Report Writing & Documentation Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Report Writing & Documentation flashcards as text
A security consultant must write a report that will be used as evidence in litigation. Which characteristic is MOST important for this document?
Answer: Objectivity, factual accuracy, and a clear chain of custody for all supporting evidence
Litigation-bound reports must be factually precise, objective, and supported by auditable evidence to withstand legal scrutiny.
When writing a security policy document, which component describes the consequences for non-compliance?
Answer: Enforcement clause
The enforcement clause specifies disciplinary or legal consequences for individuals who violate the policy.
Which of the following is an example of an 'observation' as opposed to a 'finding' in a security report?
Answer: Administrators frequently sharing credentials, noted as a process risk but not tested technically
An observation is a noted concern that was not directly tested or confirmed through technical exploitation, unlike a validated finding.
A report's 'attack narrative' section is MOST useful for:
Answer: Walking the client through the attacker's perspective to illustrate how multiple low-severity issues combine into a critical attack path
An attack narrative contextualizes findings by showing how an adversary would chain vulnerabilities to achieve a goal.
What is the significance of including a 'limitations' section in a security assessment report?
Answer: It transparently discloses constraints (time, access, scope restrictions) that may have affected the completeness of the assessment
Disclosing limitations helps clients understand gaps in coverage and make informed decisions about residual risk.
When a security report recommends 'defense-in-depth' as a remediation strategy, what concept is being advocated?
Answer: Implementing multiple overlapping layers of security controls so that failure of one does not lead to complete compromise
Defense-in-depth advocates layered controls so no single point of failure can be catastrophically exploited.
A consultant delivers a security report containing a finding that was later determined to be a false positive. What is the CORRECT follow-up action?
Answer: Issue a formal report addendum or updated report version correcting the false positive and notifying the client
Professional integrity requires issuing a correction to prevent the client from remediating a non-existent issue or misallocating resources.