Courseiva
Reporting and Communication →mediumMultiple Choice

CS0-003 Reporting and Communication Practice Question

An organization is preparing for an audit to demonstrate compliance with GDPR. The compliance officer needs to provide evidence of data protection controls. Which of the following would be the BEST evidence to include?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Copies of recent vulnerability scan reports and access review logs

Log exports, configuration reports, vulnerability scans, and access reviews are typical evidence for GDPR audits.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The organization's risk register

    Why it's wrong here

    The risk register is a strategic management tool used to identify, assess, and track potential threats and mitigation strategies. While it documents the decision-making process and risk acceptance, it does not provide technical, operational proof that specific security controls have been successfully deployed and are actively functioning. Auditors require empirical evidence of control execution rather than a list of planned mitigations or acknowledged risks.

  • ✓

    Copies of recent vulnerability scan reports and access review logs

    Why this is correct

    Vulnerability scan reports and access review logs serve as direct, empirical evidence of technical control implementation and operational effectiveness. These artifacts prove to auditors that vulnerability management processes are actively running and that identity and access management controls are being routinely monitored and enforced. This objective, system-generated data is crucial for validating compliance with frameworks like PCI-DSS, SOC 2, or ISO 27001.

  • ✗

    Email communications about security incidents

    Why it's wrong here

    Informal email exchanges regarding security incidents lack the structured, verifiable, and tamper-resistant qualities required for formal audit evidence. While they may document ad-hoc operational discussions, they do not constitute systematic proof of an established incident response capability or continuous control enforcement. Auditors look for formalized incident logs, ticketing system exports, and post-incident reviews rather than unstructured email threads.

  • ✗

    A summary of security policies and procedures

    Why it's wrong here

    Policies and procedures define the administrative intent and guidelines of an organization, but they only demonstrate what should be done rather than what is actually being done. A summary of these documents merely proves the existence of governance frameworks, not the operational execution of the controls. Auditors must verify that these written directives are translated into active, technical safeguards through system-generated artifacts.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.