Courseiva
mediumMultiple Choice

CS0-003 Practice Question: An analyst identifies a security policy violation…

An analyst identifies a security policy violation during a routine audit. The violation does not pose immediate risk. Which of the following is the BEST way to report this finding?

⚠ Common exam trap

CompTIA often tests the distinction between formal reporting for non-urgent findings versus immediate escalation for critical threats, trapping candidates who confuse 'no immediate risk' with 'requires urgent action' or choose informal communication methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a formal report with the finding, policy references, and recommended remediation

A formal report is the best method for documenting a security policy violation because it provides a permanent, auditable record that includes specific policy references and recommended remediation steps. This aligns with the reporting and communication domain's emphasis on structured, traceable documentation for non-urgent findings, ensuring proper tracking and accountability without causing unnecessary alarm.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a formal report with the finding, policy references, and recommended remediation

    Why this is correct

    Formalizing the security policy violation in a structured report ensures that the finding is properly documented for compliance and audit trails. Including specific policy references and actionable remediation steps provides the system owner with the necessary context to resolve the issue while establishing accountability and a clear path for follow-up verification.

  • ✗

    Mention it casually in a team meeting

    Why it's wrong here

    Raising a policy violation informally during a team meeting fails to establish a permanent, trackable record of the vulnerability. This approach lacks accountability, as there is no assigned owner or formal deadline, making it highly likely that the issue will be overlooked or forgotten during routine operations.

  • ✗

    Send an instant message to the system owner

    Why it's wrong here

    While instant messaging provides rapid communication, it does not serve as an official system of record for compliance tracking. Such messages are easily lost in daily chat history, lack the structured detail required for proper risk assessment, and fail to integrate with organizational vulnerability management workflows.

  • ✗

    Immediately report it to the Chief Information Security Officer

    Why it's wrong here

    Escalating a standard policy violation directly to the CISO bypasses the established incident response hierarchy and operational workflows. This represents an over-escalation for routine, low-risk findings, which should instead be managed through standard remediation channels before involving executive leadership.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.