Courseiva
Security Program Management and OversightmediumMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

The legal team wants to confirm that customer records are being deleted on schedule after the retention period expires. Which two artifacts best demonstrate compliance? Select two.

⚠ Common exam trap

It's easy for candidates to confuse a draft or unapproved policy (Option E) with an approved one, or mistakenly think that informal evidence like social media posts (Option B) can substitute for authoritative documentation and verifiable logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

An approved retention schedule or retention policy that defines the deletion period.

An approved retention schedule or policy is the authoritative document that defines the required deletion period for customer records. It serves as the legal mandate against which compliance is measured. Option C is correct because system or audit logs provide verifiable evidence that the deletion job executed successfully, confirming that the policy was actually followed. Together, these two artifacts demonstrate both the requirement (policy) and the execution (logs) needed to prove compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • An approved retention schedule or retention policy that defines the deletion period.

    Why this is correct

    An approved retention schedule or retention policy is the authoritative legal and operational document that specifies how long customer records must be kept before deletion. It defines the deletion period precisely, creating an enforceable rule that the organization must follow. Without an approved, current policy, there is no clear compliance baseline, and auditors cannot validate whether data disposal practices meet regulatory or contractual obligations.

  • A folder of employee social media posts about data cleanup.

    Why it's wrong here

    A folder of employee social media posts about data cleanup is informal, unsanctioned content that lacks the integrity and chain of custody required as compliance evidence. Social media posts are not controlled records, are often incomplete, and can be easily edited or deleted, making them unsuitable for an audit or legal review. They do not originate from a system of record and therefore cannot prove that retention schedules were actually implemented or enforced.

  • System or audit logs showing the deletion job ran successfully.

    Why this is correct

    System or audit logs showing the deletion job ran successfully provide operational proof that the retention process executed as intended. These logs capture timestamps, job status, affected records, and often the user or system account that triggered the action, creating a strong audit trail. They demonstrate that the deletion policy was not merely theoretical but was actively carried out, which is critical for legal teams to confirm compliance with data protection regulations.

  • A list of all printers in the office environment.

    Why it's wrong here

    A list of all printers in the office environment is an asset inventory that is unrelated to customer record retention or deletion. It does not contain any information about data lifecycle, storage locations, deletion schedules, or execution of data disposal processes. While such a list may be relevant for hardware management or security audits, it provides no evidence of proper handling of customer records and cannot support a legal confirmation of compliance.

  • A draft policy from last year that was never approved.

    Why it's wrong here

    A draft policy from last year that was never approved has no official status and does not represent the organization's enforceable requirements. Without formal approval, it remains a proposal that was never ratified, so it cannot establish a legal obligation to delete records or define a specific retention period. Auditors and legal teams require approved, current policies alongside evidence of execution, and an unapproved draft fails both criteria.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.