Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A help desk technician receives a ticket asking for a password reset on a manager's account. The requester says the manager is traveling and cannot be reached. What is the best action before making any change?

⚠ Common exam trap

Many exam-takers assume urgency (Option A) is acceptable, but CompTIA emphasizes that security controls must never be bypassed for convenience, and password sharing (Option C) is always a violation of security best practices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify the request through an approved identity-check process before taking action.

The principle of least privilege and proper identity verification are critical before performing any privileged action like a password reset. Without verifying the requester's identity through an approved process (e.g., out-of-band verification, knowledge-based authentication, or manager callback), the technician risks unauthorized access, which could lead to a security breach. This aligns with the CompTIA SY0-701 objective on implementing identity and access management controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Reset the password immediately to avoid delaying the manager's work.

    Why it's wrong here

    Resetting the password immediately to avoid delaying the manager's work bypasses all identity verification and authorization steps, which is exactly what social engineering exploits. An attacker who merely claims to be a manager and creates a sense of urgency could gain control of a legitimate account without any proof. Security policies require identity proofing via out-of-band verification, and privileges like password resets must not be granted based on perceived time pressure. This action also violates the principle of least privilege and change management, potentially leading to a data breach.

  • Verify the request through an approved identity-check process before taking action.

    Why this is correct

    The best action is to verify the requester and the request using the organization's approved process before changing access. This helps prevent social engineering and unauthorized account changes. Account resets are sensitive because they can give an attacker control if the help desk relies only on a convincing story or urgent pressure.

  • Tell the requester to ask a coworker to share the manager's existing password.

    Why it's wrong here

    Telling the requester to have a coworker share the manager's existing password directly violates password policies and destroys non-repudiation, as multiple individuals would then know the secret. This practice makes it impossible to attribute actions taken under that account to the actual account owner and increases the attack surface by distributing credentials. Additionally, the coworker has no authority to share another person's password, and the requester might not even be a legitimate employee. The correct procedure is to issue a temporary credential through an approved identity-check process, not to reuse or expose an existing one.

  • Ignore the ticket until the manager returns from travel.

    Why it's wrong here

    Ignoring the ticket until the manager returns from travel is not a security control because it does nothing to verify the requester's identity or the request's legitimacy; it simply delays the decision. An attacker could just as easily disrupt the manager's work by resubmitting the request later, and a legitimate request would be unnecessarily blocked, causing business disruption. Proper security requires an approved verification process, such as a call back to the manager on a known phone number or confirmation through a second authorized party, rather than assuming that waiting inherently mitigates risk. This approach mistakenly equates inactivity with protection, leaving unresolved vulnerabilities.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.