Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

External audit request
--------------------------------------------------
Request: Provide proof of quarterly privileged access reviews for FY2025.
Evidence package received:
1. Signed access review spreadsheet with reviewer name, review date, and exceptions
2. SIEM export of administrator logins
3. Help desk ticket for a password reset
4. Screenshot of the access review policy

Based on the exhibit, which item is the strongest evidence that quarterly privileged access reviews occurred?

⚠ Common exam trap

The trap here is that candidates mistake evidence of activity (like login logs) or policy existence for evidence of a completed review process, overlooking the need for documented attestation with reviewer identity and date.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Signed access review spreadsheet with reviewer, date, and exceptions.

A signed access review spreadsheet with reviewer, date, and exceptions provides direct, non-repudiable evidence that a formal review of privileged access was completed. Unlike logs or policies, it explicitly documents the reviewer's identity, the date of review, and any exceptions, satisfying audit requirements for quarterly privileged access reviews.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SIEM export of administrator logins.

    Why it's wrong here

    A SIEM export of administrator logins is evidence of authentication activity, not of a governance process. It may show that administrators signed in, but it does not show that anyone evaluated their entitlements, noted segregation-of-duties conflicts, or approved continued access. Moreover, raw logs are not a durable, reviewable artifact because they can be truncated, rotated, or lack the attestation of a reviewer.

  • Signed access review spreadsheet with reviewer, date, and exceptions.

    Why this is correct

    A signed access review spreadsheet with the reviewer's name, the date, and listed exceptions is direct evidence that the quarterly privileged access review control was actually performed. It ties the review to a responsible individual, establishes a clear audit trail of when the review occurred, and documents that exceptions were identified and adjudicated. This is the strongest proof because it is a discrete, retained artifact that demonstrates both the process and its outcome.

  • Help desk ticket for a password reset.

    Why it's wrong here

    A help desk ticket for a password reset is an operational event that simply indicates a user needed credentials reissued, often due to a forgotten password or suspected compromise. It has no nexus to the quarterly review of privileged access rights, and it does not demonstrate that any access decision was evaluated or recorded. Therefore, it is irrelevant as evidence that a periodic access review took place.

  • Screenshot of the access review policy.

    Why it's wrong here

    A screenshot of the access review policy shows that a written policy requiring quarterly reviews exists, but it does not prove the policy was executed. It is evidence of control design, not control performance, and a screenshot can easily be edited or taken without actually performing the underlying process. Thus, it fails to demonstrate that specific reviewer, date, or exception data were ever generated.

Go deeper

Related to this question

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.