Courseiva

CS0-003 Reporting and Communication Practice Question

An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?

⚠ Common exam trap

CS0-004 often tests the difference between design evidence (policies, screenshots) and operating effectiveness evidence (test results, metrics), tempting candidates to pick a configuration screenshot because it 'shows' the control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A control effectiveness report with test results and metrics

A control effectiveness report with test results and metrics provides objective, measurable evidence that the control actually works as intended, which is what auditors require. Configuration screenshots and policy documents only show intent or design, not operational effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A screenshot of the control configuration

    Why it's wrong here

    A screenshot captures the control's configuration at a single point in time, proving the setting was applied, but it says nothing about whether the control has actually functioned correctly or detected anything over an operating period.

  • ✗

    A policy document describing the control

    Why it's wrong here

    A policy document states intended requirements, not whether the control actually operates, so it cannot evidence effectiveness. It is tempting because policies are easy to produce and auditors request them, but that fits demonstrating design or intent, whereas effectiveness requires operational records such as logs or test results.

  • ✓

    A control effectiveness report with test results and metrics

    Why this is correct

    A control effectiveness report supplies measured test results and metrics, giving auditors objective proof that the control operates as intended rather than merely existing. This directly satisfies the stem's requirement to demonstrate effectiveness, since design documentation or policy statements alone cannot evidence actual performance.

  • ✗

    An email from the system owner stating the control is working

    Why it's wrong here

    An email asserting the control works is unverified assertion, not objective evidence of operation. It is tempting because it is quick to obtain from a responsible owner, but that suits confirming ownership or attestation, whereas effectiveness demands independently verifiable artefacts such as configuration exports or audit logs.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.