Courseiva
mediumMultiple Select

CS0-003 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for distributing security reports to stakeholders?

⚠ Common exam trap

CompTIA often tests the misconception that convenience (e.g., public posting or unencrypted messaging) is acceptable for security reports, when in fact any distribution method must enforce confidentiality, integrity, and access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use encrypted email for sensitive reports

Encrypted email (e.g., using S/MIME or PGP) ensures that sensitive security reports are protected from unauthorized interception during transit, maintaining confidentiality and integrity as required by security best practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Post reports on a public website for easy access

    Why it's wrong here

    Publishing vulnerability or incident reports on a public-facing web server violates the core security principle of confidentiality. It exposes proprietary network architecture, active vulnerabilities, or sensitive business intelligence to unauthorized external actors, including malicious threat agents seeking targets.

  • ✓

    Use encrypted email for sensitive reports

    Why this is correct

    Utilizing end-to-end encryption protocols, such as S/MIME or PGP, ensures that sensitive security reports remain confidential during transit. This prevents eavesdropping and man-in-the-middle attacks, ensuring that only the intended recipient with the corresponding private key can decrypt and read the contents.

  • ✗

    Send reports via instant messaging without encryption

    Why it's wrong here

    Transmitting unencrypted reports over standard instant messaging platforms leaves data vulnerable to interception by packet sniffers or unauthorized access on transit servers. Without transport-layer or end-to-end encryption, sensitive technical details can be easily compromised by adversaries monitoring the network path.

  • ✗

    Print and leave reports in common areas

    Why it's wrong here

    Leaving hard copies of sensitive reports in shared physical spaces introduces a severe risk of shoulder surfing and unauthorized physical access. This bypasses digital access controls entirely, allowing clean-desk policy violations and enabling insider threats or visitors to view proprietary security findings.

  • ✓

    Grant access via a secure portal with role-based permissions

    Why this is correct

    Hosting reports on an HTTPS-secured portal governed by Role-Based Access Control (RBAC) enforces the principle of least privilege. This mechanism restricts access to authorized personnel based on their organizational roles while generating robust audit logs to track who viewed or downloaded the files.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.