Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A data analyst needs a copy of a customer file for product testing. The file includes names, email addresses, purchase history, and government ID numbers, but the test team only needs the names and purchase history. What is the BEST handling action?

⚠ Common exam trap

Candidates often assume internal teams are automatically trusted and fail to apply data minimization, overlooking that even trusted users should only receive the minimum data necessary for their role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remove or mask the government ID numbers before sharing the minimum necessary fields.

It applies the principle of least privilege and data minimization. The test team only needs names and purchase history, so removing or masking the government ID numbers before sharing the minimum necessary fields protects sensitive personally identifiable information (PII) and complies with data protection regulations like GDPR or CCPA. This action reduces the risk of unauthorized exposure of high-risk data while still enabling the test team to perform their work.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Provide the full file because the test team is internal and already trusted.

    Why it's wrong here

    Internal trust does not override the principle of least privilege or data minimization policies that apply to all personnel, including contractors and full-time employees. Customer records containing government ID numbers fall under regulatory and contractual confidentiality obligations (e.g., HIPAA, GDPR, PCI DSS) that mandate restricting access to only the fields required for the task. A compromised or careless insider can still exfiltrate the full file, so sharing the complete dataset is an avoidable privacy risk.

  • Remove or mask the government ID numbers before sharing the minimum necessary fields.

    Why this is correct

    This is the best action because it follows data minimization and privacy principles. The test team does not need government ID numbers, so those fields should be removed or masked before the data is shared. Limiting the dataset to the minimum necessary information reduces privacy risk, lowers the chance of unauthorized disclosure, and aligns with common handling requirements for sensitive customer data.

  • Encrypt the file and send it by email to the entire test group.

    Why it's wrong here

    Encryption safeguards the file in transit, but it does not address the fact that distributing it to the entire test group expands the user population with access far beyond the analysts who need it. Group email creates persistent copies in mail servers, individual inboxes, mobile devices, and backups, making it far harder to track or revoke access later. Proper handling would use a secure file share with per-user permissions and audit logging, rather than a broad broadcast.

  • Keep the file unchanged and rely on the team not to open the sensitive columns.

    Why it's wrong here

    Relying on the team to simply avoid opening sensitive columns is a weak administrative control that ignores the need for technical safeguards like column-level masking or redaction. The data remains fully sensitive at rest, in memory, and in any derivative files, so even accidental opening or a screen share could expose government ID numbers. Least privilege demands that the test environment receive only the minimum necessary fields, not that users be trusted to self-censor.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.