SY0-701 exam dumps

SY0-701 practice question 456 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 456

Single answerCompliance reporting: Internal , External

A healthcare company recently completed a quarterly review of its access controls, log retention, and incident response procedures. The security manager must provide one report to the executive leadership team to track remediation progress against internal security policies, and a separate report to an external assessor to demonstrate adherence to regulatory requirements. Which approach best meets these reporting needs?

  1. A

    Create a single highly technical report for both audiences so the same evidence is preserved and no information is omitted.

  2. B

    Provide an internal report focused on policy exceptions, risk trends, and remediation status, and provide an external report mapped to the applicable compliance framework and required evidence.

  3. C

    Provide only the external compliance report because executive leadership can rely on the assessor's findings for internal decision-making.

  4. D

    Provide an internal report that lists only pass/fail results and an external report that includes future security strategy and budget requests.

Show answer and explanation

Correct answer: B

Explanation

The best answer is to tailor compliance reporting to its intended audience. Internal compliance reports are commonly used by management, security leadership, and control owners to monitor policy compliance, exceptions, remediation status, and risk trends. External compliance reports are intended for outside parties such as auditors, regulators, partners, or customers and should be aligned to the relevant framework or requirement set, such as HIPAA, PCI DSS, or contractual obligations. Best practice is to reuse underlying evidence where appropriate, but present it differently depending on the audience and objective. This reflects standard audit and governance practices, where internal reporting supports decision-making and continuous improvement, while external reporting supports attestation, validation, and demonstration of compliance.

  • A. Incorrect.

    Incorrect. While reusing evidence can be efficient, internal and external reports serve different purposes and audiences. Internal reporting is typically used for governance, operational decision-making, and remediation tracking, while external reporting is usually structured around specific regulatory, contractual, or audit requirements. A single highly technical report often fails to address executive needs and may include unnecessary detail for external assessors.

  • B. Correct.

    Correct. Internal compliance reporting is generally tailored to management and stakeholders who need visibility into risk, policy exceptions, control effectiveness, and remediation progress. External compliance reporting is usually formatted to demonstrate conformity with a specific standard, law, or contract requirement and should include the evidence and control mapping expected by the auditor, regulator, or customer. This approach aligns reporting with audience, purpose, and evidentiary requirements.

  • C. Incorrect.

    Incorrect. External compliance reports are not a substitute for internal reporting. Leadership needs internal reporting to understand business risk, prioritize remediation, allocate resources, and ensure accountability. Relying only on an external report can leave gaps in operational oversight because external assessments are usually scoped to specific compliance objectives rather than broader internal governance needs.

  • D. Incorrect.

    Incorrect. An internal report limited to pass/fail results lacks the context leadership needs, such as severity, trends, root causes, and remediation ownership. Conversely, external compliance reports should focus on demonstrating adherence to defined requirements, not on internal strategic planning or budget justification unless specifically requested. This option reverses the typical focus of each reporting type.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam