Drag a concept onto its matching description — or click a concept then click the description.
Access review attestation report
Approved change ticket
LMS completion export
Retention deletion log
Match each audit request to the best evidence artifact. 1. Auditors want proof that managers reviewed privileged access last quarter. 2. Auditors want evidence that an emergency firewall change was approved before implementation. 3. Auditors want to verify that annual security training was completed by staff. 4. Auditors want to confirm that records were deleted after the retention period expired.
Drag a concept onto its matching description — or click a concept then click the description.
Access review attestation report
Approved change ticket
LMS completion export
Retention deletion log
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Request 1: Access review records with manager sign-offs
Each audit request requires specific evidence: access reviews show manager sign-offs, change requests prove pre-approval, training records confirm completion, and deletion logs demonstrate data disposal per policy.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Request 1: Access review records with manager sign-offs
Why this is correct
Access review records with manager sign-offs are the definitive evidence for an audit request to verify that privileged access is periodically reviewed. These records capture the date of review, the specific accounts or roles examined, and the manager's attestation, establishing accountability and compliance with the principle of least privilege. The sign-off provides a verifiable chain of responsibility, proving the review actually occurred rather than just being scheduled, which is essential for access control audits.
Request 2: Change request with approval timestamp
Why this is correct
A change request with an approval timestamp directly evidences that the emergency firewall change was pre-authorized before implementation. It documents the rationale for the change, the change control board's decision, and the exact approval time, which is critical for verifying chronological compliance with change management policy. Without such a record, an auditor cannot distinguish an authorized change from an unauthorized alteration, making this artifact uniquely suited to a change-approval audit request.
Request 3: Training completion records
Why this is correct
Training completion records, typically exported from a learning management system, prove that each employee finished the mandatory annual security training. They include user identity, course name, completion date, and usually a score or certificate, substantiating the organization's security awareness program. This artifact directly answers an audit request for verification of training participation, but it does not serve operational evidence for infrastructure changes or data lifecycle events.
Request 4: Data deletion logs with timestamps
Why this is correct
Data deletion logs with timestamps demonstrate that records were physically or logically destroyed after the retention period expired, as required by policy or regulation. These logs typically detail the employee who executed the deletion, the storage location, the volume of data removed, and the timestamp of the event. This evidence confirms that the disposal control was executed at the correct time, ensuring data was not prematurely or negligently retained during an audit of data lifecycle management.
Request 2: Access review records with manager sign-offs
Why it's wrong here
Access review records with manager sign-offs are an incorrect artifact for a change-approval request because they attest to user permission reviews, not to the pre-authorization of firewall rule modifications. They contain information about account entitlements and reviewer decisions, but no indication that the specific firewall change was evaluated and approved before implementation. Consequently, this artifact leaves an auditor without proof of adherence to change management governance, so it fails to satisfy the request.
Request 4: Training completion records
Why it's wrong here
Training completion records do not satisfy a request for deletion confirmation because they only prove that employees took security awareness courses; they contain no information about whether data was erased, when the erasure occurred, or which data was affected. This artifact lacks event logs, target paths, or audit trails related to data destruction, providing no evidence that records were removed after their retention period expired. Relying on this artifact would leave a compliance gap in the data lifecycle audit.
Go deeper
Learn chapter
Security Policies and Procedures
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An external auditor asks for proof that emergency firewall changes were reviewed and approved before implementation last quarter. Which two artifacts are the best evidence? Select two.
mediumWhy A: An approved change ticket with reviewer, approver, and timestamps directly documents the required pre-approval workflow for emergency firewall changes. Similarly, CAB or workflow approval records serve as formal documentation of the decision to approve the change. Both artifacts provide an auditable trail showing that the change was reviewed and approved before implementation, which is the exact evidence the auditor is requesting.
Variation 2. An external auditor asks for proof that firewall rule changes were reviewed and approved before being implemented during the last quarter. Which evidence is MOST appropriate to provide?
mediumWhy B: Change tickets provide a formal, auditable record of the entire change management process, including requester identification, reviewer approval, implementation date, and rollback plan. This directly satisfies the auditor's requirement for proof that firewall rule changes were reviewed and approved before implementation, aligning with the principle of separation of duties and change control.
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.