SY0-701 Security Program Management and Oversight Practice Question
A records manager finds a folder of payroll reports on a shared drive. The business says the reports are no longer active, but legal retention rules require keeping them for another two years. What is the best action?
⚠ Common exam trap
Watch out — candidates often assume 'no longer active' means the data can be deleted, ignoring the overriding legal retention requirement, or they may think renaming or distributing files is a valid workaround instead of using a proper archive solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Move the reports to an approved archive and retain them for the required period
The reports are subject to a legal retention policy requiring two more years of storage. Moving them to an approved archive ensures they remain accessible for compliance purposes while removing them from the active shared drive, which reduces the risk of accidental modification or deletion. This aligns with data lifecycle management and legal hold procedures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the reports immediately because the business no longer uses them
Why it's wrong here
Deleting the reports immediately without consulting the retention schedule constitutes spoliation—the destruction of evidence potentially relevant to litigation, audits, or regulatory inquiries. Payroll records frequently have statutory retention periods (e.g., under the Fair Labor Standards Act) that apply regardless of current operational use, and premature deletion can trigger fines, legal sanctions, or adverse inference instructions. A compliant disposition process requires documented authorization and verification that no legal or regulatory hold applies before any physical or logical deletion occurs.
- ✓
Move the reports to an approved archive and retain them for the required period
Why this is correct
Moving the reports to an approved archive—implemented with immutable storage, access logging, and role-based permissions—satisfies the governing retention schedule while also preserving the records' authenticity and metadata for any future audit or e-discovery request. This action removes the sensitive payroll data from the unrestricted shared workspace and places it under formal records management controls, ensuring it remains retrievable for the required period. The archive should also recognize any active legal hold and tag the records for automatic, auditable disposition once that period expires without risk of inadvertent loss.
- ✗
Email the reports to each manager so they can keep their own copy
Why it's wrong here
Emailing the reports to individual managers breaks the chain of custody by creating multiple decentralized copies that lack consistent classification, encryption, and access governance. Each inbox becomes an uncontrolled repository, making it impossible to enforce a single retention period or to uniformly respond to legal holds, while also enlarging the attack surface for data exfiltration and violating privacy principles like data minimization. Informal email copies also defeat future disposal obligations because managers may keep or delete them arbitrarily, creating compliance liability under regulations such as GDPR or the Sarbanes-Oxley Act.
- ✗
Rename the folder so users do not notice it on the shared drive
Why it's wrong here
Renaming the folder merely changes its label while leaving the underlying records unclassified, ungoverned, and still physically present on a shared drive with existing permissions. This action does not alter the records' retention status, access controls, or audit trail, and it fails to address legal or regulatory discovery requirements. In practice, renaming can mask the records from compliance tools, increase confusion among authorized users, and inadvertently delay a defensible disposition, which is far worse than leaving the original name visible but properly managed.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.