Courseiva
General Security ConceptshardMultiple ChoiceObjective-mapped

SY0-701 General Security Concepts Practice Question

Exhibit

Data handling procedure:
- Managers may approve external sharing exceptions verbally.
- Staff record exceptions in email threads.
- No retention period is defined for exception evidence.

Audit note: multiple exceptions could not be traced to an approver.

Based on the exhibit, what is the best governance improvement?

Data handling procedure: - Managers may approve external sharing exceptions verbally. - Staff record exceptions in email threads. - No retention period is defined for exception evidence.

Audit note: multiple exceptions could not be traced to an approver.

⚠ Common exam trap

Test-takers frequently think training alone (Option D) can fix a procedural gap, but the SY0-701 exam emphasizes that governance improvements require enforceable controls, not just awareness, to ensure accountability and auditability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Replace verbal and email exceptions with a documented approval workflow and retained exception records.

The current procedure lacks a documented approval workflow and retention policy, which directly caused the audit finding that exceptions could not be traced to an approver. Implementing a formal, auditable process ensures non-repudiation and compliance with data handling governance, addressing the root cause rather than relying on informal verbal or email-based approvals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Replace verbal and email exceptions with a documented approval workflow and retained exception records.

    Why this is correct

    A documented approval workflow creates a verifiable audit trail for every exception, capturing who authorized it, why, and for how long. Retained records support regulatory inquiries, internal audits, and periodic reviews to ensure exceptions remain justified. This replaces fragile verbal or email agreements with enforceable accountability and reproducible evidence, making governance measurably stronger.

  • Allow each team to decide its own exception format to increase flexibility.

    Why it's wrong here

    Delegating exception format choices to individual teams fragments the audit record, making inconsistencies across departments inevitable. Without centralized fields for approver, rationale, and expiration, compliance reviewers cannot reliably compare or aggregate exception risk. This approach improves convenience but sacrifices the standardized evidence that governance requires.

  • Remove exception handling entirely so no external sharing can ever occur.

    Why it's wrong here

    Banning all external sharing may eliminate one vector of unauthorized data flow, but it fails to recognize legitimate business needs that require exceptions. Such a binary stance neither discourages shadow IT nor produces an audit trail; it simply pushes sharing outside oversight. Governance improvements must focus on controlling and documenting exceptions, not pretending they can be fully abolished.

  • Keep the procedure unchanged and rely on additional awareness training alone.

    Why it's wrong here

    Awareness training can improve staff understanding of policy, but it does nothing to capture who approved an exception or when it expires. Reliance on memory and informal habits leaves the organization without durable evidence for audits or incident investigations. To strengthen governance, training must be paired with procedural controls that mandate documentation and approval sign-off.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.