โ† All CSC Flashcard Decks

Report Writing & Documentation Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Report Writing & Documentation flashcards as text
  1. What is the purpose of a 'methodology' section in a security assessment report?

    Answer: To explain the testing approach, frameworks, and tools used so findings can be reproduced and validated

    The methodology section gives transparency into how the assessment was conducted, supporting repeatability and client confidence.

  2. In the context of security reporting, what does 'dwell time' refer to?

    Answer: The length of time a threat actor remains undetected within a compromised environment

    Dwell time measures how long an attacker has persistent access before detection, a key metric in incident reports.

  3. Which of the following is the BEST practice for version control of a security report during peer review?

    Answer: Use versioned filenames (e.g., v0.1, v0.2, FINAL) and track changes using document revision history

    Versioned filenames and revision histories prevent overwriting and ensure reviewers can track what changed between drafts.

  4. A security consultant's report includes an appendix with raw tool output. What is the PRIMARY function of this appendix?

    Answer: To provide supporting technical evidence that validates findings without cluttering the main body

    Appendices house detailed evidence that substantiates findings while keeping the main report readable.

  5. When documenting a social engineering assessment in a report, what information must be handled with particular sensitivity?

    Answer: The identities of employees who failed simulated phishing tests

    Individual employee names tied to failure results can create HR and legal complications and should be anonymized or handled carefully.

  6. Which NIST publication provides guidance on security assessment documentation and reporting standards for federal systems?

    Answer: NIST SP 800-115

    NIST SP 800-115 is the Technical Guide to Information Security Testing and Assessment, covering assessment documentation.

  7. What is the BEST way to communicate urgency for a critical vulnerability discovered mid-engagement before the final report is delivered?

    Answer: Issue an out-of-band notification or interim advisory to the client immediately

    Critical findings should be communicated immediately out-of-band so the client can begin remediation without waiting for the final report.