Courseiva
Question 144 of 1,013
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A marketing analyst asks for a spreadsheet containing customer names, email addresses, purchase history, and government ID numbers so the team can build a campaign list. What is the BEST security response?

⚠ Common exam trap

Watch out — candidates often think 'asking not to store it permanently' is a sufficient control, but the SY0-701 exam emphasizes that administrative controls without technical enforcement (like DLP policies or data classification labels) are ineffective against data leakage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Provide only the minimum fields required and remove the government ID numbers.

The best security response is to apply the principle of least privilege and data minimization. Government ID numbers are sensitive personally identifiable information (PII) that are not necessary for building a marketing campaign list; providing only the minimum required fields (e.g., names and email addresses) reduces the risk of exposure and complies with data protection regulations like GDPR or CCPA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Approve the request because the data is needed for any marketing activity.

    Why it's wrong here

    Need alone is not a sufficient justification; data minimization requires assessing the specific business purpose, and marketing does not inherently require government ID numbers. Granting blanket access to all customer data without a legitimate purpose limitation violates privacy principles such as NIST SP 800-122 and GDPR data minimization, and it expands the organization's attack surface. The request should be evaluated against the minimum necessary standard, not simply because the requester is a marketing analyst.

  • Provide only the minimum fields required and remove the government ID numbers.

    Why this is correct

    This follows data minimization and handling requirements by sharing only what is necessary for the business purpose. Government ID numbers are highly sensitive and are not needed for a typical marketing campaign. Limiting the dataset reduces privacy exposure, lowers compliance risk, and helps ensure the data is used appropriately.

  • Send the full file, but ask the analyst not to store it permanently.

    Why it's wrong here

    A verbal instruction to not permanently store the file does not constitute a technical or administrative control; once the full dataset is transmitted, the recipient possesses all sensitive fields and the organization loses control over copying, forwarding, or accidental exposure. Prohibiting permanent storage does not mitigate the immediate risk of redundant data residing in email inboxes, temporary downloads, or analytics pipelines, nor does it address the unnecessary inclusion of government IDs. Instead, the data must be minimized at the source before any sharing occurs, with technical protections such as encryption and access logging in place.

  • Classify the file as public so it can be shared more easily with the marketing team.

    Why it's wrong here

    Reclassifying customer personally identifiable information from internal or restricted to public would authorize broader access and undermine the data classification requirements established in the organization's security policy. Public classification removes the need for access controls and encryption, potentially exposing the data to unauthorized individuals and violating legal data protection obligations. This action increases the likelihood of a breach and is not an appropriate way to facilitate an internal marketing request.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.