SY0-701 exam dumps

SY0-701 practice question 455 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 455

Single answerCompliance reporting: Internal , External

A healthcare company is preparing two different compliance reports after a quarterly security review. Senior management wants a report that summarizes risk trends, policy exceptions, and remediation progress across departments. At the same time, an independent regulator has requested evidence that the company is meeting required security and privacy controls for protected health information. Which approach BEST meets both reporting needs?

  1. A

    Provide the same detailed vulnerability scan report to both senior management and the regulator to ensure consistency

  2. B

    Create an internal report focused on business risk, trends, and remediation status for management, and a separate external report mapped to applicable regulatory control requirements with supporting evidence

  3. C

    Prepare a regulator-facing report first, then reuse it internally because compliance reports should be identical for all audiences

  4. D

    Deliver an internal report with technical log data only, and provide the regulator with a high-level executive summary to avoid exposing sensitive details

Show answer and explanation

Correct answer: B

Explanation

The best answer is to produce separate but related reports for internal and external audiences. In practice, internal compliance reporting is used to inform governance, track remediation, identify policy exceptions, and support management decisions. External compliance reporting is intended for parties such as regulators, auditors, or customers and must demonstrate adherence to specific requirements through documented evidence. Security and compliance best practices emphasize audience-appropriate reporting, evidence retention, and traceability from controls to findings to remediation. In regulated environments such as healthcare, external reporting often aligns to applicable frameworks and legal obligations, while internal reporting focuses more on risk management and operational oversight. This distinction is consistent with common governance, risk, and compliance practices and with audit preparation guidance that recommends tailoring reports to stakeholder needs while preserving underlying evidence.

  • A. Incorrect.

    This is incorrect because internal and external compliance reporting serve different audiences and purposes. Senior management typically needs summarized information that supports governance, risk decisions, and resource allocation. Regulators or external assessors usually require evidence-based reporting aligned to specific legal, regulatory, or contractual requirements. A raw vulnerability scan may be too technical for executives and may not demonstrate full compliance on its own.

  • B. Correct.

    This is correct because internal reporting is usually tailored to organizational stakeholders, such as executives, risk committees, and department leaders, and emphasizes business impact, trends, exceptions, and remediation progress. External reporting is typically structured around the requirements of a regulator, auditor, or customer and includes control mappings, attestation details, and supporting evidence. This approach aligns the report format and content to the intended audience while maintaining accuracy and traceability.

  • C. Incorrect.

    This is incorrect because internal and external reports should not automatically be identical. Although they may draw from the same source data, they are generally tailored for different stakeholders. External reports often need formal compliance mappings and evidence packages, while internal reports are often more focused on operational status, risk posture, and decision-making. Reusing one report unchanged for all audiences is a common mistake.

  • D. Incorrect.

    This is incorrect because the reporting depth is reversed from what is usually needed. Internal stakeholders often benefit from concise summaries tied to business objectives, not only raw technical logs. External regulators typically need sufficient detail and objective evidence to validate compliance claims, not just an executive summary. Withholding necessary evidence can result in a failed assessment or follow-up findings.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam