Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Corporate privacy notice excerpt:
- Employee home addresses, personal phone numbers, and emergency contacts are collected for payroll, benefits, tax reporting, and emergency notification only.
- Access is limited to HR and Payroll unless a privacy review approves another purpose.

Ticket:
- Facilities manager requests an export of all employee home addresses and personal phone numbers to mail holiday gifts and parking passes.

Based on the exhibit, what is the best response to the facilities manager's request?

⚠ Common exam trap

Candidates often assume a manager's role and business relationship automatically grant data access, overlooking the need for formal privacy review and approved data handling procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deny the request and direct the manager to use an approved work-contact list or seek privacy review.

The facilities manager's request to export employee contact information for a separate system likely violates data privacy policies and potentially regulations like GDPR or CCPA. Option B is correct because the proper procedure is to deny the ad-hoc export and direct the manager to use an approved work-contact list or seek a privacy review, ensuring data handling complies with organizational data governance and privacy requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Provide the export because the requester is a manager with a legitimate business relationship to employees.

    Why it's wrong here

    Manager status alone does not confer an entitlement to export PII under role-based access control; the privacy notice explicitly limits home addresses and personal phone numbers to HR and payroll processing. A legitimate business relationship only establishes a reason to communicate, not a lawful basis to access sensitive personal data outside the stated purpose. The correct action is to deny the unreserved export and steer the requester toward the approved work-contact list or an official privacy review.

  • Deny the request and direct the manager to use an approved work-contact list or seek privacy review.

    Why this is correct

    The privacy notice clearly limits home addresses and personal phone numbers to defined HR and payroll purposes. The facilities request exceeds that purpose, so the correct action is to deny the export unless a formal privacy review approves another use. Where possible, use a work-contact list that contains less sensitive information.

  • Send the data to the manager if the manager promises not to share it externally.

    Why it's wrong here

    A verbal promise not to share externally is not an enforceable data governance control and leaves no audit trail; the manager’s informal assurance does not constitute the required legal basis under data-processing policy. The purpose limitation in the exhibit still applies, so the export would be a prohibited secondary use regardless of confidentiality assurances. Approved mechanisms such as a signed internal data-usage agreement or a formal privacy review are the only acceptable paths to access this protected data.

  • Store the export in a shared drive so multiple teams can use it for convenience.

    Why it's wrong here

    Persisting the export to a shared drive would expand access beyond the individuals with a need-to-know and violate the least-privilege principle, as shared drives often have broad team-wide ACLs and lack role-based scoping. Data minimization requires that personal data be accessible only to specifically authorized personnel, not to any team that finds it convenient. Additionally, storing records outside the authoritative HR/payroll system undermines the organization’s ability to enforce retention, consent, and breach-notification obligations.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.