SY0-701 exam dumps

SY0-701 practice question 435 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 435

Single answerRisk reporting

A security analyst has completed a quarterly risk assessment and must present the results to executive leadership. The assessment identified several high-likelihood vulnerabilities, but only two of them affect systems that support a revenue-generating customer portal. The executives have limited technical knowledge and want to know which issues require immediate funding. Which of the following is the BEST way to report the findings?

  1. A

    Provide a detailed vulnerability scan export with CVSS scores and full technical output so leadership can review all findings directly

  2. B

    Present a risk register summary that ranks issues by likelihood, business impact, affected assets, and recommended treatment actions

  3. C

    Focus only on the number of vulnerabilities discovered this quarter so leadership can compare it to prior reporting periods

  4. D

    Submit a list of systems with missing patches and leave prioritization to the infrastructure team

Show answer and explanation

Correct answer: B

Explanation

Effective risk reporting should be tailored to the audience and support decision-making. For executive leadership, the best practice is to summarize risk in business terms rather than present raw technical data. A risk register or equivalent summary commonly includes the asset or process at risk, threat/vulnerability, likelihood, impact, current controls, residual risk, owner, and recommended response. This aligns with widely accepted practices in risk management frameworks such as NIST guidance on risk assessment and risk response, which emphasize communicating risk in a form that supports organizational priorities. In this scenario, the most important reporting elements are the relationship to the revenue-generating customer portal, the likelihood and impact of exploitation, and the recommended treatment actions requiring funding. Metrics like vulnerability counts or raw scanner exports may support technical remediation, but they are less effective for executive-level risk reporting.

  • A. Incorrect.

    This is not the best choice for executive risk reporting. Raw scanner output and CVSS details may be useful for technical teams, but executives typically need a business-focused summary that translates technical issues into organizational risk, operational impact, and funding priorities. A common misconception is that more technical detail improves reporting quality for every audience; in practice, reporting should be tailored to the audience.

  • B. Correct.

    This is correct. A risk register summary is an appropriate reporting method because it communicates risk in terms leadership can act on: likelihood, impact, affected business assets, and recommended treatment such as mitigation, transfer, acceptance, or avoidance. This helps executives prioritize funding and remediation based on business risk rather than raw technical severity alone.

  • C. Incorrect.

    This is incorrect because reporting only the number of vulnerabilities emphasizes a metric without sufficient context. A higher or lower count does not necessarily reflect greater organizational risk. Executives need information about which findings matter most to critical services, especially those tied to revenue or mission-essential operations. This option reflects the misconception that volume-based metrics are enough for decision-making.

  • D. Incorrect.

    This is not the best answer because it provides an incomplete operational view rather than a formal risk report. Missing patches may be part of the problem, but leadership needs prioritized risk information tied to business impact and treatment recommendations. Leaving prioritization entirely to the infrastructure team does not meet the executive need for risk-based funding decisions.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam