CS0-003 Reporting and Communication Practice Question
A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access review documentation
Auditors typically require log exports, vulnerability scan reports, and access reviews to verify controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Employee training attendance records
Why it's wrong here
Employee training attendance records are a secondary artifact: they support awareness program compliance but do not directly prove the effectiveness of technical controls or the security state of the environment. For technical audits, these records are only relevant under specific frameworks (e.g., PCI DSS) and are typically requested with course content, evaluations, and policy linkage. Without that context, attendance lists alone cannot demonstrate whether access decisions, logging, or vulnerability management are functioning correctly.
- ✓
Access review documentation
Why this is correct
Access review documentation is primary audit evidence because it shows a periodic recertification of user entitlements against role definitions, least privilege, and separation of duties. It provides an auditable trail of who reviewed critical systems, what discrepancies were detected, and how they were remediated, directly satisfying access control compliance requirements. Auditors frequently cite missing or outdated access reviews as a material finding, so this documentation is a cornerstone of evidence collection.
- ✓
Log exports from critical systems
Why this is correct
Log exports from critical systems supply objective, machine-generated evidence of authentication events, configuration changes, and data access that auditors can correlate with authorization decisions and incident timelines. To be accepted, the logs must be exported with verified timestamps, secure storage, and a clear chain of custody, ensuring they have not been altered. This evidence verifies that monitoring controls are active and that anomalous activity is detectable and reviewable.
- ✓
Vulnerability scan reports
Why this is correct
Vulnerability scan reports demonstrate compliance with an organization's vulnerability management standard by showing scan coverage, detection of known CVEs, and the lifecycle of remediation exceptions and closures. Auditors evaluate these reports to confirm that scanning is scheduled, credentialed where appropriate, and that findings are prioritized based on risk and threat intelligence. They are distinct from access or log evidence because they focus on the effectiveness of the patch and configuration management process rather than user activity.
- ✗
Marketing brochures
Why it's wrong here
Marketing brochures have no probative value in a technical audit because they are promotional materials created for external customers, not records of security operations, control implementation, or risk decisions. They cannot substantiate claims about system configurations, access rights, or vulnerability status, and may even contain aspirational statements that contradict actual audit evidence. Including them in an evidence packet would undermine the chain of custody and dilute the credibility of the submission.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.