SY0-701 Question 305
Single answerReportingA security analyst is preparing a monthly report for executive leadership after several phishing attempts and one confirmed malware infection were handled during the reporting period. The executives want a concise report that helps them decide whether additional funding is needed for email security improvements. Which of the following reporting approaches would BEST meet this need?
- A
Provide a high-level summary showing phishing volume, the number of users affected, business impact, response outcomes, and trends compared with prior months
- B
Include raw SIEM logs, full packet captures, and endpoint forensic artifacts so leadership can independently validate the incident details
- C
Focus the report on every indicator of compromise, hash value, and registry change observed during the malware investigation
- D
Limit the report to a statement that the incidents were resolved successfully and no further action is required
Show answer and explanation
Correct answer: A
Explanation
The best answer is the high-level summary tailored to executive leadership. In Security+ reporting scenarios, an important principle is audience-specific communication: executives need strategic, business-relevant information rather than deep technical artifacts. Effective executive reports typically include incident counts, trends over time, business impact, remediation status, residual risk, and recommendations. This aligns with common incident response and reporting best practices described by NIST, including guidance in NIST SP 800-61 on tailoring communications and reports to stakeholders. Technical details such as IOCs, packet captures, and host-level artifacts are more appropriate for SOC analysts, incident responders, or forensic teams, while executives need concise reporting that supports governance, risk, and funding decisions.
- A. Correct.
Correct. Executive reporting should be concise, business-focused, and decision-oriented. For leadership, the most useful report emphasizes metrics and trends such as incident volume, affected users or systems, operational or financial impact, response effectiveness, and whether current controls appear sufficient. This allows executives to assess risk posture and make funding or policy decisions without being overloaded by highly technical evidence.
- B. Incorrect.
Incorrect. Raw SIEM logs, packet captures, and forensic artifacts are appropriate for analysts, investigators, or auditors who need technical validation, but they are not appropriate as the primary format for executive reporting. This option reflects the common mistake of sending the same technical report to all audiences instead of tailoring reporting to stakeholder needs.
- C. Incorrect.
Incorrect. Indicators of compromise, hashes, and registry changes are valuable for technical incident reports, threat hunting, and detection tuning. However, they do not directly help executives evaluate business impact or justify budget decisions. This option confuses operational reporting for security teams with management reporting for leadership.
- D. Incorrect.
Incorrect. A report that only states the incidents were resolved lacks the context needed for informed decision-making. Executives need enough detail to understand frequency, impact, trends, control gaps, and recommendations. Omitting these elements can hide risk and prevent appropriate resource allocation.