Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager is preparing a quarterly report for the board of directors on the effectiveness of the organization's security program. The manager has access to detailed technical data, including firewall log statistics, patch compliance percentages, and number of phishing simulation clicks. Which of the following would be the most appropriate way to present this information to the board?

⚠ Common exam trap

The trap here is that candidates mistake operational granularity (firewall changes, raw logs) for meaningful board-level metrics, failing to recognize that executives need summarized, trend-based data that ties security activities to business outcomes like risk reduction and efficiency.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Show a trend chart of the number of security incidents categorized by severity, along with average time to resolve.

It presents security program effectiveness in a business-relevant format: trend charts of incidents by severity and resolution times directly address risk reduction and operational efficiency, which board members need for strategic oversight. Unlike raw technical data, this aggregated, visualized information enables non-technical stakeholders to assess whether the security program is improving over time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Provide a list of all firewall rule changes made during the quarter.

    Why it's wrong here

    A quarterly log of every firewall rule change is a change-management audit trail, not a risk report. Thousands of additions, deletions, and modifications can be technically valid but still leave the network exposed if they are not mapped to threat scenarios or compliance requirements. Oversight requires aggregate measures such as percentage of rule changes reviewed within SLA, or before-and-after attack-surface exposure, rather than the raw configuration diff that a security engineer would consume.

    When this WOULD be correct

    A question asking for the best way to demonstrate compliance with change management procedures or to provide evidence of firewall policy enforcement during an audit would make this option correct.

  • Show a trend chart of the number of security incidents categorized by severity, along with average time to resolve.

    Why this is correct

    This option provides a high-level, actionable summary that demonstrates the security program's effectiveness. Incident trends by severity and resolution time are key performance indicators that the board can use to assess risk reduction and operational maturity.

  • Include raw logs of the top 10 most frequent alerts from the SIEM.

    Why it's wrong here

    Raw SIEM logs—packet payloads, source/destination IPs, and alert IDs—are forensic artifacts for Tier 2 analysts, not executive summaries. Board members cannot infer business risk from a noisy list of repeated detections, especially since the most frequent alerts are often false positives or low-severity policy violations. This presentation would obscure strategic indicators like incident count, severity distribution, and resolution time, which directly reflect the program's efficacy and risk posture.

  • Describe the technical architecture of the intrusion prevention system.

    Why it's wrong here

    Describing the technical architecture of an intrusion prevention system fails to address the board’s need for effectiveness metrics such as patch compliance percentages or phishing click rates; the board requires quantified risk-reduction data, not system design details. This option is tempting because explaining IPS architecture would be correct when presenting to a technical team evaluating deployment or tuning decisions, where architectural understanding directly informs operational configuration.

    When this WOULD be correct

    A question asking for the best way to present technical details to a new IT security team member who needs to understand the system's design and capabilities would make this option correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Show a trend chart of the number of security incidents categorized by severity, along with average time to resolve.Correct answer

Why this is correct

This option provides a high-level, actionable summary that demonstrates the security program's effectiveness. Incident trends by severity and resolution time are key performance indicators that the board can use to assess risk reduction and operational maturity.

Provide a list of all firewall rule changes made during the quarter.Wrong answer — click to see why

Why this is wrong here

The board of directors needs high-level, summarized information to assess security program effectiveness, not granular operational details like firewall rule changes.

★ When this WOULD be the correct answer

A question asking for the best way to demonstrate compliance with change management procedures or to provide evidence of firewall policy enforcement during an audit would make this option correct.

Why candidates choose this

Candidates may think that showing specific actions (rule changes) proves security activity, but they overlook the board's need for strategic, not operational, data.

Describe the technical architecture of the intrusion prevention system.Wrong answer — click to see why

Why this is wrong here

The board of directors needs high-level, summarized information to assess security program effectiveness, not detailed technical architecture. Describing the IPS architecture is too granular and does not convey performance or risk trends.

★ When this WOULD be the correct answer

A question asking for the best way to present technical details to a new IT security team member who needs to understand the system's design and capabilities would make this option correct.

Why candidates choose this

Candidates may think that explaining the IPS architecture demonstrates technical depth and security posture, but they overlook the audience's need for strategic, not technical, information.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.