SY0-701 Security Program Management and Oversight Practice Question
A security manager at a financial services company is proposing a new policy that would require annual background checks for all employees with access to sensitive customer payment data. The proposed policy, if implemented, would increase the organization's operational costs by approximately $200,000 per year. The manager needs to obtain formal approval to implement this policy. Which of the following groups is MOST likely to have the authority to approve this policy and allocate the necessary budget?
⚠ Common exam trap
Many exam-takers confuse operational authority (CISO) with financial governance authority (board), assuming the CISO can approve any security-related budget without recognizing that large, recurring costs require board-level approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Board of directors
The board of directors holds the ultimate fiduciary responsibility and authority over significant financial commitments and strategic policy changes. A $200,000 annual cost increase requires approval at the highest governance level, as it impacts the organization's budget and risk posture. The board is the only group with the formal power to allocate such a substantial operational expense and approve a new policy affecting all employees with access to sensitive payment data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Board of directors
Why this is correct
The board of directors has the fiduciary responsibility and ultimate authority to approve significant policy changes that require a substantial budget allocation, such as a $200,000 annual expense for background checks. This is correct because the policy crosses functional areas (security, HR, finance) and requires formal governance approval.
- ✗
Chief Information Security Officer (CISO)
Why it's wrong here
While the CISO is the senior security leader and may champion the policy, the CISO typically does not have the sole authority to approve a multi-departmental policy that costs $200,000 and involves HR processes. The CISO would recommend the policy to higher governance bodies such as the board or executive committee.
When this WOULD be correct
A question asks who is responsible for approving a new security policy that does not require additional budget or significant organizational change, such as updating an existing access control procedure within the security department's authority.
- ✗
IT steering committee
Why it's wrong here
An IT steering committee usually prioritizes technology projects and IT investments, but this policy is an HR/security policy that affects all employees, not just IT. The committee lacks the authority to approve enterprise-wide human resources policies and budget increases of this magnitude.
When this WOULD be correct
An IT steering committee would be the correct approving body for a policy that involves changes to IT project priorities or resource allocation within an existing approved budget, such as approving a new security tool implementation that fits within the current fiscal year's IT budget.
- ✗
Security operations team
Why it's wrong here
The security operations team (SOC) is a tactical execution layer responsible for continuous monitoring, triage, alert investigation, and incident response. Approving a multi-departmental policy with a $200,000 annual budget requires fiduciary authority and governance oversight, which the SOC does not possess. The SOC would only implement the background-check procedures after the policy is formally approved by a body with budget and compliance authority, such as the board of directors.
When this WOULD be correct
In a scenario where a security operations team is asked to approve a minor procedural change that does not require additional budget, such as updating a standard operating procedure for incident response, the team would have the authority to approve it.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Board of directorsCorrect answer▾
Why this is correct
The board of directors has the fiduciary responsibility and ultimate authority to approve significant policy changes that require a substantial budget allocation, such as a $200,000 annual expense for background checks. This is correct because the policy crosses functional areas (security, HR, finance) and requires formal governance approval.
✗Chief Information Security Officer (CISO)Wrong answer — click to see why▾
Why this is wrong here
The CISO typically manages security strategy and operations but lacks authority to approve a $200,000 budget increase for a new policy; such financial decisions require higher-level approval like the board of directors.
★ When this WOULD be the correct answer
A question asks who is responsible for approving a new security policy that does not require additional budget or significant organizational change, such as updating an existing access control procedure within the security department's authority.
Why candidates choose this
Candidates may assume the CISO has full authority over security policies and budgets, overlooking that significant financial commitments require approval from higher governance bodies like the board.
✗IT steering committeeWrong answer — click to see why▾
Why this is wrong here
The IT steering committee typically oversees IT project prioritization and resource allocation, but it lacks the authority to approve a new policy requiring a $200,000 annual budget increase; such financial decisions are reserved for the board of directors.
★ When this WOULD be the correct answer
An IT steering committee would be the correct approving body for a policy that involves changes to IT project priorities or resource allocation within an existing approved budget, such as approving a new security tool implementation that fits within the current fiscal year's IT budget.
Why candidates choose this
Candidates may think the IT steering committee has broad authority over IT-related policies and budgets, overlooking that significant financial commitments require higher-level approval from the board of directors.
✗Security operations teamWrong answer — click to see why▾
Why this is wrong here
The security operations team is an operational group responsible for day-to-day security tasks, not for approving policies or allocating budgets of this magnitude. They lack the authority to approve a $200,000 annual expense.
★ When this WOULD be the correct answer
In a scenario where a security operations team is asked to approve a minor procedural change that does not require additional budget, such as updating a standard operating procedure for incident response, the team would have the authority to approve it.
Why candidates choose this
Candidates may mistakenly believe that the security operations team, being directly involved with security, has the authority to approve security-related policies, overlooking the financial and strategic implications that require higher-level approval.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.