CS0-003 Reporting and Communication Practice Question
An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?
⚠ Common exam trap
CS0-004 often tests the difference between design evidence (policies, screenshots) and operating effectiveness evidence (test results, metrics), tempting candidates to pick a configuration screenshot because it 'shows' the control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A control effectiveness report with test results and metrics
A control effectiveness report with test results and metrics provides objective, measurable evidence that the control actually works as intended, which is what auditors require. Configuration screenshots and policy documents only show intent or design, not operational effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A screenshot of the control configuration
Why it's wrong here
A screenshot captures the control's configuration at a single point in time, proving the setting was applied, but it says nothing about whether the control has actually functioned correctly or detected anything over an operating period.
- ✗
A policy document describing the control
Why it's wrong here
A policy document states intended requirements, not whether the control actually operates, so it cannot evidence effectiveness. It is tempting because policies are easy to produce and auditors request them, but that fits demonstrating design or intent, whereas effectiveness requires operational records such as logs or test results.
- ✓
A control effectiveness report with test results and metrics
Why this is correct
A control effectiveness report supplies measured test results and metrics, giving auditors objective proof that the control operates as intended rather than merely existing. This directly satisfies the stem's requirement to demonstrate effectiveness, since design documentation or policy statements alone cannot evidence actual performance.
- ✗
An email from the system owner stating the control is working
Why it's wrong here
An email asserting the control works is unverified assertion, not objective evidence of operation. It is tempting because it is quick to obtain from a responsible owner, but that suits confirming ownership or attestation, whereas effectiveness demands independently verifiable artefacts such as configuration exports or audit logs.
Go deeper
Related to this question
Learn chapter
Compliance Reporting
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.