Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Data sharing request:
Recipient: Outside analytics vendor
Requested file: Monthly absenteeism report
Fields requested: employee name, home address, phone number, badge ID, medical leave code, department
Purpose stated by requester: Trend analysis for staffing patterns

Internal note: The vendor only needs department-level trends for the project.

Based on the exhibit, what should the security team recommend before sharing the report?

⚠ Common exam trap

CompTIA often tests the misconception that a signed NDA or encryption alone is sufficient to share sensitive data, when in fact data minimization and least privilege are the primary security controls required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Remove unnecessary personal fields and share only the minimum data needed for the analysis.

The principle of data minimization requires that only the minimum necessary data be shared to fulfill the analysis purpose. Removing unnecessary personal fields reduces the risk of exposing PII and aligns with privacy regulations such as GDPR and HIPAA, even when a nondisclosure agreement (NDA) is in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Share the report exactly as requested, because the vendor signed a nondisclosure agreement.

    Why it's wrong here

    An NDA creates a contractual duty of confidentiality, but it does not change the legal obligation to limit personal data to what is relevant and necessary for the stated purpose. When a vendor signs an NDA, they still receive the full dataset, including sensitive fields such as home addresses and medical leave codes, which are unnecessary for department-level trend analysis. Privacy regulations and data-protection principles are independent of a vendor's contractual promises.

  • Remove unnecessary personal fields and share only the minimum data needed for the analysis.

    Why this is correct

    This is the correct privacy-by-design response because the vendor only needs department-level trends. The organization should minimize the data shared, especially sensitive or unnecessary fields like home addresses and medical leave codes. Limiting the dataset reduces privacy risk, supports compliance, and follows the principle of collecting and disclosing only what is needed for the stated business purpose.

  • Keep all fields and encrypt the file before sending it to the vendor.

    Why it's wrong here

    Encrypting the file protects it in transit and at rest, reducing the risk of unauthorized interception, but it is a security control rather than a privacy control. The encrypted dataset still contains the same sensitive personal data, so once the vendor legitimately decrypts it for analysis, every unnecessary field is exposed within the vendor's environment. Encryption does not satisfy data minimization or purpose limitation, and it may create a false sense of compliance if the file is later subpoenaed or compromised.

  • Store the report in a shared folder so the vendor can access it later if needed.

    Why it's wrong here

    Placing the report in a shared folder extends access beyond the immediate analysis task and gives the vendor a persistent, potentially uncontrolled path to the data. Shared-folder permissions are often broader than needed, may lack MFA, file-level audit logging, or expiration policies, and can be exploited through credential theft or lateral movement. This approach also fails to remove unnecessary personal fields, so it amplifies both the privacy and security risk rather than reducing the exposed dataset.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.