SY0-701 Security Program Management and Oversight Practice Question
A project lead needs to send a spreadsheet labeled confidential to an external auditor. The file contains employee names, salaries, and performance notes. Which handling step best protects the data while still supporting the business need?
⚠ Common exam trap
Candidates often think an NDA alone provides sufficient protection, overlooking that encryption and access controls are required to prevent data breaches during transmission and storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an approved encrypted file-sharing portal with named recipients and access logging
Using an approved encrypted file-sharing portal with named recipients and access logging ensures data-in-transit and data-at-rest encryption, restricts access to only the intended auditor, and provides an audit trail for compliance. This approach meets the business need of securely sharing confidential employee data while supporting regulatory requirements like GDPR or HIPAA, unlike unencrypted email which exposes data to interception.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Email the attachment unencrypted if the auditor signed an NDA
Why it's wrong here
An NDA is a legal agreement, not a technical control, and it does nothing to protect the confidentiality of the spreadsheet while it is in transit. Unencrypted email sends the data as plaintext over the internet, where intermediary servers and email providers can store or intercept it, and even TLS only protects the connection between specific mail servers, not the content at rest on endpoints. The auditor's signature creates liability after a breach but does not prevent interception or unauthorized access to the data.
- ✓
Use an approved encrypted file-sharing portal with named recipients and access logging
Why this is correct
An approved encrypted file-sharing portal enforces confidentiality through encryption in transit (TLS) and at rest (AES-256), while limiting access to authenticated, named recipients via unique accounts or email invitations. The portal logs every access attempt, download, and interaction, creating a permanent audit trail that satisfies compliance and accountability requirements. It also allows policy controls such as link expiration, download limits, and the ability to revoke access, ensuring that only the intended auditor can view the data and that the exposure window is tightly controlled.
- ✗
Upload the spreadsheet to a public link so the auditor can access it easily
Why it's wrong here
Posting the spreadsheet as a public link removes all authentication and authorization checks, meaning anyone who obtains the URL—through search engine indexing, forwarding, or accidental exposure—can view the file. There is no per-person access logging, because the portal only sees anonymous requests, and the link cannot be reliably revoked once it has been shared, as copies may already exist. This transforms a controlled confidential document into an open data exposure, violating the principle of least privilege and making it impossible to trace who actually accessed the data.
- ✗
Remove the confidential label before sending it to avoid confusion
Why it's wrong here
Removing the 'confidential' label does not change the intrinsic sensitivity of the employee data; it merely strips away an administrative control that signals handlers to apply technical safeguards like encryption and restricted access. This action can lead to careless handling and insecure transmission, because the lack of a label discourages personnel from following required security procedures, thereby increasing the risk of exposure. Moreover, altering classification labels may violate organizational policy and data governance requirements, and it completely sidesteps the underlying need to protect the data regardless of its label.
Go deeper
Related to this question
Learn chapter
Compliance and Regulatory Frameworks
Key term
Audit trail
An audit trail is a chronological record of events, changes, or activities in a system that provides evidence of who did what, when, and from where.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.