CompTIA CySA+ (CS0-004) — All Questions
3 questions
A SOC manager wants a metric that shows how quickly the team resolves incidents from detection to closure. Which key performance indicator best fits?
- a.Number of open firewall ports
- b.Mean time to respond/resolve (MTTR)✓
- c.CVSS base score
- d.Total lines in the SIEM ruleset
MTTR measures the average time to respond to and resolve incidents, directly reflecting response efficiency. Tracking it over time reveals whether process improvements are working and where bottlenecks remain. Pairing MTTR with mean time to detect (MTTD) gives a fuller picture of program performance for stakeholders.
When reporting a major incident to executive leadership, which communication approach is most effective?
- a.Withhold information until every detail is confirmed weeks later
- b.Summarize business impact, risk, and recommended actions in clear language✓
- c.Provide raw packet captures and full log exports
- d.Use highly technical jargon to demonstrate depth
Executives need concise, business-focused communication that explains impact, risk, and decisions required, not raw technical artifacts. Tailoring the message to the audience ensures leadership can make informed, timely decisions. Reserving deep technical detail for appendices or technical stakeholders keeps the report actionable.
A vulnerability report is being prepared for both engineers and management. What is the best practice for structuring it?
- a.Combine everything into one dense paragraph
- b.Send only the CVSS numbers with no context
- c.Include an executive summary for leaders and detailed technical findings for remediation teams✓
- d.Report findings verbally with no written record
Effective reports serve multiple audiences by pairing a concise executive summary with detailed technical findings and remediation guidance. Leaders get risk and business context, while engineers get the specifics needed to act. A clear written record also supports accountability, tracking, and compliance evidence.