SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Data sharing request: Recipient: Outside analytics vendor Requested file: Monthly absenteeism report Fields requested: employee name, home address, phone number, badge ID, medical leave code, department Purpose stated by requester: Trend analysis for staffing patterns Internal note: The vendor only needs department-level trends for the project.
Based on the exhibit, what should the security team recommend before sharing the report?
⚠ Common exam trap
CompTIA often tests the misconception that a signed NDA or encryption alone is sufficient to share sensitive data, when in fact data minimization and least privilege are the primary security controls required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove unnecessary personal fields and share only the minimum data needed for the analysis.
The principle of data minimization requires that only the minimum necessary data be shared to fulfill the analysis purpose. Removing unnecessary personal fields reduces the risk of exposing PII and aligns with privacy regulations such as GDPR and HIPAA, even when a nondisclosure agreement (NDA) is in place.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share the report exactly as requested, because the vendor signed a nondisclosure agreement.
Why it's wrong here
An NDA creates a contractual duty of confidentiality, but it does not change the legal obligation to limit personal data to what is relevant and necessary for the stated purpose. When a vendor signs an NDA, they still receive the full dataset, including sensitive fields such as home addresses and medical leave codes, which are unnecessary for department-level trend analysis. Privacy regulations and data-protection principles are independent of a vendor's contractual promises.
- ✓
Remove unnecessary personal fields and share only the minimum data needed for the analysis.
Why this is correct
This is the correct privacy-by-design response because the vendor only needs department-level trends. The organization should minimize the data shared, especially sensitive or unnecessary fields like home addresses and medical leave codes. Limiting the dataset reduces privacy risk, supports compliance, and follows the principle of collecting and disclosing only what is needed for the stated business purpose.
- ✗
Keep all fields and encrypt the file before sending it to the vendor.
Why it's wrong here
Encrypting the file protects it in transit and at rest, reducing the risk of unauthorized interception, but it is a security control rather than a privacy control. The encrypted dataset still contains the same sensitive personal data, so once the vendor legitimately decrypts it for analysis, every unnecessary field is exposed within the vendor's environment. Encryption does not satisfy data minimization or purpose limitation, and it may create a false sense of compliance if the file is later subpoenaed or compromised.
- ✗
Store the report in a shared folder so the vendor can access it later if needed.
Why it's wrong here
Placing the report in a shared folder extends access beyond the immediate analysis task and gives the vendor a persistent, potentially uncontrolled path to the data. Shared-folder permissions are often broader than needed, may lack MFA, file-level audit logging, or expiration policies, and can be exploited through credential theft or lateral movement. This approach also fails to remove unnecessary personal fields, so it amplifies both the privacy and security risk rather than reducing the exposed dataset.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.