. Owners now ignore the labels. What is the MOST accurate account of what this practice cost?
- A.Severity stopped carrying information, so owners now defer everything equally and genuinely urgent findings no longer earn priority.✓ Answer
- B.The reporting became more defensible, because rating every finding at the top severity can never understate the real risk.
- C.Owners will remediate faster overall, because a uniformly urgent queue removes any argument about which finding comes first.
- D.The severity ratings stayed accurate, because severity is the analyst's judgement and asset owners must accept it as issued.
Severity is useful only because it discriminates between findings; inflating it removes the discrimination and the queue reverts to whatever the owner felt like doing. The analyst's credibility is the mechanism at stake, because once labels stop predicting real urgency the owner has no reason to treat the next one as urgent either.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — risk communication and analyst credibility; severity must reflect validated exposure and exploitabilityReport a problem with this question
6. A monthly vulnerability report has always shown one number: open findings on the last day of the month. Leadership says it cannot tell whether exposure is being reduced. Which addition does the MOST to answer that question?
- A.A refreshed ranking of the ten highest-severity findings currently open, with the numeric severity rating for each of them.
- B.Findings opened against findings closed each month, plus how long the open ones have been open, so direction is visible.✓ Answer
- C.The number of scans executed each month and the number of plugins in the scanner's feed, to show the effort being expended.
- D.The count of open findings per business unit, so the units carrying the largest raw totals can be identified and named.
A single end-of-month count is a snapshot and cannot show direction: the same total can hide a team closing nothing or closing as fast as new findings arrive. Comparing arrivals with closures and reading how long open items persist is what tells leadership whether exposure is actually shrinking.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — trend analysis and vulnerability metrics (open versus closed, aging, recurrence)Report a problem with this question
7. For four consecutive quarters the same insecure service configuration has been remediated on production servers and then reappeared on servers built after the fix. Which reading is best supported, and what should the report recommend?
- A.The defect lives in the build image and change process, so the report should recommend correcting its origin.✓ Answer
- B.The remediation was never actually performed, so the report should escalate the owner's non-compliance to management.
- C.The scanner is reporting a false positive, so the report should record the item as an approved documented exception.
- D.Recurrence here is ordinary churn, so the report should re-issue the same tickets and keep tracking time to remediate.
Recurrence on newly built hosts after a verified fix points upstream, to the gold image, provisioning template or change process that keeps reintroducing the weakness. A recurring-report finding of this shape should recommend fixing the source rather than reissuing the same per-host tickets forever.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — recurrence as a reported metric; configuration management as a remediation recommendationReport a problem with this question
8. A report breaks open findings down by age. Most high-severity findings have been open more than 180 days, while low-severity findings close within a week, and the total number of open findings has not changed. What does this profile MOST likely indicate?
- A.The high-severity ratings are inflated, so the severity scale should be recalibrated before the next reporting cycle.
- B.Scanning runs far too often, so reducing the scan cadence would let owners close the older findings already in the queue.
- C.Remediation effort is flowing to the easiest fixes, so the aging profile, not the total, should drive the discussion.✓ Answer
- D.The programme is healthy, because the closure rate is high and most tickets are being closed inside a single week.
Aging read together with severity exposes where the work is really going: a healthy closure count built entirely from low-severity items leaves the dangerous exposure untouched for months. That is why the recurring report should present the age distribution of open findings by severity rather than a single total.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — vulnerability aging and time-to-remediate reporting broken out by severityReport a problem with this question
9. A quarterly report leads with '98% of findings remediated within the agreed window'. A footnote records that the scan reached 61% of known assets and that an acquired subsidiary's network has never been scanned. What belongs at the top of the report?
- A.The scanner credential failures, because authenticated coverage is a scan configuration matter, not a report item.
- B.The severity breakdown of the remediated findings, because it shows where the effort was actually spent.
- C.The remediation rate, because it is the outcome the programme is accountable for and the trend is favourable.
- D.The coverage gap, because an unscanned estate means the remediation figure describes only the portion that was measured.✓ Answer
A remediation percentage is a ratio over the findings that were discovered, so it says nothing about assets never examined; the unscanned network is the larger unknown and belongs in front of the reader, not in a footnote. Reporting coverage alongside outcomes is what keeps the headline figure from being read as whole-estate assurance.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — scan coverage and asset inventory reported alongside remediation metricsReport a problem with this question
10. A clinical device cannot be patched by the customer and the business decides to keep it in service. The analyst must present this as a risk acceptance in the vulnerability report. What must the record contain for the acceptance to stand?
- A.The severity rating, the asset's criticality and confirmation that the risk sits below the reporting threshold.
- B.The vendor's statement that no patch exists and the ticket number showing the item left the remediation queue.
- C.The risk accepted, the named owner with authority to accept it, the measures in place and a date for review.✓ Answer
- D.The analyst's recommendation, the scanner evidence and a written note that security closed the finding as accepted risk.
Acceptance is a business decision, so the report must make the decision itself visible: what is being accepted, by whom under what authority, what compensating measures reduce it and when it will be looked at again. Without a named accepting owner and a review date it is not an acceptance, only an unremediated finding that stopped being tracked.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — risk acceptance and communication of risk-management decisions to stakeholdersReport a problem with this question
11. A development team wants to keep running an unsupported database release for two more release cycles, which the hardening standard forbids. How should this deviation be communicated and recorded?
- A.As a closed finding, with a scanner suppression applied so the host stops appearing in the reports that follow.
- B.As a time-bound exception that names the approver, the compensating controls, the expiry date and the residual risk accepted.✓ Answer
- C.As an informal agreement between the analyst and the team, revisited whenever the next quarterly scan is executed.
- D.As a revision to the hardening standard, since the standard should describe what the production environment runs today.
A deviation from policy is only defensible when someone with authority approved it for a stated period, with compensating controls and a known residual risk, so that it expires by default instead of quietly becoming permanent. Rewriting the standard to match reality removes the control, and suppressing the finding hides it from the very report meant to track it.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — exceptions, compensating controls and documented deviations in vulnerability reportingReport a problem with this question
12. A critical internet-facing finding has passed its agreed remediation date twice. The system owner acknowledges the emails but schedules no work. What is the correct next step for the analyst?
- A.Publish the finding on a company-wide channel so that visibility and peer pressure push the owner into scheduling it.
- B.Escalate along the documented path to the owner's management and the risk function, attaching the record of attempts.✓ Answer
- C.Apply the patch during the next maintenance window, since the security team ultimately carries the risk for the asset.
- D.Close the item as a business-accepted risk, since the owner's continued inaction is in effect an acceptance of it.
Escalation is a defined path, not an improvisation: the analyst raises the unaddressed exposure to the owner's management and the risk function with evidence of what was communicated and when. Broadcasting it, patching someone else's system, or treating silence as acceptance all bypass the accountable decision-maker.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — escalation paths and action-plan governance when remediation stallsReport a problem with this question
13. A system owner rejects a finding, stating that the installed build number does not match the version the scanner claims is present. The analyst believes the detection is sound. How should the analyst handle the disagreement?
- A.Accept the owner's version statement, close the item as a false positive and note the closure in the report.
- B.Leave the finding as written and list the team as non-compliant until it produces vendor documentation.
- C.Re-test the host together with the owner, show the evidence behind the result, and record the corrected outcome.✓ Answer
- D.Escalate to the owner's director at once, because disputing a scanner result is an attempt to avoid the work.
A disputed finding is settled with evidence, jointly, and the outcome is written down either way, because both a confirmed finding and a genuine false positive are useful records. Escalating first, or conceding on the owner's word alone, both trade the evidence for a position and damage the working relationship the analyst depends on.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — communication with asset owners; validation outcomes (true positive, false positive) recorded in the reportReport a problem with this question
14. An integration partner emails the analyst directly asking for full details of an unremediated flaw in the shared interface, before the organisation has agreed what to disclose. What should the analyst do?
- A.Refuse all further contact and delete the request, because any discussion of an open finding creates legal liability.
- B.Route the request through legal and the communications owner, and share only what the approved process releases.✓ Answer
- C.Publish a summary on the company's blog first, so that customers hear about the flaw from the organisation itself.
- D.Send the partner the relevant scan output, since the partner's own integration is affected and needs the technical detail.
Details of an unremediated flaw are exploitable information with contractual and legal consequences, so the decision to disclose belongs to legal and the communications owner, not to the individual analyst. Refusing all contact is also wrong: the request is legitimate and must be answered through the approved channel rather than ignored or answered unilaterally.
Source: CompTIA CySA+ CS0-004 Objective 4.1 / 4.2 — stakeholder identification; external communication routed through legal and communicationsReport a problem with this question
15. An external assessor asks for evidence that the cardholder data environment met its required external scanning obligation for the past period. The analyst has last night's internal authenticated scan export. Which artifact does the assessor need?
- A.The executive dashboard showing the quarter's remediation percentage against the programme's own internal targets.
- B.The internal authenticated scan export for the same subnet, since it detects strictly more issues than an external scan.
- C.The action plan listing every open finding together with its owner, its due date and the compensating controls in place.
- D.The passing external scan record from the approved scanning process, retained as the attestation for that period.✓ Answer
A scan export is technical evidence the organisation produced for itself, whereas a compliance obligation is met by the specified assessment performed the specified way and retained for the period in question. A more thorough internal scan does not substitute, because the obligation is about the prescribed method and record, not about which tool finds more.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — compliance reports and attestation of findings versus technical scan reportsReport a problem with this question
16. A managed security appliance carries a high-severity operating system flaw. The vendor contract states that support is void if the customer applies operating system patches itself. What should the report recommend?
- A.A compensating control plus a documented, time-bound exception, while the real fix is pursued with the vendor's support.✓ Answer
- B.Acceptance of the risk with no further action, because the contract removes any ability to remediate the flaw at all.
- C.Removal of the finding from the report, because a device the organisation may not patch is outside its scan scope.
- D.Immediate patching by the local administrators, because an unpatched high-severity flaw outweighs a support contract.
A vendor or contractual restriction is a recognised inhibitor to remediation, and an inhibitor changes how the risk is treated rather than whether it is reported. The reportable answer is a compensating control that reduces exposure now, a documented exception with an expiry, and pressure on the vendor to deliver the supported fix.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — inhibitors to remediation (proprietary systems, contractual constraints) and compensating controlsReport a problem with this question
17. Three requests arrive in one week: an external auditor wants proof that a required control was met, a director wants to see whether her division's posture improved over four quarters, and a server team wants to know what to change this month. Which set of artifacts matches the three requests, in that order?
- A.A compliance report, a risk scorecard and an action plan naming owners and dates.✓ Answer
- B.A risk scorecard, a raw scan export and an executive summary of the open findings.
- C.A raw scan export, an action plan and a compliance report naming the failed controls.
- D.An executive summary, a compliance report and a raw scan export of the affected hosts.
Each artifact has a purpose: a compliance report attests control-by-control status to an outside party, a risk scorecard aggregates posture over time for a business unit, and an action plan tells a team what to change, who owns it and by when. Handing an auditor a scan export or a director a host list is the classic right-artifact-wrong-purpose error.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — report types: compliance reports, risk scores/scorecards, action plans, executive summariesReport a problem with this question
18. An action plan row reads: 'Upgrade the authentication service on three internet-facing hosts. Owner: Platform team. Due: end of next quarter.' The flaw appears in a public catalogue of vulnerabilities known to be exploited. What is the MOST important defect in the row?
- A.No individual is accountable, no dependency is stated and no escalation applies if the date slips.✓ Answer
- B.No numeric severity score is recorded, so a reader cannot confirm the finding was rated correctly.
- C.No framework control is mapped to the flaw, so the audit trail for the remediation is incomplete.
- D.No scanner plugin identifier is given, so the owner cannot reproduce the detection before starting.
An action plan exists to make work happen, so each row needs a person who answers for it, the prerequisites the work depends on, and what occurs if the date passes; a team name and a quarter-end date give nobody a reason to act this week. The other omissions are documentation gaps that do not stop the upgrade from being scheduled.
Source: CompTIA CySA+ CS0-004 Objective 4.1 — action plan elements: owner, dependency, escalation, and due date tied to exposureReport a problem with this question
19. An analyst has an internal AI assistant draft the monthly vulnerability narrative. The draft states that two hosts were remediated and cites a CVE that appears in no scan result. What must happen before the narrative is distributed?
- A.The draft is pasted into a public model for a second opinion, since two models rarely repeat one error.
- B.The draft goes out with a note that it was machine-generated, so readers can weigh the findings themselves.
- C.The assistant is retrained on the disputed hosts so later narratives no longer carry the error.
- D.The analyst verifies each claim against the scan data of record and remains accountable for whatever is issued.✓ Answer
A generated draft can assert remediation that never happened and invent identifiers, so every claim must be reconciled with the authoritative scan and ticket data before publication, with a named human answerable for the result. Labelling the draft transfers the checking to the reader, and pasting vulnerability detail into an external model exposes sensitive data as well.
Source: CompTIA CySA+ CS0-004 Objective 4.1 / 4.2 — AI-assisted documentation with human verification; AI risks (hallucination, data exposure) in reportingReport a problem with this question
Practice questions based on the CompTIA CySA+ exam objectives. This site is not affiliated with or endorsed by CompTIA, and these are not real exam questions. CompTIA refreshes this exam periodically, runs two versions side by side during a transition, and sets the exam length, passing standard and eligibility terms — confirm the current objectives and the live exam code with CompTIA before you register. The real exam also includes performance-based items that a multiple-choice bank cannot reproduce, so pair this with hands-on practice. Official CySA+ exam objectives →