SY0-701 General Security Concepts Practice Question
Exhibit
Data handling procedure: - Managers may approve external sharing exceptions verbally. - Staff record exceptions in email threads. - No retention period is defined for exception evidence. Audit note: multiple exceptions could not be traced to an approver.
Based on the exhibit, what is the best governance improvement?
Data handling procedure: - Managers may approve external sharing exceptions verbally. - Staff record exceptions in email threads. - No retention period is defined for exception evidence.
Audit note: multiple exceptions could not be traced to an approver.
⚠ Common exam trap
Test-takers frequently think training alone (Option D) can fix a procedural gap, but the SY0-701 exam emphasizes that governance improvements require enforceable controls, not just awareness, to ensure accountability and auditability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Replace verbal and email exceptions with a documented approval workflow and retained exception records.
The current procedure lacks a documented approval workflow and retention policy, which directly caused the audit finding that exceptions could not be traced to an approver. Implementing a formal, auditable process ensures non-repudiation and compliance with data handling governance, addressing the root cause rather than relying on informal verbal or email-based approvals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Replace verbal and email exceptions with a documented approval workflow and retained exception records.
Why this is correct
A documented approval workflow creates a verifiable audit trail for every exception, capturing who authorized it, why, and for how long. Retained records support regulatory inquiries, internal audits, and periodic reviews to ensure exceptions remain justified. This replaces fragile verbal or email agreements with enforceable accountability and reproducible evidence, making governance measurably stronger.
- ✗
Allow each team to decide its own exception format to increase flexibility.
Why it's wrong here
Delegating exception format choices to individual teams fragments the audit record, making inconsistencies across departments inevitable. Without centralized fields for approver, rationale, and expiration, compliance reviewers cannot reliably compare or aggregate exception risk. This approach improves convenience but sacrifices the standardized evidence that governance requires.
- ✗
Remove exception handling entirely so no external sharing can ever occur.
Why it's wrong here
Banning all external sharing may eliminate one vector of unauthorized data flow, but it fails to recognize legitimate business needs that require exceptions. Such a binary stance neither discourages shadow IT nor produces an audit trail; it simply pushes sharing outside oversight. Governance improvements must focus on controlling and documenting exceptions, not pretending they can be fully abolished.
- ✗
Keep the procedure unchanged and rely on additional awareness training alone.
Why it's wrong here
Awareness training can improve staff understanding of policy, but it does nothing to capture who approved an exception or when it expires. Reliance on memory and informal habits leaves the organization without durable evidence for audits or incident investigations. To strengthen governance, training must be paired with procedural controls that mandate documentation and approval sign-off.
Go deeper
Related to this question
Learn chapter
Non-Repudiation and Digital Signatures
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.