SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Data request: File: customer_export.csv Contents: full name, street address, SSN last 4, account balance, support notes Requestor: external troubleshooting contractor Policy excerpt: - Internal: company staff only - Confidential: encrypt in transit, approved recipients only - Restricted: minimize, mask where possible, owner approval required, time-limited access, logged sharing - Public: may be shared externally without restriction
Based on the exhibit, what is the best handling decision for the requested file?
⚠ Common exam trap
It's easy for candidates to assume that sharing only the last four digits of an SSN makes the data safe to send via email (Option A), but CompTIA tests that any PII, even partial, requires Restricted handling and encrypted transfer to prevent data breaches and comply with regulations like GDPR or HIPAA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Treat it as Restricted, redact unnecessary fields, and provide only the minimum approved dataset through a logged encrypted transfer.
The file contains personally identifiable information (PII) in the form of a Social Security Number (SSN), which requires handling under a Restricted classification per most data governance frameworks. The correct procedure is to redact unnecessary fields, such as the full SSN, and transmit only the minimum approved dataset via a logged encrypted transfer (e.g., using SFTP or HTTPS with TLS 1.2+) to ensure confidentiality, integrity, and auditability. This aligns with the principle of least privilege and data minimization, which are core to security program management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share the full file by email as Confidential because only the last four digits of the SSN are included.
Why it's wrong here
The presence of only the last four digits of a Social Security number does not remove the data from the PII category—such fragments are still subject to privacy regulations like GLBA or GDPR and can enable identity verification or record linking. The email channel is also problematic: standard email is not an approved encrypted transfer method, and it lacks the logging and user authentication required for Restricted data. Finally, the file includes full addresses, account balances, and case-specific support notes, which clearly exceed the minimum necessary for troubleshooting, so labeling the entire attachment as Confidential is both a classification and a minimization failure.
- ✗
Label it Public because the contractor needs the information to troubleshoot effectively.
Why it's wrong here
Labeling the file Public is a fundamental classification error because Public means no access restrictions, which would make customers' PII and financial details accessible to anyone, including outside the organization. The contractor's legitimate need to troubleshoot does not change the inherent sensitivity of the data; classification is based on the data's value and regulatory requirements, not on the requester's convenience. In fact, the correct response to a contractor's need is to apply least privilege—provide only the minimal fields required, under an NDA/BAA where appropriate, and through a controlled channel—not to elevate the data to a level with no controls.
- ✗
Mark it Internal and place it on the shared project drive for easy access.
Why it's wrong here
An Internal classification is far too broad for customer records containing PII, financial information, and case notes; per the policy, such data belongs in the Restricted tier, which requires explicit owner approval, encryption, and access logging. Placing the file on a shared project drive would expose it to any user with access to that space, many of whom have no legitimate need, and typical shared drives lack the per-file audit trails and automatic expiry needed for sensitive data. This approach also bypasses the mandatory steps of redaction, minimization, and time-limited access, so it would violate both the letter and the spirit of the data handling policy.
- ✓
Treat it as Restricted, redact unnecessary fields, and provide only the minimum approved dataset through a logged encrypted transfer.
Why this is correct
The file contains customer PII, financial information, and case notes, so it should be handled as Restricted rather than merely Confidential. The policy requires minimization, masking where possible, owner approval, time-limited access, and logged sharing. Because the request comes from an external contractor, the organization should provide only the least amount of data needed, with encryption and formal approval.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.