Courseiva
Reporting and CommunicationhardMultiple SelectObjective-mapped

CS0-003 Reporting and Communication Practice Question

A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Access review documentation

Auditors typically require log exports, vulnerability scan reports, and access reviews to verify controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Employee training attendance records

    Why it's wrong here

    Employee training attendance records are a secondary artifact: they support awareness program compliance but do not directly prove the effectiveness of technical controls or the security state of the environment. For technical audits, these records are only relevant under specific frameworks (e.g., PCI DSS) and are typically requested with course content, evaluations, and policy linkage. Without that context, attendance lists alone cannot demonstrate whether access decisions, logging, or vulnerability management are functioning correctly.

  • Access review documentation

    Why this is correct

    Access review documentation is primary audit evidence because it shows a periodic recertification of user entitlements against role definitions, least privilege, and separation of duties. It provides an auditable trail of who reviewed critical systems, what discrepancies were detected, and how they were remediated, directly satisfying access control compliance requirements. Auditors frequently cite missing or outdated access reviews as a material finding, so this documentation is a cornerstone of evidence collection.

  • Log exports from critical systems

    Why this is correct

    Log exports from critical systems supply objective, machine-generated evidence of authentication events, configuration changes, and data access that auditors can correlate with authorization decisions and incident timelines. To be accepted, the logs must be exported with verified timestamps, secure storage, and a clear chain of custody, ensuring they have not been altered. This evidence verifies that monitoring controls are active and that anomalous activity is detectable and reviewable.

  • Vulnerability scan reports

    Why this is correct

    Vulnerability scan reports demonstrate compliance with an organization's vulnerability management standard by showing scan coverage, detection of known CVEs, and the lifecycle of remediation exceptions and closures. Auditors evaluate these reports to confirm that scanning is scheduled, credentialed where appropriate, and that findings are prioritized based on risk and threat intelligence. They are distinct from access or log evidence because they focus on the effectiveness of the patch and configuration management process rather than user activity.

  • Marketing brochures

    Why it's wrong here

    Marketing brochures have no probative value in a technical audit because they are promotional materials created for external customers, not records of security operations, control implementation, or risk decisions. They cannot substantiate claims about system configurations, access rights, or vulnerability status, and may even contain aspirational statements that contradict actual audit evidence. Including them in an evidence packet would undermine the chain of custody and dilute the credibility of the submission.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.