Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

An employee notices that a contractor left a printed report containing customer data on a conference room table. What should the employee do first?

⚠ Common exam trap

It's easy for candidates to think immediate destruction (shredding) is the best way to protect data, but they overlook the legal and procedural requirement to preserve evidence and report the incident through official channels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Secure the report and report the incident through the company's approved process.

The immediate priority is to protect the sensitive customer data from further unauthorized access by securing the report, and then to follow the organization's incident response policy. This aligns with the principle of data breach containment and the requirement to report security incidents through official channels to ensure proper investigation and compliance with regulations like GDPR or HIPAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Take a photo of the report and post it in the team chat as a warning.

    Why it's wrong here

    Photographing and posting the report to a team chat multiplies the exposure of customer data well beyond the original incident, turning a physical containment problem into an electronic data spill. Even if the intent is to warn others, the act violates the principle of least privilege and likely breaches data handling policies, as the photo becomes a searchable copy outside controlled systems. It also destroys the chain of custody: the image may enter personal devices or unmanaged collaboration tools, complicating any formal incident response and increasing regulatory liability.

  • Secure the report and report the incident through the company's approved process.

    Why this is correct

    The best first action is to protect the sensitive document from further exposure and then report it through the proper process. This limits privacy impact, preserves accountability, and allows the organization to handle the issue according to policy. It also teaches safe behavior without unnecessarily spreading the data.

  • Leave the report where it is so the contractor can collect it later.

    Why it's wrong here

    Leaving the report in place assumes that only the contractor will retrieve it, but any employee, visitor, or cleaning crew can view or remove the document in the meantime. Without secure storage, you cannot guarantee confidentiality or maintain accountability for the data, which may trigger breach notification obligations under regulations like HIPAA or GDPR if it is patient or citizen data. The proper action is to take custody of the document and follow the organization's incident reporting workflow so the contractor's lapse is formally managed and mitigated.

  • Shred the report immediately without telling anyone.

    Why it's wrong here

    Shredding the report before notifying anyone destroys physical evidence that may be essential for an internal investigation, such as identifying how the contractor obtained the data, whether other copies exist, or whether the paper contains hidden tracking marks. Forensic preservation is a core incident response tenet; destroying media can be seen as spoliation and may create legal or compliance sanctions, especially when a data breach response plan requires holding evidence for analysis. Reporting first and letting designated personnel handle retention ensures the organization can assess scope and prevent recurrence without losing critical clues.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.