SY0-701 Security Program Management and Oversight Practice Question
HR needs to share a copy of employee records with a benefits contractor for testing. The contractor only needs names and coverage selections, not Social Security numbers or bank details. Which two actions best satisfy data handling requirements? Select two.
⚠ Common exam trap
Many candidates assume trust (option B) or convenience (option D or E) justifies sharing full data, but the exam emphasizes that data handling requirements always mandate minimizing exposure and enforcing access controls regardless of trust level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Redact or mask unnecessary sensitive fields before sharing the file.
Redacting or masking sensitive fields like Social Security numbers and bank details ensures that the contractor receives only the necessary data (names and coverage selections) while protecting personally identifiable information (PII). This aligns with the principle of data minimization and compliance with regulations such as GDPR or HIPAA, which require that only the minimum necessary data be shared for a specific purpose. Masking techniques, such as replacing SSNs with placeholders or applying irreversible hashing, prevent unauthorized exposure even if the file is intercepted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Redact or mask unnecessary sensitive fields before sharing the file.
Why this is correct
Redaction or masking is a foundational data-minimization control that replaces or removes sensitive fields such as SSNs, bank details, and medical information before any external sharing. This reduces the potential impact of unauthorized disclosure because even if the file is leaked, the exposed data is not sensitive. It also aligns with privacy regulations like GDPR and HIPAA, which require using the minimum necessary data for a given purpose.
- ✗
Send the full employee record set because the contractor is trusted.
Why it's wrong here
Trusting a third party does not eliminate privacy obligations or the risk of compromise. A trusted contractor may still misconfigure storage, fall victim to phishing, or have an insider threat—all of which can expose personally identifiable information (PII). Sending entire records violates the principle of least privilege and data minimization, expanding the attack surface without adding functional value for the benefits project.
- ✓
Restrict access to the file to approved HR and project staff only.
Why this is correct
Implementing need-to-know access controls via IAM and RBAC restricts file visibility to a small set of authorized HR and project personnel, drastically reducing accidental or intentional insider exposure. Access checks, separation of duties, and audit logging ensure that only those with a clear business need can open the file. This is a direct confidentiality control that complements data minimization and should be enforced regardless of storage location.
- ✗
Upload the file to a public collaboration site so the contractor can retrieve it easily.
Why it's wrong here
Using a public collaboration site removes authentication and encryption, making employee PII indexable and accessible to anyone with the link. Without access controls, the file could be crawled by search engines, downloaded by unintended parties, and retained by the provider, leading to likely breach notification obligations and severe privacy violations. Secure file transfer should use encrypted repositories with per-user permissions and audit trails.
- ✗
Keep an unrestricted copy on multiple shared drives for convenience.
Why it's wrong here
Creating unrestricted copies on multiple shared drives expands the attack surface and complicates access revocation—any one copy can leak without the others being traceable. Uncontrolled data sprawl violates data retention and disposal policies, increases the likelihood of malware infection, and makes compliance audits difficult. Convenience is not a valid justification for bypassing hardware security and least-privilege controls.
Go deeper
Related to this question
Learn chapter
Compliance and Regulatory Frameworks
Key term
GDPR
The General Data Protection Regulation (GDPR) is a European Union law that sets strict rules for how organizations collect, store, process, and protect the personal data of individuals within the EU.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.