Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

An external auditor asks for proof that quarterly privileged access reviews were completed and that any exceptions were tracked to closure during the last year. Which evidence is MOST appropriate to provide?

⚠ Common exam trap

Many candidates confuse policy documentation (Option C) or informal communication (Option D) with actual audit evidence, failing to recognize that only signed records and remediation tickets provide the verifiable, objective proof required by an external auditor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Signed access review records and remediation tickets from the access management process.

Signed access review records provide verifiable proof that quarterly reviews were conducted, and remediation tickets demonstrate that any exceptions (e.g., excessive privileges) were tracked and resolved. This aligns with the principle of audit evidence: it must be objective, verifiable, and show a complete chain of actions from review to closure. A screenshot or policy alone lacks the audit trail of actual completion and exception handling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A screenshot of one administrator's account showing current privileges.

    Why it's wrong here

    A screenshot of a single administrator's account provides only a point-in-time view, with no verifiable timestamp or audit trail that the image corresponds to a particular quarter. The capture can be staged or taken after the fact, and it says nothing about who reviewed the account, what variances were found, or how they were resolved. Auditors require evidence that demonstrates a repeatable quarterly process was executed across the entire population of privileged accounts, not just one account's current state.

  • Signed access review records and remediation tickets from the access management process.

    Why this is correct

    This is the best evidence because it directly shows the process was performed and that findings were handled. Signed review records demonstrate that quarterly reviews occurred, and remediation or exception tickets show that identified issues were tracked and resolved. Auditors look for traceable, repeatable evidence rather than isolated screenshots or verbal confirmation, so process records are the strongest support.

  • The security policy that says access reviews must happen every quarter.

    Why it's wrong here

    A security policy is a statement of intent; it establishes the requirement for quarterly reviews but offers zero proof that reviews actually occurred. Auditors look for execution evidence such as signed checklists, meeting minutes, or workflow entries that show which privileged accounts were examined, by whom, and when. Without those artifacts, the policy could be aspirational or unenforced. In audit terms, a policy is a control design document, not a control operating record.

  • An email from the system administrator stating that reviews were completed on time.

    Why it's wrong here

    An email from an administrator is hearsay in the audit context: it is an unauthenticated, self-reported claim with no independent verification. The message lacks the integrity protections of a formal access management workflow, such as electronic signatures, unique review instance IDs, or linked remediation tickets that demonstrate follow-through. Auditors must rely on forensic, traceable evidence, and a plain email can be fabricated or misinterpreted; it does not prove that reviews were on time or that identified access risks were actually closed.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.