Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A project lead needs to send a spreadsheet labeled confidential to an external auditor. The file contains employee names, salaries, and performance notes. Which handling step best protects the data while still supporting the business need?

⚠ Common exam trap

Candidates often think an NDA alone provides sufficient protection, overlooking that encryption and access controls are required to prevent data breaches during transmission and storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use an approved encrypted file-sharing portal with named recipients and access logging

Using an approved encrypted file-sharing portal with named recipients and access logging ensures data-in-transit and data-at-rest encryption, restricts access to only the intended auditor, and provides an audit trail for compliance. This approach meets the business need of securely sharing confidential employee data while supporting regulatory requirements like GDPR or HIPAA, unlike unencrypted email which exposes data to interception.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Email the attachment unencrypted if the auditor signed an NDA

    Why it's wrong here

    An NDA is a legal agreement, not a technical control, and it does nothing to protect the confidentiality of the spreadsheet while it is in transit. Unencrypted email sends the data as plaintext over the internet, where intermediary servers and email providers can store or intercept it, and even TLS only protects the connection between specific mail servers, not the content at rest on endpoints. The auditor's signature creates liability after a breach but does not prevent interception or unauthorized access to the data.

  • Use an approved encrypted file-sharing portal with named recipients and access logging

    Why this is correct

    An approved encrypted file-sharing portal enforces confidentiality through encryption in transit (TLS) and at rest (AES-256), while limiting access to authenticated, named recipients via unique accounts or email invitations. The portal logs every access attempt, download, and interaction, creating a permanent audit trail that satisfies compliance and accountability requirements. It also allows policy controls such as link expiration, download limits, and the ability to revoke access, ensuring that only the intended auditor can view the data and that the exposure window is tightly controlled.

  • Upload the spreadsheet to a public link so the auditor can access it easily

    Why it's wrong here

    Posting the spreadsheet as a public link removes all authentication and authorization checks, meaning anyone who obtains the URL—through search engine indexing, forwarding, or accidental exposure—can view the file. There is no per-person access logging, because the portal only sees anonymous requests, and the link cannot be reliably revoked once it has been shared, as copies may already exist. This transforms a controlled confidential document into an open data exposure, violating the principle of least privilege and making it impossible to trace who actually accessed the data.

  • Remove the confidential label before sending it to avoid confusion

    Why it's wrong here

    Removing the 'confidential' label does not change the intrinsic sensitivity of the employee data; it merely strips away an administrative control that signals handlers to apply technical safeguards like encryption and restricted access. This action can lead to careless handling and insecure transmission, because the lack of a label discourages personnel from following required security procedures, thereby increasing the risk of exposure. Moreover, altering classification labels may violate organizational policy and data governance requirements, and it completely sidesteps the underlying need to protect the data regardless of its label.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.