mediumMultiple Choice
CS0-003 Practice Question: An analyst identifies a security policy violation…
An analyst identifies a security policy violation during a routine audit. The violation does not pose immediate risk. Which of the following is the BEST way to report this finding?
⚠ Common exam trap
CompTIA often tests the distinction between formal reporting for non-urgent findings versus immediate escalation for critical threats, trapping candidates who confuse 'no immediate risk' with 'requires urgent action' or choose informal communication methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a formal report with the finding, policy references, and recommended remediation
A formal report is the best method for documenting a security policy violation because it provides a permanent, auditable record that includes specific policy references and recommended remediation steps. This aligns with the reporting and communication domain's emphasis on structured, traceable documentation for non-urgent findings, ensuring proper tracking and accountability without causing unnecessary alarm.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a formal report with the finding, policy references, and recommended remediation
Why this is correct
Formalizing the security policy violation in a structured report ensures that the finding is properly documented for compliance and audit trails. Including specific policy references and actionable remediation steps provides the system owner with the necessary context to resolve the issue while establishing accountability and a clear path for follow-up verification.
- ✗
Mention it casually in a team meeting
Why it's wrong here
Raising a policy violation informally during a team meeting fails to establish a permanent, trackable record of the vulnerability. This approach lacks accountability, as there is no assigned owner or formal deadline, making it highly likely that the issue will be overlooked or forgotten during routine operations.
- ✗
Send an instant message to the system owner
Why it's wrong here
While instant messaging provides rapid communication, it does not serve as an official system of record for compliance tracking. Such messages are easily lost in daily chat history, lack the structured detail required for proper risk assessment, and fail to integrate with organizational vulnerability management workflows.
- ✗
Immediately report it to the Chief Information Security Officer
Why it's wrong here
Escalating a standard policy violation directly to the CISO bypasses the established incident response hierarchy and operational workflows. This represents an over-escalation for routine, low-risk findings, which should instead be managed through standard remediation channels before involving executive leadership.
Go deeper
Related to this question
Learn chapter
AWS CloudTrail and Azure Audit Log Analysis
Key term
Remediation
Remediation is the process of fixing or eliminating vulnerabilities, misconfigurations, or security weaknesses in an IT environment.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.