Report Writing & Documentation Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Report Writing & Documentation flashcards as text
When documenting a chain of custody for digital evidence in a security incident report, what information is MOST critical to record at each transfer?
Answer: The identity of each person who handled the evidence and the date/time of transfer
Chain of custody documentation must record who handled the evidence and when, ensuring its legal admissibility and integrity.
A security consultant is writing an executive summary of a penetration test. Which of the following should be EXCLUDED from this section?
Answer: Detailed packet captures and hex dumps of exploits
Executive summaries target non-technical leadership and should omit granular technical artifacts like packet captures.
Which report structure is MOST appropriate when a consultant must deliver findings incrementally throughout a long-term engagement?
Answer: Periodic interim reports supplemented by a final summary report
Interim reports allow clients to act on findings in real time, reducing risk before the engagement concludes.
What is the PRIMARY purpose of including a 'scope' section in a security assessment report?
Answer: To define the boundaries of the assessment so findings can be properly contextualized
The scope section establishes what was and was not tested, preventing misinterpretation of findings.
When assigning a CVSS score in a vulnerability report, which metric group assesses the exploitability of the vulnerability independently of any specific environment?
Answer: Base metrics
CVSS base metrics measure the intrinsic characteristics of a vulnerability that are constant regardless of environment or time.
A consultant discovers that a client's report template uses 'TBD' placeholders in the risk rating fields. What is the BEST course of action?
Answer: Complete all risk ratings using the agreed-upon methodology before delivery
Delivering incomplete risk ratings undermines the report's value and may expose the consultant to professional liability.
In security report writing, what does the term 'finding' typically refer to?
Answer: A documented observation of a security weakness or policy violation discovered during the assessment
A finding is a documented security issue identified during the assessment, supported by evidence.