mediumMultiple Select
CS0-003 Practice Question: Which TWO of the following are best practices for…
Which TWO of the following are best practices for distributing security reports to stakeholders?
⚠ Common exam trap
CompTIA often tests the misconception that convenience (e.g., public posting or unencrypted messaging) is acceptable for security reports, when in fact any distribution method must enforce confidentiality, integrity, and access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use encrypted email for sensitive reports
Encrypted email (e.g., using S/MIME or PGP) ensures that sensitive security reports are protected from unauthorized interception during transit, maintaining confidentiality and integrity as required by security best practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Post reports on a public website for easy access
Why it's wrong here
Publishing vulnerability or incident reports on a public-facing web server violates the core security principle of confidentiality. It exposes proprietary network architecture, active vulnerabilities, or sensitive business intelligence to unauthorized external actors, including malicious threat agents seeking targets.
- ✓
Use encrypted email for sensitive reports
Why this is correct
Utilizing end-to-end encryption protocols, such as S/MIME or PGP, ensures that sensitive security reports remain confidential during transit. This prevents eavesdropping and man-in-the-middle attacks, ensuring that only the intended recipient with the corresponding private key can decrypt and read the contents.
- ✗
Send reports via instant messaging without encryption
Why it's wrong here
Transmitting unencrypted reports over standard instant messaging platforms leaves data vulnerable to interception by packet sniffers or unauthorized access on transit servers. Without transport-layer or end-to-end encryption, sensitive technical details can be easily compromised by adversaries monitoring the network path.
- ✗
Print and leave reports in common areas
Why it's wrong here
Leaving hard copies of sensitive reports in shared physical spaces introduces a severe risk of shoulder surfing and unauthorized physical access. This bypasses digital access controls entirely, allowing clean-desk policy violations and enabling insider threats or visitors to view proprietary security findings.
- ✓
Grant access via a secure portal with role-based permissions
Why this is correct
Hosting reports on an HTTPS-secured portal governed by Role-Based Access Control (RBAC) enforces the principle of least privilege. This mechanism restricts access to authorized personnel based on their organizational roles while generating robust audit logs to track who viewed or downloaded the files.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.