SY0-701 exam dumps

SY0-701 practice question 304 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 304

Single answerReporting

A security analyst has completed the initial investigation of a ransomware incident affecting several file servers. Executive leadership wants a report within the hour that explains business impact, current containment status, and the immediate actions required from nontechnical stakeholders. At the same time, the incident response team needs a separate document with indicators of compromise, affected hosts, timeline details, and evidence references for continued investigation. Which reporting approach is the MOST appropriate?

  1. A

    Create a single detailed technical report and send it to both executives and the incident response team to ensure everyone has the same information

  2. B

    Prepare an executive summary for leadership and a separate technical incident report for the response team, tailoring the level of detail to each audience

  3. C

    Delay reporting until forensic imaging is complete so the organization does not distribute incomplete or potentially inaccurate information

  4. D

    Provide only a verbal briefing to leadership first and avoid written documentation until the legal department approves every incident detail

Show answer and explanation

Correct answer: B

Explanation

The best answer is to produce separate reports tailored to the intended audience. In Security+ reporting scenarios, a key principle is that reports should be accurate, timely, and relevant to stakeholder needs. Executives usually need a high-level summary covering business impact, operational disruption, financial or reputational considerations, current response status, and decisions or approvals required. Technical teams need deeper detail such as affected assets, attack timeline, observables, evidence locations, and response actions. This aligns with common incident response guidance from NIST, including NIST SP 800-61, which emphasizes coordinated incident handling and communication with different stakeholders throughout the incident lifecycle. Good reporting also supports chain of custody, lessons learned, regulatory response, and management decision-making without overloading nontechnical readers with unnecessary forensic detail.

  • A. Incorrect.

    This is incorrect because using one highly technical report for all audiences is not effective reporting practice. Executives typically need concise, business-focused information such as operational impact, risk, decisions needed, and status, while responders need detailed technical data to continue containment, eradication, and recovery. A single report often overwhelms leadership and still may not provide the structured technical depth responders require.

  • B. Correct.

    This is correct because effective security reporting is audience-specific. Leadership should receive an executive summary focused on business impact, scope, current status, and required decisions, while the incident response team should receive a technical report containing indicators of compromise, systems affected, evidence references, and investigative findings. This approach supports informed decision-making and operational response at the same time.

  • C. Incorrect.

    This is incorrect because incident reporting should be timely, even when all facts are not yet finalized. Waiting for full forensic completion can delay critical business decisions and stakeholder coordination. A preliminary report can clearly state that findings are initial and subject to change. Security best practices emphasize prompt, accurate, and appropriately scoped communication during active incidents.

  • D. Incorrect.

    This is incorrect because verbal briefings may be useful, but relying only on verbal communication creates gaps in documentation, accountability, and continuity. Written reporting is important for tracking actions, preserving timelines, supporting post-incident review, and meeting organizational or regulatory requirements. Legal review may be needed for some external communications, but that does not eliminate the need for prompt internal written reporting.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam