CompTIA CySA+ (CS0-003)Reporting and CommunicationEasy
A security analyst is reviewing a vulnerability report for a public-facing web application. The report identifies a Cross-Site Scripting (XSS) vulnerability with a CVSS score of 7.5 (High). The analyst needs to communicate this finding to the development team for remediation. Which of the following would be the MOST effective way to communicate the technical details and remediation steps?
- ASchedule a meeting with the development team to verbally explain the vulnerability.
- BCreate a Jira ticket with a clear description, proof-of-concept, affected code, and recommended fix.
- CSend an email with a link to the full vulnerability scan report.
- DPost an alert in the company-wide instant messaging channel about the critical vulnerability.
Show answer & explanationAnswer & explanation
Correct answer: B. Create a Jira ticket with a clear description, proof-of-concept, affected code, and recommended fix.
For technical communication with a development team, a structured ticketing system like Jira is highly effective. It allows for detailed descriptions, attachment of proof-of-concept, direct linkage to affected code, and clear, actionable remediation steps, ensuring proper tracking and accountability.
Why the other options are wrong
- A. Verbal explanations can lead to misinterpretations and lack a formal record for tracking and accountability.
- C. A link to a full report might lack specific actionable details and can be overwhelming for developers who need targeted information.
- D. An instant message alert is too informal and lacks the necessary detail, context, and tracking capabilities for a technical vulnerability remediation task.
Technical Vulnerability Communication
The process of effectively conveying detailed information about security vulnerabilities, including their nature, impact, and specific remediation steps, to technical audiences like development teams.
- Requires precision and clarity.
- Should include proof-of-concept and affected code where possible.
- Best delivered through structured, trackable systems (e.g., ticketing).
Memory trick: Developers need 'Code, Proof, Fix' in a 'Ticket', not just 'Talk'.