SY0-701 Question 485
Single answerReporting and monitoring: Initial , RecurringA security manager is formalizing reporting for a newly deployed SIEM. Executives want an initial report that quickly communicates the organization's current security posture, while operations staff need recurring reports that help them track trends and measure whether controls are improving over time. Which reporting approach BEST meets these requirements?
- A
Create an initial baseline report summarizing current findings, asset coverage, and open risks, then schedule recurring reports with consistent metrics such as incident volume, mean time to respond, and unresolved high-risk alerts
- B
Send the same detailed raw event log export to both executives and operations staff each week so everyone receives identical data for consistency
- C
Provide only a one-time initial report because recurring reports can be misleading as the environment changes after deployment
- D
Use recurring reports only for compliance exceptions and avoid including metrics, since metrics can create unnecessary pressure on analysts
Show answer and explanation
Correct answer: A
Explanation
The best answer is to produce an initial baseline report followed by recurring reports that track consistent security metrics. In practice, initial reporting establishes the starting point: current risks, monitoring coverage, notable findings, and gaps. Recurring reporting then supports continuous monitoring by showing trends, operational effectiveness, and whether remediation efforts are working. This approach is consistent with widely accepted security operations and risk management practices, including continuous monitoring concepts described by NIST guidance such as NIST SP 800-137 (Information Security Continuous Monitoring) and the general emphasis on metrics and ongoing assessment found in NIST cybersecurity documentation. Reports should also be tailored to the audience: executives need summarized posture and business risk, while operations teams need actionable metrics and trends.
- A. Correct.
Correct. An initial report should establish a baseline of the organization's current security posture, including what is being monitored, major findings, asset or log-source coverage, and outstanding risks. Recurring reports should then use consistent, meaningful metrics to support trend analysis and operational improvement over time. This aligns with common security monitoring practices: establish a baseline first, then measure changes against it through regular reporting.
- B. Incorrect.
Incorrect. Raw event logs are not appropriate for executive reporting because they lack summarization, business context, and prioritization. While operations staff may need detailed data for investigation, recurring reporting should be tailored to the audience. A common misconception is that identical reporting improves consistency; in practice, effective reporting is role-based and decision-focused.
- C. Incorrect.
Incorrect. Recurring reports are essential for monitoring trends, validating control effectiveness, and identifying deterioration or improvement over time. It is true that environments change, but that is exactly why recurring reporting is needed. The misconception here is treating the initial report as sufficient, when it is only the starting point for ongoing monitoring.
- D. Incorrect.
Incorrect. Recurring reports should include metrics because measurable indicators help security teams track performance and risk over time. Limiting reports only to compliance exceptions ignores broader operational security needs such as incident trends, alert backlog, and response efficiency. The misconception is that metrics are optional or counterproductive; in reality, they are central to continuous monitoring.