CS0-003 Reporting and Communication Practice Question
A security analyst is collecting evidence for an upcoming compliance audit. Which three types of evidence are typically required? (Select THREE.)
⚠ Common exam trap
CS0-004 often tests the distinction between governance/awareness artifacts (training records) and technical/operational evidence (access reviews, logs, scan reports) — candidates over-select training records because they sound compliance-related but are not among the three required technical evidence types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access review documentation
Access review documentation (B) is required because compliance frameworks such as SOX, HIPAA, PCI DSS, and ISO 27001 mandate periodic attestation that user access rights are appropriate and least-privilege, providing auditable proof of authorization control. Log exports from critical systems (C) are essential evidence because they demonstrate continuous monitoring, traceability of user and system activity, and support incident investigation and retention requirements under regulations like PCI DSS Req. 10 and HIPAA §164.312(b). Vulnerability scan reports (D) are required to prove that the organization identifies, tracks, and remediates technical weaknesses on a recurring basis, satisfying requirements such as PCI DSS Req. 11.2 and NIST SP 800-53 RA-5. Employee training attendance records (A) are useful for awareness programs but are not one of the three evidence types typically demanded in this audit context, and marketing brochures (E) are promotional materials with no evidentiary value for compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Employee training attendance records
Why it's wrong here
Employee training attendance records are a secondary artifact: they support awareness program compliance but do not directly prove the effectiveness of technical controls or the security state of the environment. For technical audits, these records are only relevant under specific frameworks (e.g., PCI DSS) and are typically requested with course content, evaluations, and policy linkage. Without that context, attendance lists alone cannot demonstrate whether access decisions, logging, or vulnerability management are functioning correctly.
- ✓
Access review documentation
Why this is correct
Access review documentation is primary audit evidence because it shows a periodic recertification of user entitlements against role definitions, least privilege, and separation of duties. It provides an auditable trail of who reviewed critical systems, what discrepancies were detected, and how they were remediated, directly satisfying access control compliance requirements. Auditors frequently cite missing or outdated access reviews as a material finding, so this documentation is a cornerstone of evidence collection.
- ✓
Log exports from critical systems
Why this is correct
Log exports from critical systems supply objective, machine-generated evidence of authentication events, configuration changes, and data access that auditors can correlate with authorization decisions and incident timelines. To be accepted, the logs must be exported with verified timestamps, secure storage, and a clear chain of custody, ensuring they have not been altered. This evidence verifies that monitoring controls are active and that anomalous activity is detectable and reviewable.
- ✓
Vulnerability scan reports
Why this is correct
Vulnerability scan reports demonstrate compliance with an organization's vulnerability management standard by showing scan coverage, detection of known CVEs, and the lifecycle of remediation exceptions and closures. Auditors evaluate these reports to confirm that scanning is scheduled, credentialed where appropriate, and that findings are prioritized based on risk and threat intelligence. They are distinct from access or log evidence because they focus on the effectiveness of the patch and configuration management process rather than user activity.
- ✗
Marketing brochures
Why it's wrong here
Marketing brochures have no probative value in a technical audit because they are promotional materials created for external customers, not records of security operations, control implementation, or risk decisions. They cannot substantiate claims about system configurations, access rights, or vulnerability status, and may even contain aspirational statements that contradict actual audit evidence. Including them in an evidence packet would undermine the chain of custody and dilute the credibility of the submission.
Go deeper
Related to this question
Learn chapter
Risk Register and Vulnerability Register
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.