Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Paper onboarding forms have reached the end of their retention period, and no legal hold applies. What should happen next?

⚠ Common exam trap

Many exam-takers think indefinite storage (Option A) is safer or that scanning to a personal cloud (Option C) preserves data, but the exam tests that data must be destroyed when retention expires and no legal hold exists, not retained or migrated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Destroy them using an approved secure disposal method.

Once paper onboarding forms have reached the end of their retention period and no legal hold applies, the organization must destroy them using an approved secure disposal method (e.g., cross-cut shredding, pulping, or incineration) to prevent unauthorized access to personally identifiable information (PII) and comply with data protection regulations such as GDPR or HIPAA. Retaining data beyond its required lifecycle violates the data minimization principle and increases breach risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Store them indefinitely in case the company needs them later.

    Why it's wrong here

    Retaining paper forms indefinitely ignores the records management lifecycle and the established retention schedule, which exists to limit unnecessary storage of sensitive information. Indefinite storage also elevates the risk of a data breach, since more records mean more exposure, and it conflicts with data minimization principles found in frameworks like GDPR and HIPAA. There is no legitimate basis for keeping records beyond their scheduled disposition merely in case they are needed later, especially when a proper legal hold, not guesswork, is the only reason to preserve records beyond the retention period.

  • Destroy them using an approved secure disposal method.

    Why this is correct

    This is correct because once retention requirements are satisfied and no legal hold exists, the records should be securely destroyed. Secure disposal reduces the chance of unauthorized disclosure and supports compliance with the retention schedule. For paper records, approved shredding or other secure destruction methods are appropriate.

  • Scan them to a personal cloud account so they are not lost.

    Why it's wrong here

    Scanning the forms into a personal cloud account bypasses the organization's approved archival systems and security controls, such as role-based access, encryption, and audit logging. This creates an uncontrolled copy of sensitive data outside the company's governance boundary, potentially violating compliance requirements regarding data residency and storage oversight. Personal cloud storage is not a sanctioned records repository, so this action would compound the compliance issue by failing to preserve the records in a manner that supports retention, e-discovery, or proper destruction.

  • Mail copies to every manager for review before disposal.

    Why it's wrong here

    Mailing copies to every manager multiplies the number of people with access to the forms, directly violating the principle of least privilege that governs sensitive records. This broad, indiscriminate distribution exposes personal information to individuals who likely have no legitimate business need, increasing the chance of unauthorized disclosure or misplacement. Review by managers is not a requirement of the retention schedule, and the copies themselves would then require their own secure disposal, creating a larger trail of unnecessary sensitive data.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.