SY0-701 Security Program Management and Oversight Practice Question
Exhibit
External audit request -------------------------------------------------- Request: Provide proof of quarterly privileged access reviews for FY2025. Evidence package received: 1. Signed access review spreadsheet with reviewer name, review date, and exceptions 2. SIEM export of administrator logins 3. Help desk ticket for a password reset 4. Screenshot of the access review policy
Based on the exhibit, which item is the strongest evidence that quarterly privileged access reviews occurred?
⚠ Common exam trap
The trap here is that candidates mistake evidence of activity (like login logs) or policy existence for evidence of a completed review process, overlooking the need for documented attestation with reviewer identity and date.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signed access review spreadsheet with reviewer, date, and exceptions.
A signed access review spreadsheet with reviewer, date, and exceptions provides direct, non-repudiable evidence that a formal review of privileged access was completed. Unlike logs or policies, it explicitly documents the reviewer's identity, the date of review, and any exceptions, satisfying audit requirements for quarterly privileged access reviews.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SIEM export of administrator logins.
Why it's wrong here
A SIEM export of administrator logins is evidence of authentication activity, not of a governance process. It may show that administrators signed in, but it does not show that anyone evaluated their entitlements, noted segregation-of-duties conflicts, or approved continued access. Moreover, raw logs are not a durable, reviewable artifact because they can be truncated, rotated, or lack the attestation of a reviewer.
- ✓
Signed access review spreadsheet with reviewer, date, and exceptions.
Why this is correct
A signed access review spreadsheet with the reviewer's name, the date, and listed exceptions is direct evidence that the quarterly privileged access review control was actually performed. It ties the review to a responsible individual, establishes a clear audit trail of when the review occurred, and documents that exceptions were identified and adjudicated. This is the strongest proof because it is a discrete, retained artifact that demonstrates both the process and its outcome.
- ✗
Help desk ticket for a password reset.
Why it's wrong here
A help desk ticket for a password reset is an operational event that simply indicates a user needed credentials reissued, often due to a forgotten password or suspected compromise. It has no nexus to the quarterly review of privileged access rights, and it does not demonstrate that any access decision was evaluated or recorded. Therefore, it is irrelevant as evidence that a periodic access review took place.
- ✗
Screenshot of the access review policy.
Why it's wrong here
A screenshot of the access review policy shows that a written policy requiring quarterly reviews exists, but it does not prove the policy was executed. It is evidence of control design, not control performance, and a screenshot can easily be edited or taken without actually performing the underlying process. Thus, it fails to demonstrate that specific reviewer, date, or exception data were ever generated.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Access review
An access review is a periodic audit process where administrators check and confirm which users have permissions to what resources, ensuring only authorized people retain access.
Key term
Privileged access
Privileged access is a special level of permission that allows a user or system to perform high-impact actions like installing software, changing system settings, or accessing sensitive data across an IT environment.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.