An organization is preparing evidence for a compliance audit. Which of the following pieces of evidence would BEST demonstrate that a security control is effective?
A control effectiveness report supplies measured test results and metrics, giving auditors objective proof that the control operates as intended rather than merely existing. This directly satisfies the stem's requirement to demonstrate effectiveness, since design documentation or policy statements alone cannot evidence actual performance.
Why this answer
A control effectiveness report with test results and metrics provides objective, measurable evidence that the control actually works as intended, which is what auditors require. Configuration screenshots and policy documents only show intent or design, not operational effectiveness.
Exam trap
CS0-004 often tests the difference between design evidence (policies, screenshots) and operating effectiveness evidence (test results, metrics), tempting candidates to pick a configuration screenshot because it 'shows' the control.
How to eliminate wrong answers
Option A is wrong because a screenshot of the configuration shows the control was set up but not that it functions correctly or is enforced over time. Option B is wrong because a policy document describes what should be done, which is design evidence, not proof of operating effectiveness. Option D is wrong because an email assertion from the system owner is subjective, unverified, and lacks the test data auditors need to conclude the control is effective.