TechNuggets Academy

Reporting and Communication

Free CompTIA Cybersecurity Analyst (CySA+) practice — 6 questions on Reporting and Communication, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Reporting and Communication
A vulnerability management team identifies a critical CVE affecting an ICS controller in a manufacturing plant. The third-party vendor's support contract states that any firmware update must be scheduled through the vendor and can only occur during a bi-annual maintenance window, delaying remediation by four months. Which of the following BEST describes this remediation inhibitor?
An SLA is a binding contractual agreement with a vendor that defines support terms, including maintenance windows and change scheduling, and is the correct classification when a vendor contract dictates when patching can occur.
Question 2 of 6 · Reporting and Communication
An incident timeline reconstruction shows an attacker gained initial access to a workstation on Day 0, but the SOC did not identify anomalous C2 beaconing until Day 12. Which metric captures this Day 0-to-Day 12 gap?
MTTD measures the elapsed time between when a compromise actually occurs and when the security team identifies it, which is exactly the Day 0-to-Day 12 window described.
Question 3 of 6 · Reporting and Communication
During a ransomware incident affecting a hospital's patient scheduling system, the CISO must brief the board of directors 30 minutes before a scheduled press conference. Which report characteristic is MOST appropriate for this audience?
Board-level stakeholders need business-impact framing, current status, and recovery expectations in plain language to make decisions and speak publicly; deep technical detail is not actionable for this audience.
Question 4 of 6 · Reporting and Communication
When drafting a root cause analysis (RCA) report following a data breach, which technique/section is used to iteratively ask 'why' a failure occurred until the systemic, underlying cause is identified, rather than stopping at the technical symptom?
The five whys technique is specifically used in RCA to move past the surface-level technical symptom by repeatedly asking why until the systemic root cause (process, policy, or control failure) is uncovered.
Question 5 of 6 · Reporting and Communication
A retail organization must submit quarterly vulnerability scan results to maintain PCI DSS compliance. The latest scan found three high-severity vulnerabilities on a point-of-sale system, and remediation is still pending a scheduled patch cycle. Which document is required to explain the outstanding findings and remediation timeline to the acquiring bank?
When findings remain unresolved, PCI DSS requires documentation of compensating controls and a clear remediation action plan with a timeline so the acquiring bank can assess ongoing risk exposure and compliance intent.
Question 6 of 6 · Reporting and Communication
A vulnerability management program lead needs to communicate to IT operations managers exactly which systems require patching, the assigned system owner, the priority ranking, and the target completion date for the next patch cycle. Which document BEST fits this purpose?
A remediation action plan is the operational document that assigns specific vulnerabilities to owners, sets priority, and defines target dates, making it the correct artifact for coordinating tactical patch execution with IT operations.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →