CS0-003 Reporting and Communication Practice Question
An organization is preparing for an audit to demonstrate compliance with GDPR. The compliance officer needs to provide evidence of data protection controls. Which of the following would be the BEST evidence to include?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Copies of recent vulnerability scan reports and access review logs
Log exports, configuration reports, vulnerability scans, and access reviews are typical evidence for GDPR audits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The organization's risk register
Why it's wrong here
The risk register is a strategic management tool used to identify, assess, and track potential threats and mitigation strategies. While it documents the decision-making process and risk acceptance, it does not provide technical, operational proof that specific security controls have been successfully deployed and are actively functioning. Auditors require empirical evidence of control execution rather than a list of planned mitigations or acknowledged risks.
- ✓
Copies of recent vulnerability scan reports and access review logs
Why this is correct
Vulnerability scan reports and access review logs serve as direct, empirical evidence of technical control implementation and operational effectiveness. These artifacts prove to auditors that vulnerability management processes are actively running and that identity and access management controls are being routinely monitored and enforced. This objective, system-generated data is crucial for validating compliance with frameworks like PCI-DSS, SOC 2, or ISO 27001.
- ✗
Email communications about security incidents
Why it's wrong here
Informal email exchanges regarding security incidents lack the structured, verifiable, and tamper-resistant qualities required for formal audit evidence. While they may document ad-hoc operational discussions, they do not constitute systematic proof of an established incident response capability or continuous control enforcement. Auditors look for formalized incident logs, ticketing system exports, and post-incident reviews rather than unstructured email threads.
- ✗
A summary of security policies and procedures
Why it's wrong here
Policies and procedures define the administrative intent and guidelines of an organization, but they only demonstrate what should be done rather than what is actually being done. A summary of these documents merely proves the existence of governance frameworks, not the operational execution of the controls. Auditors must verify that these written directives are translated into active, technical safeguards through system-generated artifacts.
Go deeper
Related to this question
Learn chapter
Privileged Access Management and PAM Tools
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.