SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Data extract request: - Fields in spreadsheet: employee name, home address, email, bank routing number, bank account number, government ID number, benefits selections - Requester: Third-party benefits administrator - Business purpose: Test import mapping; only name, email, and benefits selections are required - Policy note: Government IDs and bank data must not leave HR systems unless explicitly approved
Based on the exhibit, what is the best data-handling action before sharing the file with the third party?
⚠ Common exam trap
CompTIA often tests the misconception that a signed NDA or encryption alone is sufficient to share all data, when in fact data minimization and formal approval are required to meet security and compliance standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Redact the unnecessary sensitive fields and provide only the minimum necessary extract after approval.
Data minimization and the principle of least privilege require that only the minimum necessary sensitive data be shared with a third party. Redacting unnecessary sensitive fields and obtaining approval ensures compliance with data protection policies and reduces the risk of unauthorized exposure, even if the recipient has signed an NDA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send the full spreadsheet encrypted and let the vendor filter out the extra columns.
Why it's wrong here
Encryption protects the spreadsheet in transit and at rest, but it does not satisfy data minimization: the vendor still receives bank account and government-ID fields it does not need for benefits verification. Allowing the vendor to filter after transfer means the sensitive data has already been exposed to a third-party environment, expanding the potential attack surface. The policy note requires removing unnecessary sensitive fields before sharing, not after the recipient takes possession.
- ✓
Redact the unnecessary sensitive fields and provide only the minimum necessary extract after approval.
Why this is correct
This follows data minimization and handling requirements. The third party only needs names, email addresses, and benefits selections, so bank and government-ID fields should be removed before sharing. Encryption alone is not enough because the recipient would still receive more data than needed. This approach reduces privacy exposure and aligns with the policy note in the exhibit.
- ✗
Mark the spreadsheet as internal and share it through the benefits contractor's cloud portal.
Why it's wrong here
Marking the spreadsheet as 'internal' is only a classification label and does not remove or protect the sensitive fields within it; the file still contains bank and government-ID data. Uploading it to the contractor's cloud portal moves the data outside the organization's direct security controls, and the portal's access controls or retention policies may not align with the company's data-handling rules. This approach increases exposure risk rather than reducing it, because redaction and approval should happen before any third-party transfer.
- ✗
Send the file unchanged because the contractor signed a nondisclosure agreement.
Why it's wrong here
A signed nondisclosure agreement is a legal control, not a technical safeguard; it cannot prevent exposure if the file is lost, stolen, or accidentally shared, and it does not change the fact that the vendor only needs names, email addresses, and benefits selections. Sending the unchanged file violates the minimum-necessary principle and the policy note that says avoid sharing sensitive fields unless explicitly required. The NDA also does not justify the additional risks of transmitting bank and government-ID data that serve no business purpose in this benefit enrollment task.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
NDA
A legally binding contract that restricts the sharing of confidential information with unauthorized parties.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.