How to confirm a software application is no longer in scope for external reporting?

The internal audit team determines a software application is no longer in scope for external reporting requirements. Which of the following will confirm that the application is no longer applicable?

  1. Data inventory and retention
  2. Right to be forgotten
  3. Due care and due diligence
  4. Acknowledgement and attestation Source Reference Answer

Community Votes

D
67%
A
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests your ability to identify the formal governance mechanism that confirms a system's removal from a compliance scope, with the common trap being confusing operational data reviews with formal sign-off procedures.

When an internal audit determines a software application is no longer in scope for external reporting, acknowledgement and attestation provide the formal documented sign-off needed to confirm its removal from scope. Community consensus strongly favors attestation as the definitive control to verify applicability changes.

Many candidates choose 'Data inventory and retention' (Option A) because it seems logical to verify data relevance first; however, an inventory is an investigative tool, not the formal confirmation mechanism that attestation provides.

Community Discussion (4 comments)

Commando9800 👍 1 Selected: D
D. Acknowledgement and attestation
prabh1251 👍 2 Selected: D
In the context of CompTIA Security+ certification, the correct option is: D. Acknowledgement and attestation – This involves formal documentation or sign-off to confirm that the application is no longer required for external reporting
test_arrow 👍 3 Selected: A
Explanation: A data inventory and retention review helps confirm whether a software application still processes, stores, or transmits data relevant to external reporting requirements. If an application no longer holds relevant data, it can be formally removed from scope.
PjoterK 👍 3 Selected: D
Acknowledgement and attestation is the most appropriate method to formally confirm that a software application is no longer applicable for external reporting requirements. This ensures that there is a documented and verifiable statement from the relevant parties affirming the change in status

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Acknowledgement and attestation (Option D) provides the formal, documented sign-off from authorized parties confirming that the application is no longer applicable for external reporting requirements. In GRC frameworks, attestation serves as the auditable evidence that stakeholders have reviewed and agreed upon the change in scope. This documented confirmation is what auditors and regulators require to validate that a system has been properly removed from compliance obligations.

Why the Other Options Are Wrong

Option A (Data inventory and retention) is an operational process used to identify what data exists and how long it should be kept, but it does not constitute formal confirmation of scope removal. Option B (Right to be forgotten) is a privacy regulation concept related to data subject requests, not scope determination. Option C (Due care and due diligence) represents the general legal and ethical obligation to act responsibly, but it is too broad and abstract to serve as specific confirmation documentation.

Community Comment Notes

The vote split (67 for D, 33 for A) reveals significant confusion between investigative processes and formal confirmation mechanisms. Comment [1] advocates for Option A, arguing that data inventory helps confirm whether an application still processes relevant data, which is a reasonable operational step but not the final confirmation. Comments [2], [3], and [4] correctly identify that attestation provides the documented and verifiable statement needed to formally affirm the change in status, which aligns with audit and compliance requirements.

Official Reference

Exam Strategy

When a question asks what will 'confirm' or 'verify' a governance decision, look for formal documentation and sign-off mechanisms like attestation rather than operational processes. Distinguish between tools used to investigate a situation and the formal evidence used to document the conclusion.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide