Courseiva
Security Program Management and OversighthardMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Data extract request:
- Fields in spreadsheet: employee name, home address, email, bank routing number, bank account number, government ID number, benefits selections
- Requester: Third-party benefits administrator
- Business purpose: Test import mapping; only name, email, and benefits selections are required
- Policy note: Government IDs and bank data must not leave HR systems unless explicitly approved

Based on the exhibit, what is the best data-handling action before sharing the file with the third party?

⚠ Common exam trap

CompTIA often tests the misconception that a signed NDA or encryption alone is sufficient to share all data, when in fact data minimization and formal approval are required to meet security and compliance standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Redact the unnecessary sensitive fields and provide only the minimum necessary extract after approval.

Data minimization and the principle of least privilege require that only the minimum necessary sensitive data be shared with a third party. Redacting unnecessary sensitive fields and obtaining approval ensures compliance with data protection policies and reduces the risk of unauthorized exposure, even if the recipient has signed an NDA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Send the full spreadsheet encrypted and let the vendor filter out the extra columns.

    Why it's wrong here

    Encryption protects the spreadsheet in transit and at rest, but it does not satisfy data minimization: the vendor still receives bank account and government-ID fields it does not need for benefits verification. Allowing the vendor to filter after transfer means the sensitive data has already been exposed to a third-party environment, expanding the potential attack surface. The policy note requires removing unnecessary sensitive fields before sharing, not after the recipient takes possession.

  • Redact the unnecessary sensitive fields and provide only the minimum necessary extract after approval.

    Why this is correct

    This follows data minimization and handling requirements. The third party only needs names, email addresses, and benefits selections, so bank and government-ID fields should be removed before sharing. Encryption alone is not enough because the recipient would still receive more data than needed. This approach reduces privacy exposure and aligns with the policy note in the exhibit.

  • Mark the spreadsheet as internal and share it through the benefits contractor's cloud portal.

    Why it's wrong here

    Marking the spreadsheet as 'internal' is only a classification label and does not remove or protect the sensitive fields within it; the file still contains bank and government-ID data. Uploading it to the contractor's cloud portal moves the data outside the organization's direct security controls, and the portal's access controls or retention policies may not align with the company's data-handling rules. This approach increases exposure risk rather than reducing it, because redaction and approval should happen before any third-party transfer.

  • Send the file unchanged because the contractor signed a nondisclosure agreement.

    Why it's wrong here

    A signed nondisclosure agreement is a legal control, not a technical safeguard; it cannot prevent exposure if the file is lost, stolen, or accidentally shared, and it does not change the fact that the vendor only needs names, email addresses, and benefits selections. Sending the unchanged file violates the minimum-necessary principle and the policy note that says avoid sharing sensitive fields unless explicitly required. The NDA also does not justify the additional risks of transmitting bank and government-ID data that serve no business purpose in this benefit enrollment task.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.