CSC Report Writing & Documentation 2 — Questions and Answers
Question 1: When documenting a chain of custody for digital evidence in a security incident report, what information is MOST critical to record at each transfer?
- The names of all project stakeholders
- The identity of each person who handled the evidence and the date/time of transfer (Correct answer)
- The total cost of the investigation
- The software versions used during analysis
Correct answer: The identity of each person who handled the evidence and the date/time of transfer
Chain of custody documentation must record who handled the evidence and when, ensuring its legal admissibility and integrity.
Question 2: A security consultant is writing an executive summary of a penetration test. Which of the following should be EXCLUDED from this section?
- Overall risk posture of the organization
- Detailed packet captures and hex dumps of exploits (Correct answer)
- High-level findings and business impact
- Summary of recommendations
Correct answer: Detailed packet captures and hex dumps of exploits
Executive summaries target non-technical leadership and should omit granular technical artifacts like packet captures.
Question 3: Which report structure is MOST appropriate when a consultant must deliver findings incrementally throughout a long-term engagement?
- A single comprehensive final report delivered at project close
- Periodic interim reports supplemented by a final summary report (Correct answer)
- Verbal briefings only, with no written documentation
- A single slide deck presented to executives
Correct answer: Periodic interim reports supplemented by a final summary report
Interim reports allow clients to act on findings in real time, reducing risk before the engagement concludes.
Question 4: What is the PRIMARY purpose of including a 'scope' section in a security assessment report?
- To list the consultant's qualifications and certifications
- To define the boundaries of the assessment so findings can be properly contextualized (Correct answer)
- To describe the client's revenue and business model
- To outline the payment schedule for consulting services
Correct answer: To define the boundaries of the assessment so findings can be properly contextualized
The scope section establishes what was and was not tested, preventing misinterpretation of findings.
Question 5: When assigning a CVSS score in a vulnerability report, which metric group assesses the exploitability of the vulnerability independently of any specific environment?
- Environmental metrics
- Temporal metrics
- Base metrics (Correct answer)
- Supplemental metrics
Correct answer: Base metrics
CVSS base metrics measure the intrinsic characteristics of a vulnerability that are constant regardless of environment or time.
Question 6: A consultant discovers that a client's report template uses 'TBD' placeholders in the risk rating fields. What is the BEST course of action?
- Submit the report with placeholders to meet the deadline
- Complete all risk ratings using the agreed-upon methodology before delivery (Correct answer)
- Ask the client to fill in the ratings themselves
- Remove the risk rating section entirely
Correct answer: Complete all risk ratings using the agreed-upon methodology before delivery
Delivering incomplete risk ratings undermines the report's value and may expose the consultant to professional liability.
Question 7: In security report writing, what does the term 'finding' typically refer to?
- A description of the client's business objectives
- A documented observation of a security weakness or policy violation discovered during the assessment (Correct answer)
- The consultant's billing summary
- A list of recommended security tools to purchase
Correct answer: A documented observation of a security weakness or policy violation discovered during the assessment
A finding is a documented security issue identified during the assessment, supported by evidence.
When documenting a chain of custody for digital evidence in a security incident report, what information is MOST critical to record at each transfer?