SY0-701 exam dumps

SY0-701 practice question 436 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 436

Single answerRisk reporting

A security analyst has completed a quarterly risk assessment and identified a legacy public-facing application with a high likelihood of exploitation and a potentially severe business impact. The analyst must present the results to executive leadership, who are not technical and need to decide whether to fund remediation this quarter. Which of the following is the MOST effective way to report this risk?

  1. A

    Provide a report that summarizes the risk in business terms, includes likelihood and impact, identifies the affected business service, and recommends response options with residual risk

  2. B

    Provide raw vulnerability scan output with all detected CVEs so leadership can review the technical details and determine the priority

  3. C

    Provide a report focused on firewall rules, packet captures, and exploit proof-of-concept steps to demonstrate the urgency of the issue

  4. D

    Provide a short email stating the application is critical and must be fixed immediately, without including risk criteria or remediation options

Show answer and explanation

Correct answer: A

Explanation

Risk reporting should be tailored to the audience. For executive leadership, the most effective report is concise, business-focused, and decision-oriented. It should describe the risk scenario, affected asset or business service, likelihood, impact, current exposure, and recommended response options. Security+ expects candidates to distinguish between technical reporting for administrators and risk reporting for management. Best practices from NIST SP 800-30 (Guide for Conducting Risk Assessments) and NIST SP 800-39 (Managing Information Security Risk) support presenting risk in terms of organizational impact and decision support rather than raw technical data alone. Including residual risk is especially important because leaders must understand not only the current risk, but also the remaining exposure after controls are applied.

  • A. Correct.

    Correct. Effective risk reporting for executive leadership should translate technical findings into business-relevant information. A strong report should clearly describe the risk, the likelihood and impact, the business process or service affected, and practical treatment options such as remediation, mitigation, transfer, or acceptance. Including residual risk helps decision-makers understand what risk remains after a proposed control is implemented. This aligns with common risk management practices in frameworks such as NIST SP 800-30 and NIST SP 800-39, which emphasize communicating risk in a way that supports organizational decisions.

  • B. Incorrect.

    Incorrect. Raw scan output may be useful for technical teams, but it is not the most effective format for executives making funding and prioritization decisions. Listing CVEs without business context does not explain operational impact, risk severity in organizational terms, or available response options. This reflects the common misconception that more technical detail automatically improves risk communication.

  • C. Incorrect.

    Incorrect. Firewall rules, packet captures, and exploit steps may help engineers validate the issue, but they are not the best content for an executive risk report. Executives typically need concise, decision-oriented information tied to business impact, not deep technical artifacts. This option confuses technical evidence collection with risk reporting for leadership.

  • D. Incorrect.

    Incorrect. Although urgency may be appropriate, a vague statement without defined risk criteria, impact, likelihood, or treatment options does not support informed risk decisions. Leadership needs enough structured information to compare this issue against other business priorities. This option reflects the misconception that severity labels alone are sufficient for risk reporting.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam