- A
Email the attachment unencrypted if the auditor signed an NDA
Why wrong: An NDA does not provide technical protection for confidential employee data during transmission.
- B
Use an approved encrypted file-sharing portal with named recipients and access logging
Approved encrypted sharing limits access to intended recipients and creates traceability for audit and oversight.
- C
Upload the spreadsheet to a public link so the auditor can access it easily
Why wrong: Public links are difficult to control and create unnecessary exposure of highly sensitive information.
- D
Remove the confidential label before sending it to avoid confusion
Why wrong: Removing the label weakens handling requirements and does not reduce the sensitivity of the data.
Quick Answer
The answer is to use an approved encrypted file-sharing portal with named recipients and access logging. This is correct because it enforces both data-in-transit and data-at-rest encryption, ensuring the spreadsheet containing employee names, salaries, and performance notes remains protected from interception or unauthorized access, while named recipients and logging provide a verifiable audit trail for compliance with regulations like GDPR or HIPAA. On the Security+ SY0-701 exam, this scenario tests your understanding of secure file sharing with an external auditor, often appearing as a trap where unencrypted email or generic cloud links are tempting but fail to meet confidentiality and non-repudiation requirements. A common memory tip is to remember that for sensitive data, you need three things: encryption, access control, and an audit trail—think "EAT" for Encrypt, Authorize, Track.
SY0-701 Security Program Management and Oversight Practice Question
This SY0-701 practice question tests your understanding of security program management and oversight. Read the scenario carefully and evaluate each option against the stated constraints before committing to an answer. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.
A project lead needs to send a spreadsheet labeled confidential to an external auditor. The file contains employee names, salaries, and performance notes. Which handling step best protects the data while still supporting the business need?
Clue words in this question
Noticing these words before you look at the options changes how you read each choice.
Clue:
"best"Why it matters: Signals that multiple options may be partially correct. Choose the option that most directly solves the exact problem described, not the one that sounds most complete.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Use an approved encrypted file-sharing portal with named recipients and access logging
Option B is correct because using an approved encrypted file-sharing portal with named recipients and access logging ensures data-in-transit and data-at-rest encryption, restricts access to only the intended auditor, and provides an audit trail for compliance. This approach meets the business need of securely sharing confidential employee data while supporting regulatory requirements like GDPR or HIPAA, unlike unencrypted email which exposes data to interception.
Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Email the attachment unencrypted if the auditor signed an NDA
Why it's wrong here
An NDA does not provide technical protection for confidential employee data during transmission.
- ✓
Use an approved encrypted file-sharing portal with named recipients and access logging
Why this is correct
Approved encrypted sharing limits access to intended recipients and creates traceability for audit and oversight.
Clue confirmation
The clue word "best" in the question point toward this answer.
Related concept
Read the scenario before looking for a memorised answer.
- ✗
Upload the spreadsheet to a public link so the auditor can access it easily
Why it's wrong here
Public links are difficult to control and create unnecessary exposure of highly sensitive information.
- ✗
Remove the confidential label before sending it to avoid confusion
Why it's wrong here
Removing the label weakens handling requirements and does not reduce the sensitivity of the data.
Common exam traps
Common exam trap: answer the scenario, not the keyword
The trap here is that candidates may think an NDA alone provides sufficient protection, overlooking that encryption and access controls are required to prevent data breaches during transmission and storage.
Detailed technical explanation
How to think about this question
Encrypted file-sharing portals typically use TLS 1.3 for data-in-transit encryption and AES-256 for data-at-rest encryption, with access controls enforced via IAM policies and OAuth 2.0 tokens. Named recipient restrictions prevent unauthorized forwarding, and access logging captures who accessed the file, when, and from which IP, supporting forensic analysis. In a real-world scenario, an auditor might need to prove compliance with SOC 2 or ISO 27001, and these logs serve as evidence of controlled access.
KKey Concepts to Remember
- Read the scenario before looking for a memorised answer.
- Find the constraint that changes the correct option.
- Eliminate answers that are true in general but not in this case.
TExam Day Tips
- Watch for words such as best, first, most likely and least administrative effort.
- Review why wrong options are wrong, not only why the correct option is correct.
Key takeaway
Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.
Real-world example
How this comes up in practice
A developer is choosing between AES-256 (symmetric) and RSA-2048 (asymmetric) for encrypting a large file that will be sent to a partner. Symmetric encryption is fast but requires key exchange; asymmetric is slower but solves the key distribution problem. A hybrid approach — encrypt the file with AES, encrypt the AES key with RSA — is standard. Questions like this test whether you understand when each approach applies.
What to study next
Got this wrong? Here's your next step.
Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.
- →
Security Program Management and Oversight — study guide chapter
Learn the concepts, then practise the questions
- →
Security Program Management and Oversight practice questions
Targeted practice on this topic area only
- →
All SY0-701 questions
1,152 questions across all exam domains
- →
Security+ SY0-701 study guide
Full concept coverage aligned to exam objectives
- →
SY0-701 practice test guide
How to use practice tests most effectively before exam day
Related practice questions
Related SY0-701 practice-question pages
Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.
General Security Concepts practice questions
Practise SY0-701 questions linked to General Security Concepts.
Threats, Vulnerabilities, and Mitigations practice questions
Practise SY0-701 questions linked to Threats, Vulnerabilities, and Mitigations.
Security Architecture practice questions
Practise SY0-701 questions linked to Security Architecture.
Security Operations practice questions
Practise SY0-701 questions linked to Security Operations.
Security Program Management and Oversight practice questions
Practise SY0-701 questions linked to Security Program Management and Oversight.
Security+ social engineering questions
Practise SY0-701 questions linked to Security+ social engineering questions.
Security+ cryptography practice questions
Practise SY0-701 questions linked to Security+ cryptography.
Security+ IAM questions
Practise SY0-701 questions linked to Security+ IAM questions.
Security+ risk management questions
Practise SY0-701 questions linked to Security+ risk management questions.
Security+ incident response questions
Practise SY0-701 questions linked to Security+ incident response questions.
Security+ malware questions
Practise SY0-701 questions linked to Security+ malware questions.
Security+ vulnerability management questions
Practise SY0-701 questions linked to Security+ vulnerability management questions.
Practice this exam
Start a free SY0-701 practice session
Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.
FAQ
Questions learners often ask
What does this SY0-701 question test?
Security Program Management and Oversight — This question tests Security Program Management and Oversight — Read the scenario before looking for a memorised answer..
What is the correct answer to this question?
The correct answer is: Use an approved encrypted file-sharing portal with named recipients and access logging — Option B is correct because using an approved encrypted file-sharing portal with named recipients and access logging ensures data-in-transit and data-at-rest encryption, restricts access to only the intended auditor, and provides an audit trail for compliance. This approach meets the business need of securely sharing confidential employee data while supporting regulatory requirements like GDPR or HIPAA, unlike unencrypted email which exposes data to interception.
What should I do if I get this SY0-701 question wrong?
Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.
Are there clue words in this question I should notice?
Yes — watch for: "best". Signals that multiple options may be partially correct. Choose the option that most directly solves the exact problem described, not the one that sounds most complete.
What is the key concept behind this question?
Read the scenario before looking for a memorised answer.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A project team must share a spreadsheet containing customer names, account numbers, and purchase history with an external auditor. The auditor only needs account numbers and totals. What is the best privacy control?
medium- A.Send the full spreadsheet through regular email to avoid delaying the audit
- ✓ B.Redact unneeded personal data and transfer only the minimum necessary information through an approved encrypted channel
- C.Upload the spreadsheet to a public file-sharing site and protect it with a password
- D.Compress the file with a password and reuse the same password for all auditors
Why B: Option B is correct because it applies the principle of data minimization and secure transmission. Redacting unneeded personal data (customer names) ensures only the minimum necessary information (account numbers and totals) is shared, reducing exposure. Transferring via an approved encrypted channel (e.g., SFTP, HTTPS, or encrypted email) protects data in transit from interception, which is required for compliance with regulations like GDPR or PCI DSS.
Variation 2. A manager needs to send a spreadsheet containing employee names, salaries, and performance notes to an external auditor. Which two actions best support proper data handling? Select two.
easy- ✓ A.Apply the correct classification label before sending
- B.Upload the file to a personal cloud account
- C.Remove the salary columns and send the rest by email
- ✓ D.Use the organization's approved encrypted sharing method
- E.Print the file and leave it on a shared desk
Why A: Option A is correct because applying the correct classification label (e.g., 'Confidential' or 'Internal Use Only') ensures that the data is properly identified and handled according to the organization's data classification policy. This is a foundational step in data handling, as it triggers appropriate security controls such as encryption, access restrictions, and handling procedures. Without a classification label, the sensitivity of the data may be overlooked, leading to potential mishandling.
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.