SY0-701 Question 486
Single answerReporting and monitoring: Initial , RecurringA security analyst has completed the first round of vulnerability scans after a new reporting and monitoring program was deployed. Management wants to know whether the organization is improving over time, not just what was found this week. The analyst needs to create reports that support both executive review and ongoing operational follow-up. Which action BEST addresses the need for both initial and recurring reporting?
- A
Create a baseline report from the initial scan results and then issue recurring trend reports that compare new findings against that baseline
- B
Send the raw scan output from each assessment to executives so they can compare technical details between scans
- C
Wait until several scan cycles are complete before producing any report, so the first report includes long-term trends
- D
Replace scheduled reporting with ad hoc alerts only, because recurring reports duplicate what the monitoring tools already show
Show answer and explanation
Correct answer: A
Explanation
The best answer is to create an initial baseline report and then produce recurring reports that measure change against that baseline. In security operations, initial reporting establishes the starting point for risk, control effectiveness, and remediation priorities. Recurring reporting then provides ongoing monitoring through trend analysis, status updates, and metric comparison. This aligns with common security best practices in vulnerability management and security governance, where organizations track findings over time rather than treating each scan as an isolated event. Frameworks and guidance such as NIST vulnerability management practices and general security program reporting principles emphasize establishing baselines, monitoring metrics regularly, and tailoring reports to the audience. Executives typically need summarized dashboards and trends, while technical teams need detailed remediation data. Effective reporting therefore includes both an initial snapshot and recurring measurement of progress.
- A. Correct.
Correct. An initial baseline report establishes the organization's starting security posture, which is essential for measuring change. Recurring reports can then track metrics such as open vulnerabilities, remediation timelines, repeated findings, and risk trends over time. This approach supports both operational teams, who need actionable follow-up, and executives, who need progress summaries and trend visibility.
- B. Incorrect.
Incorrect. Raw scan output is usually too detailed and technical for executive reporting. While technical teams may need the full results, leadership generally needs summarized risk information, trends, and business impact. Sending raw output does not effectively support recurring reporting or demonstrate improvement over time.
- C. Incorrect.
Incorrect. Delaying the first report removes the value of initial reporting. Organizations need an initial report to establish a baseline, identify immediate issues, and prioritize remediation. Trend reporting is useful later, but it depends on having that initial reference point.
- D. Incorrect.
Incorrect. Ad hoc alerts are useful for immediate notification of important events, but they do not replace recurring reports. Scheduled recurring reporting is necessary to demonstrate compliance, track remediation progress, measure key performance indicators, and communicate status consistently to stakeholders.