Question 147 of 1,013
SY0-701 Security Program Management and Oversight Practice Question
An HR analyst must share a spreadsheet with an external auditor. The spreadsheet includes employee names, Social Security numbers, bank account numbers, and salary data, but the auditor only needs employee names and total payroll. Which three actions best protect the data? Select three.
⚠ Common exam trap
It's easy for candidates to think leaving the full spreadsheet intact is acceptable because the auditor 'requested a copy,' but CompTIA tests the principle of least privilege and data minimization, meaning you must always remove unnecessary sensitive data before sharing with external parties.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove fields the auditor does not need before sharing the file.
Removing unnecessary fields (e.g., Social Security numbers, bank account numbers) before sharing the spreadsheet minimizes the exposure of sensitive personally identifiable information (PII) and financial data. This practice, known as data minimization, aligns with the principle of least privilege and reduces the risk of unauthorized access or data breach. By stripping out extraneous columns, the HR analyst ensures the auditor receives only the required data (employee names and total payroll), thereby protecting the organization from compliance violations under regulations like GDPR or PCI DSS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Remove fields the auditor does not need before sharing the file.
Why this is correct
Applying data minimization means stripping the spreadsheet to only the audit-relevant fields (e.g., payroll totals) and eliminating personally identifiable information (PII) such as Social Security numbers, birth dates, or home addresses. This limits the potential impact of a data breach and aligns with privacy frameworks like GDPR and HIPAA, which require that only necessary data be processed. By reducing the dataset before transfer, the HR analyst also shortens the retention exposure window and makes the file less attractive to attackers.
- ✓
Send the file using an encrypted transfer method.
Why this is correct
Using an encrypted transfer method (e.g., SFTP, HTTPS, or a TLS-secured file transfer portal) ensures the spreadsheet's contents are unreadable to anyone who intercepts the network traffic during transmission. Without encryption, payroll data could be captured via packet sniffing on unsecured networks or through man-in-the-middle attacks. Encryption protects the data in transit, complementing the other controls that protect the data at rest.
- ✓
Share the file only with the named auditor account or approved firm contact.
Why this is correct
Sharing the file exclusively with the auditor's verified account (or a pre-approved firm email address) enforces need-to-know access control, ensuring the spreadsheet is not exposed to unauthorized personnel. This requires authentication to confirm the recipient's identity and may involve just-in-time permissions or expiring links, which reduce the risk of the file being forwarded or accessed later. Explicit recipient verification also mitigates social engineering attacks where files are sent to look-alike domains or incorrect recipients.
- ✗
Leave the full spreadsheet intact because the auditor requested a copy.
Why it's wrong here
Fulfilling the auditor's request with the full spreadsheet needlessly exposes sensitive HR fields that are irrelevant to the audit, violating the principle of least privilege. Even a trusted external auditor does not justify releasing all data, because excessive sharing increases both the exploitation surface and the compliance penalty if the file is misused. The auditor's request alone does not create a business need for data they will not review; the file should be filtered to the specific records and columns required.
- ✗
Post the spreadsheet in a shared public portal for easier access.
Why it's wrong here
Uploading the spreadsheet to a shared public portal removes all access control and leaves the sensitive data publicly searchable and downloadable by anyone, with no encryption or audit trail. This direct violation of confidentiality and data protection requirements would likely trigger mandatory breach notification laws and result in severe reputational damage. Even if the portal is intended for internal use, 'public' access means there is no enforcement of authentication or need-to-know, so the data is effectively beyond the organization's control.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.