Question 908 of 1,152
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

Quick Answer

The answer is to use an approved encrypted file-sharing portal with named recipients and access logging. This is correct because it enforces both data-in-transit and data-at-rest encryption, ensuring the spreadsheet containing employee names, salaries, and performance notes remains protected from interception or unauthorized access, while named recipients and logging provide a verifiable audit trail for compliance with regulations like GDPR or HIPAA. On the Security+ SY0-701 exam, this scenario tests your understanding of secure file sharing with an external auditor, often appearing as a trap where unencrypted email or generic cloud links are tempting but fail to meet confidentiality and non-repudiation requirements. A common memory tip is to remember that for sensitive data, you need three things: encryption, access control, and an audit trail—think "EAT" for Encrypt, Authorize, Track.

SY0-701 Security Program Management and Oversight Practice Question

This SY0-701 practice question tests your understanding of security program management and oversight. Read the scenario carefully and evaluate each option against the stated constraints before committing to an answer. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

A project lead needs to send a spreadsheet labeled confidential to an external auditor. The file contains employee names, salaries, and performance notes. Which handling step best protects the data while still supporting the business need?

Clue words in this question

Noticing these words before you look at the options changes how you read each choice.

  • Clue: "best"

    Why it matters: Signals that multiple options may be partially correct. Choose the option that most directly solves the exact problem described, not the one that sounds most complete.

Question 1mediummultiple choice
Full question →

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use an approved encrypted file-sharing portal with named recipients and access logging

Option B is correct because using an approved encrypted file-sharing portal with named recipients and access logging ensures data-in-transit and data-at-rest encryption, restricts access to only the intended auditor, and provides an audit trail for compliance. This approach meets the business need of securely sharing confidential employee data while supporting regulatory requirements like GDPR or HIPAA, unlike unencrypted email which exposes data to interception.

Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Email the attachment unencrypted if the auditor signed an NDA

    Why it's wrong here

    An NDA does not provide technical protection for confidential employee data during transmission.

  • Use an approved encrypted file-sharing portal with named recipients and access logging

    Why this is correct

    Approved encrypted sharing limits access to intended recipients and creates traceability for audit and oversight.

    Clue confirmation

    The clue word "best" in the question point toward this answer.

    Related concept

    Read the scenario before looking for a memorised answer.

  • Upload the spreadsheet to a public link so the auditor can access it easily

    Why it's wrong here

    Public links are difficult to control and create unnecessary exposure of highly sensitive information.

  • Remove the confidential label before sending it to avoid confusion

    Why it's wrong here

    Removing the label weakens handling requirements and does not reduce the sensitivity of the data.

Common exam traps

Common exam trap: answer the scenario, not the keyword

The trap here is that candidates may think an NDA alone provides sufficient protection, overlooking that encryption and access controls are required to prevent data breaches during transmission and storage.

Detailed technical explanation

How to think about this question

Encrypted file-sharing portals typically use TLS 1.3 for data-in-transit encryption and AES-256 for data-at-rest encryption, with access controls enforced via IAM policies and OAuth 2.0 tokens. Named recipient restrictions prevent unauthorized forwarding, and access logging captures who accessed the file, when, and from which IP, supporting forensic analysis. In a real-world scenario, an auditor might need to prove compliance with SOC 2 or ISO 27001, and these logs serve as evidence of controlled access.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Real-world example

How this comes up in practice

A developer is choosing between AES-256 (symmetric) and RSA-2048 (asymmetric) for encrypting a large file that will be sent to a partner. Symmetric encryption is fast but requires key exchange; asymmetric is slower but solves the key distribution problem. A hybrid approach — encrypt the file with AES, encrypt the AES key with RSA — is standard. Questions like this test whether you understand when each approach applies.

What to study next

Got this wrong? Here's your next step.

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

Related practice questions

Related SY0-701 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

Practice this exam

Start a free SY0-701 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this SY0-701 question test?

Security Program Management and Oversight — This question tests Security Program Management and Oversight — Read the scenario before looking for a memorised answer..

What is the correct answer to this question?

The correct answer is: Use an approved encrypted file-sharing portal with named recipients and access logging — Option B is correct because using an approved encrypted file-sharing portal with named recipients and access logging ensures data-in-transit and data-at-rest encryption, restricts access to only the intended auditor, and provides an audit trail for compliance. This approach meets the business need of securely sharing confidential employee data while supporting regulatory requirements like GDPR or HIPAA, unlike unencrypted email which exposes data to interception.

What should I do if I get this SY0-701 question wrong?

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

Are there clue words in this question I should notice?

Yes — watch for: "best". Signals that multiple options may be partially correct. Choose the option that most directly solves the exact problem described, not the one that sounds most complete.

What is the key concept behind this question?

Read the scenario before looking for a memorised answer.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A project team must share a spreadsheet containing customer names, account numbers, and purchase history with an external auditor. The auditor only needs account numbers and totals. What is the best privacy control?

medium
  • A.Send the full spreadsheet through regular email to avoid delaying the audit
  • B.Redact unneeded personal data and transfer only the minimum necessary information through an approved encrypted channel
  • C.Upload the spreadsheet to a public file-sharing site and protect it with a password
  • D.Compress the file with a password and reuse the same password for all auditors

Why B: Option B is correct because it applies the principle of data minimization and secure transmission. Redacting unneeded personal data (customer names) ensures only the minimum necessary information (account numbers and totals) is shared, reducing exposure. Transferring via an approved encrypted channel (e.g., SFTP, HTTPS, or encrypted email) protects data in transit from interception, which is required for compliance with regulations like GDPR or PCI DSS.

Variation 2. A manager needs to send a spreadsheet containing employee names, salaries, and performance notes to an external auditor. Which two actions best support proper data handling? Select two.

easy
  • A.Apply the correct classification label before sending
  • B.Upload the file to a personal cloud account
  • C.Remove the salary columns and send the rest by email
  • D.Use the organization's approved encrypted sharing method
  • E.Print the file and leave it on a shared desk

Why A: Option A is correct because applying the correct classification label (e.g., 'Confidential' or 'Internal Use Only') ensures that the data is properly identified and handled according to the organization's data classification policy. This is a foundational step in data handling, as it triggers appropriate security controls such as encryption, access restrictions, and handling procedures. Without a classification label, the sensitivity of the data may be overlooked, leading to potential mishandling.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.