CompTIA Security+ SY0-701 Practice Question
Your organization has implemented strong internal controls to manage sensitive customer data. During a routine internal audit, you discover that a newly implemented software tool does not comply with the established encryption standards. What is the next step to maintain compliance?
Immediately cease using the tool across the organization until it complies with encryption standards.
Document the issue and wait for the next external audit to confirm the non-compliance before taking action.
Request a feature update from the software tool vendor to accommodate the required encryption standards without internal notification.
Report the non-compliance issue to the compliance department for review and correction.