CS0-003 Reporting and Communication Practice Question
An organization is preparing evidence for an audit of access controls. Which THREE types of evidence should be collected? (Select THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access review documentation
Audit evidence for access controls includes log exports (showing access events), access reviews (certifying user permissions), and vulnerability scan reports (identifying misconfigurations). Incident reports are not directly relevant.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network flow data
Why it's wrong here
This data captures metadata about network communications, such as source/destination IPs, ports, protocols, and traffic volumes, but it does not directly show user identity, permissions, or whether access controls were properly enforced. It can indirectly suggest anomalous access patterns (e.g., unusual data exfiltration) but lacks the granularity of user-level access logs or authorization decisions. Therefore, it is not considered primary evidence for an access control audit.
- ✓
Access review documentation
Why this is correct
This is the strongest evidence because it demonstrates a formal, recurring process where managers or data owners explicitly certify which users have access to which systems and data, and whether that access remains appropriate. It shows that the organization systematically validates least privilege, detects orphaned accounts, and documents corrective actions after each review cycle. Auditors expect to see these review records to prove that access rights are not just assigned but continuously governed.
- ✓
Vulnerability scan reports
Why this is correct
These reports can highlight technical weaknesses in access controls, such as misconfigured permissions, default credentials, or missing patches on systems that enforce authentication/authorization. However, they are point-in-time technical assessments and do not by themselves prove that access policies were followed or that user access was reviewed by the business. They serve as supporting evidence, helping to show that the organization actively looks for and remediates access control gaps, but they do not replace user certification evidence.
- ✓
Log exports of user access events
Why this is correct
These logs provide a historical record of actual access attempts, including successful and failed authentications, source IPs, and resource accesses, which can be correlated with access decisions. They are critical for verifying that permissions were used in practice and for detecting unauthorized activity, but they are raw data and require analysis and context to be meaningful. Auditors value them as proof of monitoring and detective controls, but they do not inherently demonstrate that the access rights themselves were properly reviewed and justified.
- ✗
Incident response reports
Why it's wrong here
These documents describe how security incidents were detected, contained, and remediated, and they may reference access control failures, but they are event-driven and only cover specific anomalies. They do not provide a systematic view of user access permissions or evidence of regular access reviews. Therefore, they are not suitable as primary evidence for an access control audit, though they might supplement a narrative about improvements made after an incident.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.