SY0-701 Security Program Management and Oversight Practice Question
A coworker asks for a spreadsheet containing employee home addresses and personal phone numbers so they can build a team contact list. What is the best response?
⚠ Common exam trap
Watch out — candidates often assume internal requests are automatically safe, ignoring the need for authorization and data minimization, which is a common misconception tested in SY0-701.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Confirm the requester is authorized and only provide the minimum personal data allowed by policy.
It aligns with the principle of least privilege and data minimization, which are core to security program management. Even internal requests must be verified for authorization, and only the minimum personal data required for the stated purpose should be shared, as per organizational policy and privacy regulations like GDPR or CCPA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share the spreadsheet, because the request is from another employee inside the company.
Why it's wrong here
Although the requester is an internal employee, employment status alone never confers a blanket right to view sensitive personal data. Home addresses are classified as personally identifiable information (PII) and are typically protected by organizational data-handling policies, employment agreements, and privacy regulations such as GDPR or CCPA. Before sharing, you must verify that the requester has an approved business purpose, a signed authorization, and a genuine need-to-know under the principle of least privilege. Unauthorized internal disclosure still constitutes a data breach and can expose the organization to legal liability and insider-threat risk.
- ✓
Confirm the requester is authorized and only provide the minimum personal data allowed by policy.
Why this is correct
The best response is to verify authorization and limit the data shared to the minimum needed. Privacy and data-handling rules often restrict personal information such as home addresses and personal phone numbers. Even internal requests should follow approved business purpose, least privilege, and data minimization principles before any disclosure occurs.
- ✗
Email the full spreadsheet, because internal data is not protected by privacy rules.
Why it's wrong here
Emailing the full spreadsheet is wrong because internal data is absolutely subject to privacy and security controls. Home addresses and other personal details qualify as PII, and many jurisdictions (e.g., GDPR, PIPL, or state breach laws) regulate how such data may be processed, even within an organization. Additionally, sending the complete file violates the data minimization principle by exposing unrelated employees' information when only a subset may be needed. Email is also an insecure transport channel that could be intercepted or forwarded, compounding the confidentiality risk.
- ✗
Delete the spreadsheet immediately so the information cannot be misused.
Why it's wrong here
Deleting the spreadsheet without following procedure is an improper response to a legitimate access request. Records retention policies and potential legal holds may require preserving the file, and destruction could obstruct an authorized business need or investigation. The correct approach is to assess the request through the official access-control process, verify the requester's authorization, and release only the minimum data necessary. Erasing data preemptively also prevents audit logging and accountability, making it harder to demonstrate compliant handling if the decision is later reviewed.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Authorization
Authorization determines what an authenticated user is allowed to do within a system, such as accessing files, running programs, or changing settings.
Key term
GDPR
The General Data Protection Regulation (GDPR) is a European Union law that sets strict rules for how organizations collect, store, process, and protect the personal data of individuals within the EU.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.