Courseiva
Security Program Management and OversightmediumMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager is designing a security program to align with business goals. Which three of the following are essential components of a security program that directly support governance and oversight? (Choose three.)

⚠ Common exam trap

Watch out — candidates often confuse operational security tools (like vulnerability scanners and firewalls) with governance components, which are about oversight, policy, and strategic alignment rather than specific technical implementations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Establishing a security steering committee with executive sponsorship

A security steering committee with executive sponsorship ensures that security initiatives have top-down support and alignment with business objectives, which is a core governance function. Developing and maintaining security policies, standards, and procedures provides the formal framework for enforcing security controls and ensuring compliance, directly supporting oversight. Conducting periodic risk assessments informs decision-making by identifying and prioritizing risks, which is essential for governance and resource allocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Establishing a security steering committee with executive sponsorship

    Why this is correct

    Establishing a security steering committee with executive sponsorship aligns the security program with business strategy by placing decision-making in a body that has authority over resources and risk appetite. This governance structure ensures that security initiatives are prioritized based on organizational objectives, legal/regulatory obligations, and stakeholder expectations. It also provides a mechanism to resolve conflicts and allocate budgets, making it a foundational element of alignment.

  • Implementing a vulnerability scanning tool across all endpoints

    Why it's wrong here

    Implementing a vulnerability scanning tool across all endpoints is a tactical control that identifies system-level weaknesses such as missing patches or misconfigurations. While valuable for technical hygiene, it does not, by itself, translate business goals into security priorities or establish governance over resource allocation. This tool is just one component of a comprehensive program, and deploying it does not ensure that the program is aligned with the business's strategic objectives.

  • Developing and maintaining security policies, standards, and procedures

    Why this is correct

    Developing and maintaining security policies, standards, and procedures codifies the organization's security requirements and acceptable behaviors, turning business objectives and compliance mandates into enforceable rules. Policies are high-level directives; standards provide specific technical baselines; procedures give step-by-step actions. Together they form the governance framework that ensures every part of the business operates with the same security expectations, which is essential for aligning daily operations with strategic goals.

  • Conducting periodic risk assessments to inform decision-making

    Why this is correct

    Conducting periodic risk assessments to inform decision-making is a core function of a security program that ties security measures directly to the value and impact of business assets. These assessments evaluate threats, vulnerabilities, and the likelihood/impact of incidents, enabling management to prioritize mitigation investments based on risk tolerance and business objectives. This continuous feedback loop allows the program to adapt to changing operations and threats, ensuring that security efforts remain relevant and cost-effective.

  • Deploying a next-generation firewall to segment the network

    Why it's wrong here

    Deploying a next-generation firewall to segment the network is a specific technical control that restricts traffic flows between zones and provides features like intrusion prevention and identity-based policies. Although useful for defense-in-depth, this appliance or platform is an execution-level tool, not a program-governance mechanism. It cannot, on its own, ensure strategic alignment with business goals, because such alignment requires policy, executive direction, and risk-based resource planning.

  • Installing endpoint detection and response agents on all workstations

    Why it's wrong here

    Installing endpoint detection and response agents on all workstations provides continuous monitoring, threat detection, and response capabilities at the host level. This is an operational control that improves incident visibility and response times, but it does not address the underlying governance question of whether security objectives match business plans. It is an important tool, but the design of a security program must start with leadership, policies, and risk assessments, not with a specific technology.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.