SY0-701 Security Program Management and Oversight Practice Question
A security manager wants evidence that annual security awareness training was completed by employees. Which artifact is the best proof?
⚠ Common exam trap
The trap here is that candidates might think a visual artifact like a logo or homepage screenshot proves training occurred, but CompTIA tests the understanding that only a system-generated, auditable report with user-specific completion data constitutes valid evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A training completion report exported from the learning system
A training completion report exported from the learning system is the best proof because it provides a verifiable, timestamped record of each employee's completion status, including user IDs, course names, completion dates, and scores. This artifact directly demonstrates that the training was actually completed, not just assigned or attended, and can be audited against the organization's training policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A training completion report exported from the learning system
Why this is correct
A training completion report exported from the learning management system (LMS) provides authoritative evidence by listing each employee, their completion date, and course status, often including graded results and access history. This system-generated report creates a verifiable audit trail that can be cross-referenced with the LMS database, making it acceptable to internal and external auditors. It specifically demonstrates that the annual security awareness training was fulfilled by the required population.
- ✗
A copy of the company logo used on the training slides
Why it's wrong here
A copy of the company logo used on training slides merely demonstrates brand identity, not that any employee participated in or completed the training. The logo could be present on an empty template or an unrelated document, and it lacks user-specific data such as names, employee IDs, completion dates, or assessment scores. Consequently, it holds no evidentiary value for confirming security awareness training compliance.
- ✗
A list of office supplies purchased last quarter
Why it's wrong here
A list of office supplies purchased last quarter reflects procurement and inventory transactions, which are unrelated to the delivery or completion of security awareness training. This document does not contain employee identifiers, training module references, or engagement metrics, so it cannot prove who completed the required education. It is a business expense record, not a control verification artifact, and would be dismissed as irrelevant in an audit.
- ✗
A screenshot of the company's public homepage
Why it's wrong here
A screenshot of the company's public homepage shows only externally visible marketing content, and it contains no evidence of internal training activity or employee completion records. Screenshots are also unreliable because they can be easily edited or staged, and they lack the metadata and system provenance that auditors expect in evidence. Thus, it does not substantiate that the workforce finished the annual security awareness curriculum.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
Key term
Security awareness
Security awareness is the ongoing practice of educating people within an organization about cybersecurity risks, safe behaviors, and their individual responsibilities to protect information assets.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.