SY0-701 Security Program Management and Oversight Practice Question
A marketing analyst asks for a spreadsheet containing customer names, email addresses, purchase history, and government ID numbers so the team can build a campaign list. What is the BEST security response?
⚠ Common exam trap
Watch out — candidates often think 'asking not to store it permanently' is a sufficient control, but the SY0-701 exam emphasizes that administrative controls without technical enforcement (like DLP policies or data classification labels) are ineffective against data leakage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide only the minimum fields required and remove the government ID numbers.
The best security response is to apply the principle of least privilege and data minimization. Government ID numbers are sensitive personally identifiable information (PII) that are not necessary for building a marketing campaign list; providing only the minimum required fields (e.g., names and email addresses) reduces the risk of exposure and complies with data protection regulations like GDPR or CCPA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Approve the request because the data is needed for any marketing activity.
Why it's wrong here
Need alone is not a sufficient justification; data minimization requires assessing the specific business purpose, and marketing does not inherently require government ID numbers. Granting blanket access to all customer data without a legitimate purpose limitation violates privacy principles such as NIST SP 800-122 and GDPR data minimization, and it expands the organization's attack surface. The request should be evaluated against the minimum necessary standard, not simply because the requester is a marketing analyst.
- ✓
Provide only the minimum fields required and remove the government ID numbers.
Why this is correct
This follows data minimization and handling requirements by sharing only what is necessary for the business purpose. Government ID numbers are highly sensitive and are not needed for a typical marketing campaign. Limiting the dataset reduces privacy exposure, lowers compliance risk, and helps ensure the data is used appropriately.
- ✗
Send the full file, but ask the analyst not to store it permanently.
Why it's wrong here
A verbal instruction to not permanently store the file does not constitute a technical or administrative control; once the full dataset is transmitted, the recipient possesses all sensitive fields and the organization loses control over copying, forwarding, or accidental exposure. Prohibiting permanent storage does not mitigate the immediate risk of redundant data residing in email inboxes, temporary downloads, or analytics pipelines, nor does it address the unnecessary inclusion of government IDs. Instead, the data must be minimized at the source before any sharing occurs, with technical protections such as encryption and access logging in place.
- ✗
Classify the file as public so it can be shared more easily with the marketing team.
Why it's wrong here
Reclassifying customer personally identifiable information from internal or restricted to public would authorize broader access and undermine the data classification requirements established in the organization's security policy. Public classification removes the need for access controls and encryption, potentially exposing the data to unauthorized individuals and violating legal data protection obligations. This action increases the likelihood of a breach and is not an appropriate way to facilitate an internal marketing request.
Go deeper
Related to this question
Learn chapter
GDPR, HIPAA, and PCI-DSS
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.