An external auditor asks your vulnerability management team to prove that risk acceptance decisions were governed rather than ad hoc. The evidence pack already includes scan scope, scan findings, remediation tickets, and a summary of exceptions. Which additional artifact most directly supports defensible decision-making?
Select an answer to reveal the explanation.
Short Explanation
Think of governance like a courtroom: the scanner shows what happened, but the judge wants to know who said it was okay and for how long. If your exception register has the approver, expiry, and compensating control, you can defend the decision. Without that trail, you can't turn a 'risk accepted' note into a defensible control.
Full Explanation
Governance reporting is less about volume of data and more about showing a controlled decision process. When a vulnerability cannot be remediated on schedule, the defensible evidence is an exception or risk-acceptance record that identifies who approved the risk, when approval expires, and what compensating control reduces exposure while the risk remains. This turns a scanner finding into a business decision that can be audited. A dashboard screenshot can show status and trends, but it does not show who authorized a deviation or under what conditions. Scanner configuration output supports scan validity and scope, yet it does not explain how accepted risks were governed or reviewed. A remediation spreadsheet can demonstrate tracking and closure activity, but it does not capture formal approval, expiry, or compensating controls for findings that were intentionally not remediated. Exam caveat: CompTIA often rewards the artifact that proves accountability and repeatable control, not merely the one with the most operational detail. Operational check: Reconcile every open exception in the evidence pack to an approver name or role, an expiry date, and a compensating control before submitting it to an auditor.