CompTIA CySA+ (CS0-004) — All Questions
← Back to practice3 questions
A SOC manager wants a metric that shows how quickly the team resolves incidents from detection to closure. Which key performance indicator best fits?
- a.CVSS base score
- b.Mean time to respond/resolve (MTTR)✓
- c.Number of open firewall ports
- d.Total lines in the SIEM ruleset
MTTR measures the average time to respond to and resolve incidents, directly reflecting response efficiency. Tracking it over time reveals whether process improvements are working and where bottlenecks remain. Pairing MTTR with mean time to detect (MTTD) gives a fuller picture of program performance for stakeholders.
When reporting a major incident to executive leadership, which communication approach is most effective?
- a.Provide raw packet captures and full log exports
- b.Use highly technical jargon to demonstrate depth
- c.Summarize business impact, risk, and recommended actions in clear language✓
- d.Withhold information until every detail is confirmed weeks later
Executives need concise, business-focused communication that explains impact, risk, and decisions required, not raw technical artifacts. Tailoring the message to the audience ensures leadership can make informed, timely decisions. Reserving deep technical detail for appendices or technical stakeholders keeps the report actionable.
A vulnerability report is being prepared for both engineers and management. What is the best practice for structuring it?
- a.Include an executive summary for leaders and detailed technical findings for remediation teams✓
- b.Send only the CVSS numbers with no context
- c.Combine everything into one dense paragraph
- d.Report findings verbally with no written record
Effective reports serve multiple audiences by pairing a concise executive summary with detailed technical findings and remediation guidance. Leaders get risk and business context, while engineers get the specifics needed to act. A clear written record also supports accountability, tracking, and compliance evidence.