Courseiva
Security Program Management and OversightmediumMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

HR needs to share a copy of employee records with a benefits contractor for testing. The contractor only needs names and coverage selections, not Social Security numbers or bank details. Which two actions best satisfy data handling requirements? Select two.

⚠ Common exam trap

Many candidates assume trust (option B) or convenience (option D or E) justifies sharing full data, but the exam emphasizes that data handling requirements always mandate minimizing exposure and enforcing access controls regardless of trust level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Redact or mask unnecessary sensitive fields before sharing the file.

Redacting or masking sensitive fields like Social Security numbers and bank details ensures that the contractor receives only the necessary data (names and coverage selections) while protecting personally identifiable information (PII). This aligns with the principle of data minimization and compliance with regulations such as GDPR or HIPAA, which require that only the minimum necessary data be shared for a specific purpose. Masking techniques, such as replacing SSNs with placeholders or applying irreversible hashing, prevent unauthorized exposure even if the file is intercepted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Redact or mask unnecessary sensitive fields before sharing the file.

    Why this is correct

    Redaction or masking is a foundational data-minimization control that replaces or removes sensitive fields such as SSNs, bank details, and medical information before any external sharing. This reduces the potential impact of unauthorized disclosure because even if the file is leaked, the exposed data is not sensitive. It also aligns with privacy regulations like GDPR and HIPAA, which require using the minimum necessary data for a given purpose.

  • Send the full employee record set because the contractor is trusted.

    Why it's wrong here

    Trusting a third party does not eliminate privacy obligations or the risk of compromise. A trusted contractor may still misconfigure storage, fall victim to phishing, or have an insider threat—all of which can expose personally identifiable information (PII). Sending entire records violates the principle of least privilege and data minimization, expanding the attack surface without adding functional value for the benefits project.

  • Restrict access to the file to approved HR and project staff only.

    Why this is correct

    Implementing need-to-know access controls via IAM and RBAC restricts file visibility to a small set of authorized HR and project personnel, drastically reducing accidental or intentional insider exposure. Access checks, separation of duties, and audit logging ensure that only those with a clear business need can open the file. This is a direct confidentiality control that complements data minimization and should be enforced regardless of storage location.

  • Upload the file to a public collaboration site so the contractor can retrieve it easily.

    Why it's wrong here

    Using a public collaboration site removes authentication and encryption, making employee PII indexable and accessible to anyone with the link. Without access controls, the file could be crawled by search engines, downloaded by unintended parties, and retained by the provider, leading to likely breach notification obligations and severe privacy violations. Secure file transfer should use encrypted repositories with per-user permissions and audit trails.

  • Keep an unrestricted copy on multiple shared drives for convenience.

    Why it's wrong here

    Creating unrestricted copies on multiple shared drives expands the attack surface and complicates access revocation—any one copy can leak without the others being traceable. Uncontrolled data sprawl violates data retention and disposal policies, increases the likelihood of malware infection, and makes compliance audits difficult. Convenience is not a valid justification for bypassing hardware security and least-privilege controls.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.