Security Program Management and Oversight practice questions
Security Program Management & Oversight is the domain of the SY0-701 exam that covers how organizations build, maintain, and improve their security programs. Think of it as the 'management layer' of cybersecurity—not the technical tools like firewalls or antivirus, but the policies, procedures, governance, and risk management that ensure those tools are used effectively. In plain English, this domain teaches you how to run a security department like a business: setting goals, measuring performance, managing budgets, complying with laws, and continuously improving. It’s about the 'big picture' decisions that keep an organization safe from cyber threats.
Why is this important for real-world IT/security/cloud work? Because technical skills alone won't get you far. A security engineer who can configure a SIEM but doesn't understand incident response plans or compliance requirements (like GDPR or HIPAA) is a liability. In the real world, you’ll need to justify security spending to executives, write policies that balance security with usability, and ensure your cloud infrastructure meets regulatory standards. For example, if you work at a healthcare company, you must know how to implement a security program that protects patient data under HIPAA. This domain gives you the vocabulary and frameworks to communicate with managers, auditors, and legal teams.
On the SY0-701 exam, this domain (worth 20% of the score) tests your knowledge of: security governance principles (e.g., policies, standards, procedures), risk management processes (identifying, assessing, and mitigating risks), compliance with laws and regulations (e.g., GDPR, PCI DSS), business continuity and disaster recovery concepts, and security awareness training. You’ll also see questions on third-party risk management, data classification, and security metrics (KPIs). The exam won’t ask you to write a policy, but you must understand the purpose of each document and when to use it. For instance, you should know the difference between a policy (high-level intent) and a procedure (step-by-step instructions).
To approach studying this domain, start by memorizing the key documents and their hierarchy: policies → standards → procedures → guidelines. Then, focus on risk management: the steps of risk assessment (identification, analysis, evaluation, treatment) and common risk treatment options (avoid, transfer, mitigate, accept). Use real-world examples: imagine a company storing customer credit card data—what PCI DSS requirements apply? How would you create a business continuity plan for a ransomware attack? Practice with sample questions that ask you to identify the correct policy or control for a given scenario. Since this domain is conceptual, create flashcards for terms like 'due care' vs. 'due diligence,' 'RPO' vs. 'RTO,' and 'quantitative' vs. 'qualitative' risk assessment. Finally, connect the dots: security program management ties together all other domains—it’s the 'why' behind the technical controls you learn elsewhere.
Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.
What to know about Security Program Management and Oversight
Security Program Management & Oversight covers the governance, risk management, compliance, and business continuity aspects of cybersecurity—how to plan, implement, and improve an organization's security program.
Security governance principles: policies, standards, procedures, and guidelines
Risk management process: identification, assessment, analysis, and treatment of risks
Compliance with laws and regulations: GDPR, HIPAA, PCI DSS, SOX, etc.
Business continuity and disaster recovery: BCP, DRP, RTO, RPO, and testing
Security awareness and training: phishing simulations, role-based training, and metrics
Third-party risk management: vendor assessments, SLAs, and due diligence
Why learners struggle
Why Security Program Management and Oversight questions are commonly missed
RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).
·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
·MHz vs CL — speed vs latency trade-offs in performance
·Single-channel vs dual-channel — bandwidth impact misconception
·ECC vs non-ECC — error correction support in servers vs desktops
·32-bit vs 64-bit — maximum addressable RAM limit
Watch out for
Common Security Program Management and Oversight exam traps
▸Confusing policy vs. procedure: a policy is high-level intent, a procedure is step-by-step; exam may ask which document defines 'acceptable use' (policy) vs. 'how to reset a password' (procedure)
▸Mixing up risk treatment options: avoid (eliminate activity), transfer (buy insurance), mitigate (add controls), accept (acknowledge risk); candidates often pick 'mitigate' when 'avoid' is correct for a high-risk scenario
▸Forgetting that compliance is not the same as security: a company can be compliant with a regulation but still have poor security; exam may present a scenario where a compliant organization is breached and ask what's missing (e.g., risk assessment beyond compliance)
▸Misinterpreting RTO vs. RPO: RTO is time to restore service, RPO is acceptable data loss; exam might describe a backup strategy and ask which metric it satisfies
Practice set
Security Program Management and Oversight questions
20 questions · select your answer, then reveal the explanation
A manager asks how the security team decides which issue should be fixed first. Which two factors are MOST important to evaluate for each risk?
Trap 1: Asset age and user satisfaction
Asset age and user satisfaction are not primary factors for risk prioritization; they may be considered in other contexts but do not directly determine which risk to address first.
Trap 2: Vendor popularity and implementation speed
Popular products can still be risky, and implementation speed alone does not measure security priority.
Trap 3: Encryption algorithm and screen resolution
These are technical details, but they do not directly determine overall risk priority for the business.
Why wrong: Asset age and user satisfaction are not primary factors for risk prioritization; they may be considered in other contexts but do not directly determine which risk to address first.
B
Likelihood and impact
Likelihood and impact are the two core components of risk calculation, making them the most important factors for deciding which issue to fix first.
C
Vendor popularity and implementation speed
Why wrong: Popular products can still be risky, and implementation speed alone does not measure security priority.
D
Encryption algorithm and screen resolution
Why wrong: These are technical details, but they do not directly determine overall risk priority for the business.
Risk register:
- Scoring model: Likelihood and impact are each rated from 1 to 5; higher total score means higher priority
- R-101: Medium likelihood (3), High impact (4), current control: manual review
- R-102: High likelihood (5), Medium impact (3), current control: none
- R-103: Low likelihood (1), Critical impact (5), current control: compensating detective control
- R-104: High likelihood (4), High impact (4), current control: backup power only
- Business note: Only one risk can be funded this quarter.
Trap 1: R-101, because manual review means the risk is already partially…
A manual review is a control that should already be reflected in the risk's residual likelihood and impact scores, not treated as a separate reason to defer remediation. In the scoring model shown, priority is determined by the final likelihood-impact score, so a partially controlled risk either has a lower residual score or the control is insufficient to reduce it. R-101 still ranks below R-104, which means its residual risk is lower despite the existing review process. The presence of a control does not override the organization's stated rule of prioritizing the highest scored risk.
Trap 2: R-102, because a cheaper remediation always has priority over a…
Remediation cost is a resource consideration, but the exhibit explicitly states that the organization sets priority using the likelihood-impact score, not a cost-benefit ratio. A cheaper fix for a lower-scoring risk might be attractive from a budget perspective, but it would violate the defined prioritization model and leave the highest remaining risk untreated. Unless two risks are tied or the register includes a separate cost-priority column, cost cannot override the scoring matrix. Therefore, R-102, with its lower total score, would not be selected over R-104.
Trap 3: R-103, because critical impact always outweighs likelihood in the…
In a risk matrix that multiplies likelihood and impact, a critical impact (e.g., 5) paired with a low likelihood (e.g., 2) yields a score of 10, whereas R-104's score of 16 suggests a higher combined total. The organization uses the numeric product (or sum), so impact alone is not the deciding factor; likelihood is weighted equally in the stated model. Claiming critical impact always dominates ignores the matrix's intended balancing of probability and consequence. Thus, R-103 cannot be prioritized based solely on its high impact when its overall score is lower than R-104.
R-101, because manual review means the risk is already partially controlled.
Why wrong: A manual review is a control that should already be reflected in the risk's residual likelihood and impact scores, not treated as a separate reason to defer remediation. In the scoring model shown, priority is determined by the final likelihood-impact score, so a partially controlled risk either has a lower residual score or the control is insufficient to reduce it. R-101 still ranks below R-104, which means its residual risk is lower despite the existing review process. The presence of a control does not override the organization's stated rule of prioritizing the highest scored risk.
B
R-102, because a cheaper remediation always has priority over a higher total score.
Why wrong: Remediation cost is a resource consideration, but the exhibit explicitly states that the organization sets priority using the likelihood-impact score, not a cost-benefit ratio. A cheaper fix for a lower-scoring risk might be attractive from a budget perspective, but it would violate the defined prioritization model and leave the highest remaining risk untreated. Unless two risks are tied or the register includes a separate cost-priority column, cost cannot override the scoring matrix. Therefore, R-102, with its lower total score, would not be selected over R-104.
C
R-103, because critical impact always outweighs likelihood in the matrix.
Why wrong: In a risk matrix that multiplies likelihood and impact, a critical impact (e.g., 5) paired with a low likelihood (e.g., 2) yields a score of 10, whereas R-104's score of 16 suggests a higher combined total. The organization uses the numeric product (or sum), so impact alone is not the deciding factor; likelihood is weighted equally in the stated model. Claiming critical impact always dominates ignores the matrix's intended balancing of probability and consequence. Thus, R-103 cannot be prioritized based solely on its high impact when its overall score is lower than R-104.
D
R-104, because it has the highest likelihood-impact score in the register.
R-104 scores 16, which is higher than the other listed risks under the stated 1-to-5 model. Since the organization can fund only one risk this quarter, the highest scored item should be prioritized first. The current backup power helps resilience, but it does not reduce the fact that this is the largest remaining risk in the matrix.
Select all of the following risk term definitions that are correct.
Drag a concept onto its matching description — or click a concept then click the description.
Concepts
Matches
Likelihood
Impact
Inherent risk
Residual risk
Risk appetite
Trap 1: Inherent risk: The level of risk after controls are applied
This statement is incorrect because it reverses the temporal relationship between controls and risk. Risk measured after controls have been applied is residual risk, while inherent risk is only meaningful as the pre-control baseline. Using this incorrect definition would make it impossible to quantify control effectiveness or to justify additional investment in mitigation, since the true starting point would be unknown.
Trap 2: Risk appetite: The acceptable deviation from the risk appetite
This statement incorrectly assigns the definition of risk tolerance to risk appetite. Risk appetite is the overarching inclination to accept risk, while tolerance is the permissible variation around that appetite for a specific exposure. Failing to distinguish them can lead to either too-stringent operational limits without strategic intent, or strategic statements without actionable thresholds.
Inherent risk: The level of risk before any controls are applied
Inherent risk is the hypothetical exposure that exists before any security controls or mitigation measures are applied; it reflects the raw combination of threat, vulnerability, and potential impact. This baseline is used to prioritize where controls are most needed, even though in practice many controls are already present. It is a planning and analysis construct rather than an often-observable state.
B
Residual risk: The level of risk after controls are applied
Residual risk is the level of risk that remains after controls have been implemented, accounting for each control's effectiveness and the possibility of control failure. This is the risk the organization actually operates with and must manage, because not all risk can be eliminated. It is compared against the organization's risk appetite and tolerance to decide whether additional risk treatment is necessary.
C
Risk appetite: The amount of risk an organization is willing to accept
Risk appetite is a strategic, organization-wide declaration of the amount of risk that leadership is willing to accept while pursuing its mission and objectives. It guides major decisions and resource allocation, and is typically expressed as a qualitative principle or a quantitative threshold at a high level. Unlike tolerance, which is set for specific areas, appetite reflects the overall risk-taking philosophy.
D
Risk tolerance: The acceptable deviation from the risk appetite
Risk tolerance defines the acceptable deviation from the risk appetite for a specific risk category, project, or objective. It is operational and measurable, often expressed as a concrete limit or threshold, such as a maximum percentage of failed audits or an acceptable downtime window. This allows managers to know when a particular risk has exceeded the organization's intended appetite.
E
Inherent risk: The level of risk after controls are applied
Why wrong: This statement is incorrect because it reverses the temporal relationship between controls and risk. Risk measured after controls have been applied is residual risk, while inherent risk is only meaningful as the pre-control baseline. Using this incorrect definition would make it impossible to quantify control effectiveness or to justify additional investment in mitigation, since the true starting point would be unknown.
F
Risk appetite: The acceptable deviation from the risk appetite
Why wrong: This statement incorrectly assigns the definition of risk tolerance to risk appetite. Risk appetite is the overarching inclination to accept risk, while tolerance is the permissible variation around that appetite for a specific exposure. Failing to distinguish them can lead to either too-stringent operational limits without strategic intent, or strategic statements without actionable thresholds.
Which missing control best improves oversight of the supplier?
Exhibit
Supplier security scorecard
--------------------------------------------------
Supplier: DeltaPrint Services
New subcontractor added last week: Yes
Data processing agreement: Signed
Breach-notification window: 30 days
Right-to-audit clause: Not included
Annual attestation: Self-certified by supplier only
Trap 1: Allow the supplier to choose any encryption algorithm it wants.
Permitting the supplier to freely choose any encryption algorithm abdicates the organization's responsibility for cryptographic standards and risks adoption of outdated or non-compliant algorithms, such as DES or RC4. This weakens security because the organization cannot mandate strong options like AES-256 or proper key management, and it eliminates any chance of validating that the supplier meets regulatory requirements. This option is a delegation of control, not an improvement in oversight.
Trap 2: Disable all contract reviews after signature.
Disabling contract reviews removes the organization's ability to monitor the supplier's evolving security posture, including flagging material changes like new subcontractors or weakened controls. It turns the contract into a static document with no continuous oversight, directly contradicting the goal of supply chain risk management. This action increases risk by leaving unknown vulnerabilities undiscovered until after a breach.
Trap 3: Require the vendor to use employee badges for all facilities.
Requiring employee badges addresses physical access control at the vendor's facilities but does little to secure data processing, network segmentation, or subcontractor handling. The exhibit's missing control is a contractual/administrative mechanism like an audit right, not a physical safety measure, so badges fail to provide the necessary verification of security operations. Even with badges, the organization cannot inspect evidence of compliance or validate third-party risk.
A right-to-audit clause is a contractual control that grants the organization explicit permission to inspect the supplier's security infrastructure, processes, and evidence. It bridges the oversight gap in the exhibit because it allows verification of claims about encryption, logging, and subcontractor management rather than merely accepting self-reported compliance. Without it, the organization has no enforceable mechanisms to validate the vendor's actual security posture, making it the best missing control.
B
Allow the supplier to choose any encryption algorithm it wants.
Why wrong: Permitting the supplier to freely choose any encryption algorithm abdicates the organization's responsibility for cryptographic standards and risks adoption of outdated or non-compliant algorithms, such as DES or RC4. This weakens security because the organization cannot mandate strong options like AES-256 or proper key management, and it eliminates any chance of validating that the supplier meets regulatory requirements. This option is a delegation of control, not an improvement in oversight.
C
Disable all contract reviews after signature.
Why wrong: Disabling contract reviews removes the organization's ability to monitor the supplier's evolving security posture, including flagging material changes like new subcontractors or weakened controls. It turns the contract into a static document with no continuous oversight, directly contradicting the goal of supply chain risk management. This action increases risk by leaving unknown vulnerabilities undiscovered until after a breach.
D
Require the vendor to use employee badges for all facilities.
Why wrong: Requiring employee badges addresses physical access control at the vendor's facilities but does little to secure data processing, network segmentation, or subcontractor handling. The exhibit's missing control is a contractual/administrative mechanism like an audit right, not a physical safety measure, so badges fail to provide the necessary verification of security operations. Even with badges, the organization cannot inspect evidence of compliance or validate third-party risk.
An external auditor asks for proof that emergency firewall changes were reviewed and approved before implementation last quarter. Which two artifacts are the best evidence? Select two.
Trap 1: A screenshot of the firewall's current rule base after the change.
A screenshot of the firewall's current rule base only depicts the resulting configuration at a single point in time; it carries no metadata about who requested or authorized the change, nor when that approval occurred. It could even be captured from an unapproved modification, and it does not demonstrate that a formal review preceded implementation. As a static snapshot, it lacks the procedural and chronological evidence required to satisfy an auditor's request for change-control verification.
Trap 2: A technician's memory of getting permission over the phone.
Reliance on a technician's recollection of a phone conversation is inherently unreliable because memory is fallible, easily interpreted through bias, and vulnerable to post hoc rationalization. An auditor cannot independently verify the exact content, timing, or authority of the verbal approval, and no durable record exists to support the narrative. Evidence must be objective, reproducible, and immutable; oral testimony alone lacks these qualities and is therefore inadmissible as proof in most formal audits.
Trap 3: The organization's general information security policy.
An information security policy is a directive that establishes the rules and standards for change management, but it is not a record of any specific action having been taken. It cannot demonstrate that the particular firewall change was submitted, reviewed, or approved per the required process. Auditors require evidence of execution—such as approved tickets or CAB records—not just the existence of a governing document that merely mandates the procedure.
An approved change ticket that shows the reviewer, approver, and timestamps.
A change ticket with approval details is strong evidence because it shows the request was reviewed before implementation and by whom. It also creates an auditable record that can be tied to the actual change event.
B
A screenshot of the firewall's current rule base after the change.
Why wrong: A screenshot of the firewall's current rule base only depicts the resulting configuration at a single point in time; it carries no metadata about who requested or authorized the change, nor when that approval occurred. It could even be captured from an unapproved modification, and it does not demonstrate that a formal review preceded implementation. As a static snapshot, it lacks the procedural and chronological evidence required to satisfy an auditor's request for change-control verification.
C
CAB or workflow approval records documenting the decision.
Change Advisory Board (CAB) minutes or workflow approval records are authoritative artifacts produced by the change-management process, explicitly documenting that the proposed firewall modification was scrutinized by designated reviewers and formally approved. Unlike a configuration snapshot, they provide an auditable timeline of evaluation, decision, and authorization, aligning directly with common compliance frameworks such as ITIL or ISO 27001. These records demonstrate governance and due diligence, making them strong evidence for an audit.
D
A technician's memory of getting permission over the phone.
Why wrong: Reliance on a technician's recollection of a phone conversation is inherently unreliable because memory is fallible, easily interpreted through bias, and vulnerable to post hoc rationalization. An auditor cannot independently verify the exact content, timing, or authority of the verbal approval, and no durable record exists to support the narrative. Evidence must be objective, reproducible, and immutable; oral testimony alone lacks these qualities and is therefore inadmissible as proof in most formal audits.
E
The organization's general information security policy.
Why wrong: An information security policy is a directive that establishes the rules and standards for change management, but it is not a record of any specific action having been taken. It cannot demonstrate that the particular firewall change was submitted, reviewed, or approved per the required process. Auditors require evidence of execution—such as approved tickets or CAB records—not just the existence of a governing document that merely mandates the procedure.
After a phishing simulation, many users still nearly entered credentials. Leadership wants to reduce repeat mistakes without causing long training sessions. Which two actions are the best balance of security and usability? Select two.
Trap 1: Require every employee to attend a full-day annual course this week
Requiring a full-day annual course this week is an overreaction that sacrifices a day of business productivity for every employee, not just those who clicked, and it separates the training content from the specific simulation that exposed the weakness. The delay also means corrective information is not delivered during the acute window when users are most likely to integrate the lesson, reducing training transfer. Additionally, long, mandatory training sessions are known to induce cognitive fatigue, which can actually lower retention and engagement compared to brief, focused, repeated messages.
Trap 2: Publicly post the names of employees who clicked the simulation
Publicly posting the names of employees who clicked the simulation is an example of negative incentives that backfire in security awareness. It creates a punitive environment where users fear embarrassment or disciplinary action, which strongly suppresses the reporting of both simulated and real phishing attempts, precisely the behavior you need to encourage. It also risks violating workplace privacy norms and can lead to resentment of the security team, ultimately undermining the foundation of trust that is essential for a successful security program.
Trap 3: Disable all email attachments for every user
Disabling all email attachments for every user is a technically extreme and operationally crippling control that takes precedence over system usability and business processes. It removes a critical communication channel used for contracts, invoices, and collaborative documents, forcing workarounds that often carry greater risk, such as users sending sensitive data via less secure channels. Rather than solving the root cause of user susceptibility, it abandons education and awareness in favor of a blunt access restriction that cannot be justified in a risk-based security program.
Send a short targeted refresher focused on the exact mistake
A brief, targeted refresher that references the exact phishing simulation cues (e.g., spoofed domain, urgency, unexpected attachments) provides immediate, context-specific learning that directly addresses the observed behavioral lapse. Unlike generic annual training, this microlearning intervention reinforces the correct decision at the right moment, which aligns with the spacing and retrieval practice principles that improve long-term retention. It also minimizes disruption to daily operations, making it a proportionate response to a single simulation incident.
B
Add an easy reporting button inside the email client
An easy reporting button in the email client reduces the response cost for users, which is a key factor in whether they take the extra step to report suspected phishing. It not only enables immediate reporting to the security team for analysis and alerting, but also provides a positive feedback loop when users see that their reports are acted upon, thus reinforcing the behavior. This technical control addresses the usability gap and helps shift security awareness from recognition alone to actual intervention, which is a core goal of effective phishing defense.
C
Require every employee to attend a full-day annual course this week
Why wrong: Requiring a full-day annual course this week is an overreaction that sacrifices a day of business productivity for every employee, not just those who clicked, and it separates the training content from the specific simulation that exposed the weakness. The delay also means corrective information is not delivered during the acute window when users are most likely to integrate the lesson, reducing training transfer. Additionally, long, mandatory training sessions are known to induce cognitive fatigue, which can actually lower retention and engagement compared to brief, focused, repeated messages.
D
Publicly post the names of employees who clicked the simulation
Why wrong: Publicly posting the names of employees who clicked the simulation is an example of negative incentives that backfire in security awareness. It creates a punitive environment where users fear embarrassment or disciplinary action, which strongly suppresses the reporting of both simulated and real phishing attempts, precisely the behavior you need to encourage. It also risks violating workplace privacy norms and can lead to resentment of the security team, ultimately undermining the foundation of trust that is essential for a successful security program.
E
Disable all email attachments for every user
Why wrong: Disabling all email attachments for every user is a technically extreme and operationally crippling control that takes precedence over system usability and business processes. It removes a critical communication channel used for contracts, invoices, and collaborative documents, forcing workarounds that often carry greater risk, such as users sending sensitive data via less secure channels. Rather than solving the root cause of user susceptibility, it abandons education and awareness in favor of a blunt access restriction that cannot be justified in a risk-based security program.
After several near-miss phishing attempts, leadership wants to reduce mistakes quickly without disrupting daily work. Which three measures are the best balance of security and usability? Select three.
Trap 1: Disable email for all staff until phishing activity stops.
Disabling email for all staff until phishing activity stops is operationally disruptive and unrealistic, as email is the primary communication backbone for most organizations. Phishing activity cannot be completely stopped, so the 'until' condition may never be met, leading to indefinite downtime. This approach punishes the entire workforce and encourages risky workarounds like personal email or unmanaged file-sharing, which can introduce greater security risks. It fails to address the root cause: user susceptibility to social engineering.
Trap 2: Block all external senders permanently.
A permanent block on all external senders would sever communication with customers, vendors, and partners, causing severe business continuity damage. Legitimate external emails are essential for operations, and a blanket block would also prevent receiving security advisories, customer inquiries, and other critical correspondence. This measure does not mitigate internal phishing, account takeover, or malicious attachments from trusted compromised senders, and it ignores the need for layered, risk-based email defenses.
Run short role-based phishing training for higher-risk user groups.
Targeted, short role-based phishing training focuses on users with access to high-value systems or financial data, using realistic scenarios that mirror their specific job functions. This approach increases engagement and retention while minimizing productivity loss compared to mandatory training for everyone. It allows security teams to prioritize limited training resources on the highest-risk segments, reducing overall organizational susceptibility to phishing.
B
Add a simple report-phishing button and encourage immediate reporting.
A simple report-phishing button lowers the barrier for users to notify security, enabling rapid detection and containment of campaigns. Integrated with email security tools, it can trigger automated threat analysis and block similar messages across the organization. Encouraging immediate reporting shortens dwell time and turns users into an active sensor network, a key component of a robust incident response plan.
C
Require out-of-band verification for payment changes and wire requests.
Requiring out-of-band verification for payment changes or wire requests ensures that high-risk financial actions are confirmed via a separate, trusted channel, such as a phone call or in-person confirmation. This directly mitigates business email compromise (BEC) attacks, where an attacker compromises an email account and requests fraudulent transactions. It leverages the fact that attackers rarely control multiple communication channels, making it a highly effective control against financial phishing.
D
Disable email for all staff until phishing activity stops.
Why wrong: Disabling email for all staff until phishing activity stops is operationally disruptive and unrealistic, as email is the primary communication backbone for most organizations. Phishing activity cannot be completely stopped, so the 'until' condition may never be met, leading to indefinite downtime. This approach punishes the entire workforce and encourages risky workarounds like personal email or unmanaged file-sharing, which can introduce greater security risks. It fails to address the root cause: user susceptibility to social engineering.
E
Block all external senders permanently.
Why wrong: A permanent block on all external senders would sever communication with customers, vendors, and partners, causing severe business continuity damage. Legitimate external emails are essential for operations, and a blanket block would also prevent receiving security advisories, customer inquiries, and other critical correspondence. This measure does not mitigate internal phishing, account takeover, or malicious attachments from trusted compromised senders, and it ignores the need for layered, risk-based email defenses.
The exhibit shows a weekly risk register for a small enterprise. Which three findings should be remediated first based on likelihood of exploitation and business impact? Select three.
Exhibit
Finding 1: Customer portal admin access lacks MFA. Internet-facing, moderate exploitability, high business impact.
Finding 2: Internal training wiki uses default template permissions. Intranet only, low exploitability, low business impact.
Finding 3: Payroll file share inherits broad write permissions. Internal network, easy lateral movement, high business impact.
Finding 4: Conference-room printer uses the default admin password. Internal network, moderate exploitability, medium business impact.
Finding 5: Isolated lab VM runs an outdated package. No production connectivity, contained, low business impact.
Trap 1: Finding 2, because any default setting should always outrank all…
Finding 2 is wrong because default settings, while important, should never automatically outrank all other issues without considering context. This internal wiki is low impact and has low exploitability, as it is not internet-facing and likely contains no sensitive data; thus, its risk is limited compared to findings with remote attack vectors or critical business data. Prioritizing it solely on the existence of a default configuration would ignore the actual likelihood and impact that drive risk management.
Trap 2: Finding 5, because any outdated software should be fixed before…
Finding 5 is wrong because outdated software alone does not justify priority; the lab VM is isolated and has low business impact, meaning the likelihood of exploitation is minimal and the blast radius is tiny. The age or patch level of software is just one factor, and without internet accessibility or critical data, this finding poses far less risk than the customer portal, which is both remotely accessible and tied to administrative functions. Effective risk prioritization weighs business impact, exploitability, and exposure—not simply whether a component is outdated.
Finding 1, because the customer portal is internet-facing and protects a high-value administrative path.
Finding 1 is the highest priority because it combines internet-facing exposure with a high-value administrative path, meaning an attacker can exploit it remotely without prior access and potentially seize control of critical systems. The customer portal's public attack surface increases the likelihood of compromise, while the administrative backing elevates the potential impact to full account or system takeover, creating a severe risk-score that outranks internal findings.
B
Finding 2, because any default setting should always outrank all other issues automatically.
Why wrong: Finding 2 is wrong because default settings, while important, should never automatically outrank all other issues without considering context. This internal wiki is low impact and has low exploitability, as it is not internet-facing and likely contains no sensitive data; thus, its risk is limited compared to findings with remote attack vectors or critical business data. Prioritizing it solely on the existence of a default configuration would ignore the actual likelihood and impact that drive risk management.
C
Finding 3, because broad payroll permissions can create both fraud and lateral-movement risk.
Finding 3 is a high-priority risk because broad payroll permissions expose business-critical data and create a dual threat of fraud and lateral movement. Excessive access to payroll allows insiders or compromised accounts to exfiltrate PII, manipulate salary records, or conduct financial fraud, while the same permissions can serve as a stepping stone to other HR or finance systems. However, this risk is internal and requires authenticated access, so it is slightly less urgent than Finding 1's direct internet-facing administrative path.
D
Finding 4, because a default printer password can be used as an easy foothold on the internal network.
Finding 4 is valid because a default printer password provides an easily exploited foothold on the internal network, letting an attacker bypass authentication and then pivot to other systems. Printers are often overlooked and may run on the same LAN with minimal segmentation, making them practical entry points for lateral movement, though they lack the direct internet exposure of the customer portal. The printer's vulnerability is a serious internal weakness, but it does not outrank the portal because it requires an initial internal presence and yields only limited privileges.
E
Finding 5, because any outdated software should be fixed before higher-impact business systems.
Why wrong: Finding 5 is wrong because outdated software alone does not justify priority; the lab VM is isolated and has low business impact, meaning the likelihood of exploitation is minimal and the blast radius is tiny. The age or patch level of software is just one factor, and without internet accessibility or critical data, this finding poses far less risk than the customer portal, which is both remotely accessible and tied to administrative functions. Effective risk prioritization weighs business impact, exploitability, and exposure—not simply whether a component is outdated.
A weekly risk review lists several findings. Which two should be addressed first based on likelihood of exploitation and business impact? Select two.
Trap 1: An internal lab system with an outdated browser component, isolated…
An internal lab system with an outdated browser component is a low-priority risk because it is isolated from production and not accessible from the customer-facing network, which severely limits the attack surface. An attacker would first need to gain a foothold in the internal network, significantly reducing the likelihood of exploitation. The system's lower business impact, due to its segregated role and lack of sensitive data, further lowers its risk score. While the outdated browser could theoretically be a launch point for lateral movement, the compensating control of isolation and its non-critical function make it acceptable to defer until a routine patching cycle.
Trap 2: A training virtual machine used offline once per month in a…
A training virtual machine used offline once per month in a disconnected lab presents minimal risk because it lacks network connectivity, eliminating remote attack vectors entirely. An attacker would need physical access to the lab environment, which is typically controlled and monitored, making exploitation highly improbable. The VM does not contain production data or interact with corporate systems, so the business impact of a compromise is negligible. Consequently, while the lack of updates might be a hygiene issue, the practical risk is so low that it should be deprioritized in favor of addressing exploitable, externally facing vulnerabilities.
Trap 3: A documentation site with a spelling error in its banner text.
A documentation site with a spelling error in its banner text is not a security vulnerability at all; it is purely a cosmetic issue that does not affect confidentiality, integrity, or availability. Spelling errors do not introduce any attack vector, weaken authentication, or expose sensitive data. From a security risk assessment perspective, this finding has zero practical impact on the organization's security posture. While it might be worth fixing for professionalism, it should not consume resources from remediating actual exploitable flaws that could lead to data breaches or system compromise.
An internet-facing VPN appliance with a known exploit and no vendor patch available yet.
An internet-facing VPN appliance with a known exploit and no vendor patch is a critical risk because it is directly exposed to untrusted networks, meaning attackers can probe it remotely without prior access. The existence of a known exploit raises the likelihood of automated or targeted exploitation, and a VPN compromise often grants access to the internal network, enabling lateral movement and broad data exposure. With no patch available, the organization must rely on temporary mitigations like access control lists, intrusion prevention rules, or disabling features, which may not fully close the vulnerability. This combination of high exposure, active exploitation risk, and potentially irreversible business impact makes it a top priority.
B
An internal lab system with an outdated browser component, isolated from production and not customer-facing.
Why wrong: An internal lab system with an outdated browser component is a low-priority risk because it is isolated from production and not accessible from the customer-facing network, which severely limits the attack surface. An attacker would first need to gain a foothold in the internal network, significantly reducing the likelihood of exploitation. The system's lower business impact, due to its segregated role and lack of sensitive data, further lowers its risk score. While the outdated browser could theoretically be a launch point for lateral movement, the compensating control of isolation and its non-critical function make it acceptable to defer until a routine patching cycle.
C
A public payroll portal that still uses default administrator credentials.
A public payroll portal that still uses default administrator credentials is an imminent and severe vulnerability because it is accessible from the internet, meaning anyone can attempt to log in with widely known default username and password combinations. Successful exploitation gives an attacker full administrative control over a system that handles highly sensitive employee data, including Social Security numbers, bank account details, and salary information. This can lead to identity theft, payroll fraud, and major regulatory fines, especially under GDPR or CCPA. The combination of internet exposure and trivially guessed credentials makes compromise nearly certain if left unfixed, so it must be prioritized immediately.
D
A training virtual machine used offline once per month in a disconnected lab.
Why wrong: A training virtual machine used offline once per month in a disconnected lab presents minimal risk because it lacks network connectivity, eliminating remote attack vectors entirely. An attacker would need physical access to the lab environment, which is typically controlled and monitored, making exploitation highly improbable. The VM does not contain production data or interact with corporate systems, so the business impact of a compromise is negligible. Consequently, while the lack of updates might be a hygiene issue, the practical risk is so low that it should be deprioritized in favor of addressing exploitable, externally facing vulnerabilities.
E
A documentation site with a spelling error in its banner text.
Why wrong: A documentation site with a spelling error in its banner text is not a security vulnerability at all; it is purely a cosmetic issue that does not affect confidentiality, integrity, or availability. Spelling errors do not introduce any attack vector, weaken authentication, or expose sensitive data. From a security risk assessment perspective, this finding has zero practical impact on the organization's security posture. While it might be worth fixing for professionalism, it should not consume resources from remediating actual exploitable flaws that could lead to data breaches or system compromise.
A security manager is writing baseline requirements for all corporate laptops. Which three statements belong in the standard rather than in a policy or guideline? Select three.
Trap 1: Users should consider keeping their devices updated whenever…
The phrase 'should consider' is advisory and non-normative, placing the decision to update in the hands of the user rather than establishing a mandatory baseline. Standards require imperative language such as 'must' or 'shall' to create enforceable obligations, and this statement lacks any defined update timeliness or technical enforcement mechanism. As a result, it cannot be audited or verified through system configuration checks, making it a guideline rather than a standard. This vagueness would lead to inconsistent security posture across devices.
Trap 2: Employees must follow the company's acceptable use policy at all…
While this is a mandatory-sounding rule, 'acceptable use policy' is a broad organizational directive that governs human behavior, including internet browsing, email, and data handling, without specifying technical thresholds. It cannot be directly enforced through configuration settings or verified via system audits because it relies on user discretion and interpretation. Such high-level guidance belongs at the policy tier, above standards that must provide exact, measurable requirements like encryption algorithms or session timeouts. Therefore, it does not qualify as a technical baseline standard.
Full-disk encryption must be enabled using approved encryption software.
This statement mandates a specific technical control: full-disk encryption (FDE) using approved tools and algorithms (e.g., BitLocker with AES-256). Because it names the mechanism and the approval requirement, it is objectively auditable—compliance can be verified via centralized management reports or registry checks. The use of 'must' makes it a mandatory baseline requirement, unlike a guideline that would suggest optional measures. This is exactly the kind of enforceable configuration that belongs in a security standard.
B
The screen must lock after 10 minutes of inactivity.
A 10-minute inactivity lock timeout is a discrete, measurable configuration parameter that can be enforced through Group Policy or mobile device management (MDM). It specifies a precise threshold that balances usability with the risk of unauthorized access to unattended sessions, and it can be automatically remediated if drift occurs. This is a baseline requirement because it defines an exact, testable setting, not a broad organizational goal. It also aligns with common compliance frameworks that require session locks after a defined period.
C
Users should consider keeping their devices updated whenever convenient.
Why wrong: The phrase 'should consider' is advisory and non-normative, placing the decision to update in the hands of the user rather than establishing a mandatory baseline. Standards require imperative language such as 'must' or 'shall' to create enforceable obligations, and this statement lacks any defined update timeliness or technical enforcement mechanism. As a result, it cannot be audited or verified through system configuration checks, making it a guideline rather than a standard. This vagueness would lead to inconsistent security posture across devices.
D
Local administrator rights are not allowed on standard user laptops.
This restriction directly implements the principle of least privilege by prohibiting local administrative rights on standard user endpoints, which limits the impact of malware and reduces unauthorized system changes. It is a specific, testable control—compliance can be verified by enumerating local group membership (e.g., Administrators group) and enforcing it via Group Policy or endpoint management tools. The statement defines a concrete, immutable state for managed laptops, which is a hallmark of a security standard. It also supports application whitelisting and system hardening baselines.
E
Employees must follow the company's acceptable use policy at all times.
Why wrong: While this is a mandatory-sounding rule, 'acceptable use policy' is a broad organizational directive that governs human behavior, including internet browsing, email, and data handling, without specifying technical thresholds. It cannot be directly enforced through configuration settings or verified via system audits because it relies on user discretion and interpretation. Such high-level guidance belongs at the policy tier, above standards that must provide exact, measurable requirements like encryption algorithms or session timeouts. Therefore, it does not qualify as a technical baseline standard.
A small company can only remediate two findings this week. Which two should be fixed first based on risk to the business? Select two.
Trap 1: An internal training VM used by one student with a medium…
This VM is isolated from production traffic, reachable only by a single student, and contains no sensitive data, which minimizes both the likelihood of a meaningful attack and the business impact if compromised. A medium-severity issue on an internal training system does not usually lead to data loss, financial damage, or lateral movement into critical systems. While it should be patched eventually, it does not warrant intervention this week compared to production-facing risks.
Trap 2: A discontinued server already removed from the network but still…
This server has already been physically and logically disconnected from the network, so it poses no active or reachable security risk; an attacker cannot exploit a system that is not connected. The main concern is inventory hygiene and the risk that a ghost asset could accidentally be reconnected without proper hardening, but that is a documentation problem, not a current vulnerability. Therefore, this finding is significantly less urgent than active production systems with known exposures.
Trap 3: A low-severity cosmetic issue on a noncritical dashboard page
A low-severity cosmetic issue on a noncritical dashboard page has no direct impact on confidentiality, integrity, or availability, and it does not provide any path for unauthorized access or privilege escalation. Such a flaw might affect user experience or interface appearance but does not expose sensitive data or allow malicious code execution. Since it creates no meaningful security risk, it should be deprioritized in favor of findings that could lead to a real breach.
An internet-facing VPN appliance with a critical vulnerability and a public exploit
This internet-facing VPN appliance is directly exploitable from the untrusted network, and a public exploit dramatically reduces the skill barrier for attackers. A critical vulnerability with known exploit code typically leads to remote code execution with high privileges, which could expose the entire internal network through the VPN tunnel. Given the asset's exposure and the strong likelihood of automated scanning, this threat should be remediated before any other finding.
B
An internal training VM used by one student with a medium vulnerability and no sensitive data
Why wrong: This VM is isolated from production traffic, reachable only by a single student, and contains no sensitive data, which minimizes both the likelihood of a meaningful attack and the business impact if compromised. A medium-severity issue on an internal training system does not usually lead to data loss, financial damage, or lateral movement into critical systems. While it should be patched eventually, it does not warrant intervention this week compared to production-facing risks.
C
A production print server that still uses the default administrator password and is accessible to finance users
Default administrator credentials on a production print server create a trivial authentication bypass, especially since the device is accessible to finance users whose workstations often process sensitive financial documents. An attacker who logs in with the default password may gain administrative control, pivot to other systems via network shares or domain trust, and capture print jobs containing confidential data. Because the compromise path is simple and the asset directly supports a high-impact business function, this finding must be fixed immediately.
D
A discontinued server already removed from the network but still listed in inventory
Why wrong: This server has already been physically and logically disconnected from the network, so it poses no active or reachable security risk; an attacker cannot exploit a system that is not connected. The main concern is inventory hygiene and the risk that a ghost asset could accidentally be reconnected without proper hardening, but that is a documentation problem, not a current vulnerability. Therefore, this finding is significantly less urgent than active production systems with known exposures.
E
A low-severity cosmetic issue on a noncritical dashboard page
Why wrong: A low-severity cosmetic issue on a noncritical dashboard page has no direct impact on confidentiality, integrity, or availability, and it does not provide any path for unauthorized access or privilege escalation. Such a flaw might affect user experience or interface appearance but does not expose sensitive data or allow malicious code execution. Since it creates no meaningful security risk, it should be deprioritized in favor of findings that could lead to a real breach.
A records manager confirms that paper onboarding forms containing government IDs are past retention, no legal hold exists, and the files are no longer needed. Which two actions should happen next? Select two.
Trap 1: Verify that no legal hold or regulatory exception applies.
Before any disposal, you must verify that no active legal hold, pending litigation, or regulatory investigation requires the forms to be preserved. A legal hold overrides normal retention schedules, and destroying records subject to a hold can result in severe discovery sanctions, spoliation claims, and adverse inferences in court. This check ensures that the destruction is both lawful and defensible.
Trap 2: Store the forms in a desk drawer for another quarter just in case.
Storing expired forms in a desk drawer 'just in case' is an ad hoc action that deviates from the approved records schedule and introduces unnecessary risk. These unofficial caches often lack the access controls, environmental safeguards, and indexing of a compliant records management system, making them vulnerable to unauthorized viewing, theft, or misfiling. Keeping expired records without a documented business or legal need also violates minimum retention principles.
Trap 3: Email scans of the forms to managers so they can keep a copy.
Emailing scans of the forms to managers creates redundant digital copies in enterprise email systems and mailboxes, which may be backed up, archived, or synced to cloud services indefinitely. This broadens the attack surface and increases the chance of a data breach, since email is rarely an approved secure storage mechanism for personal information. It also contradicts the core objective of secure disposal, which requires that no copies survive after the retention period ends.
Destroy the forms using approved secure disposal methods.
Approved secure disposal methods, such as cross-cut shredding or incineration, transform paper forms into unreadable, irrecoverable material. This is the only way to ensure that sensitive personal information is permanently compromised, satisfying data protection principles and regulatory requirements that mandate destruction after the retention period expires. Merely deleting or discarding intact forms would leave the data recoverable.
B
Record the destruction according to retention and disposal procedures.
Recording the destruction in accordance with retention and disposal procedures creates a formal audit trail that documents the date, method, and authorizing party for each disposal event. This documentation proves that the organization followed its governance obligations, which is a critical defense in compliance audits or investigations. Without this record, the organization cannot demonstrate that records were properly destroyed and not simply lost or misplaced.
C
Verify that no legal hold or regulatory exception applies.
Why wrong: Before any disposal, you must verify that no active legal hold, pending litigation, or regulatory investigation requires the forms to be preserved. A legal hold overrides normal retention schedules, and destroying records subject to a hold can result in severe discovery sanctions, spoliation claims, and adverse inferences in court. This check ensures that the destruction is both lawful and defensible.
D
Store the forms in a desk drawer for another quarter just in case.
Why wrong: Storing expired forms in a desk drawer 'just in case' is an ad hoc action that deviates from the approved records schedule and introduces unnecessary risk. These unofficial caches often lack the access controls, environmental safeguards, and indexing of a compliant records management system, making them vulnerable to unauthorized viewing, theft, or misfiling. Keeping expired records without a documented business or legal need also violates minimum retention principles.
E
Email scans of the forms to managers so they can keep a copy.
Why wrong: Emailing scans of the forms to managers creates redundant digital copies in enterprise email systems and mailboxes, which may be backed up, archived, or synced to cloud services indefinitely. This broadens the attack surface and increases the chance of a data breach, since email is rarely an approved secure storage mechanism for personal information. It also contradicts the core objective of secure disposal, which requires that no copies survive after the retention period ends.
An employee receives a text message claiming their email password expired and asks them to tap a link and confirm a one-time code. Which two responses are appropriate? Select two.
Trap 1: Reply to the sender and ask them to prove they are legitimate
Replying to the sender to ask for proof of legitimacy is counterproductive because any response—even a skeptic's challenge—confirms that your phone number is actively monitored by a human or auto-responder. This validation marks your number as a 'live target,' increasing your likelihood of receiving follow-up attacks with more personalized social engineering lures. Additionally, the sender may use your reply to extract behavioral cues or to build a profile for a spear-phishing campaign against you or your colleagues.
Trap 2: Enter the code to see whether the message is real
Entering the code to test the message's authenticity is dangerous because the one-time code is likely the MFA token for your corporate account. Submitting it into any web form or replying with it gives the attacker a real-time valid token, which they can immediately use to authenticate as you before the code expires. Even if the account seems inaccessible or the portal looks suspicious, entering the code might still be enough to complete the attacker's session hijack, so you must never use the code as a diagnostic tool.
Trap 3: Forward the text to coworkers so they can compare it
Forwarding the text to coworkers so they can compare it amplifies the risk rather than mitigating it. The forwarded message may be treated as a legitimate warning, prompting others to tap the link or answer the sender, directly expanding the attack's reach and potential victim count. Additionally, forwarding does not provide the security team with the metadata or headers needed for investigation, and it can normalize the behavior of interacting with unsolicited messages instead of following proper reporting procedures.
Do not tap the link or share the one-time code. Tapping the link may lead to a spoofed authentication portal designed to harvest your corporate credentials or install malware, even if the page looks identical to a legitimate login. Sharing the one-time code—whether via reply, phone, or email—allows an attacker to complete a pass-the-cookie or MFA relay attack, granting them access to your account before you can use the code yourself. A legitimate organization will never send an unsolicited text demanding a one-time code.
B
Report the message through the company's approved security channel
Report the message through the company's approved security channel. This action enables your incident response team to capture the full message header, analyze embedded links against threat intelligence feeds, and block the sender's infrastructure if it is already known. Reporting also alerts the security operations center (SOC) so they can issue a broadcast warning to other employees if the same phishing campaign is observed, preventing a broader compromise. The approved channel ensures the report is handled by trained analysts rather than lost in personal inboxes.
C
Reply to the sender and ask them to prove they are legitimate
Why wrong: Replying to the sender to ask for proof of legitimacy is counterproductive because any response—even a skeptic's challenge—confirms that your phone number is actively monitored by a human or auto-responder. This validation marks your number as a 'live target,' increasing your likelihood of receiving follow-up attacks with more personalized social engineering lures. Additionally, the sender may use your reply to extract behavioral cues or to build a profile for a spear-phishing campaign against you or your colleagues.
D
Enter the code to see whether the message is real
Why wrong: Entering the code to test the message's authenticity is dangerous because the one-time code is likely the MFA token for your corporate account. Submitting it into any web form or replying with it gives the attacker a real-time valid token, which they can immediately use to authenticate as you before the code expires. Even if the account seems inaccessible or the portal looks suspicious, entering the code might still be enough to complete the attacker's session hijack, so you must never use the code as a diagnostic tool.
E
Forward the text to coworkers so they can compare it
Why wrong: Forwarding the text to coworkers so they can compare it amplifies the risk rather than mitigating it. The forwarded message may be treated as a legitimate warning, prompting others to tap the link or answer the sender, directly expanding the attack's reach and potential victim count. Additionally, forwarding does not provide the security team with the metadata or headers needed for investigation, and it can normalize the behavior of interacting with unsolicited messages instead of following proper reporting procedures.
A records manager finds paper onboarding forms and scanned copies that contain government ID numbers. The retention period has expired, no legal hold exists, and the forms are no longer needed. Which three actions should the records manager take to securely dispose of the records? Select three.
Trap 1: Move the forms to an unsecured archive so they can be retrieved…
Moving paper forms to an unsecured archive fails every records-management control: it provides no access restrictions, no environmental protections, and no audit trail for who can retrieve or view the documents. Because the forms contain personal identifiable information (PII), an unsecured archive increases the risk of unauthorized disclosure and data breaches. This action also does not satisfy secure disposal requirements because the records remain intact and retrievable.
Trap 2: Keep personal copies because auditors might ask informally later.
Keeping personal copies for potential informal auditor questions bypasses the formal records-management process and creates an untracked, uncontrolled copy of sensitive data. This violates the principle of least privilege and expands the organization's attack surface, because personal files are rarely protected by enterprise security controls like encryption or access monitoring. It also undermines compliance audits by making it impossible to demonstrate that records were disposed of consistently per policy.
Verify the retention schedule and confirm that no legal hold or exception applies.
Before any records are destroyed, the first required step is to consult the organization's approved records retention schedule and verify that no legal hold, litigation hold, or regulatory exception is in effect. This is a control point that prevents spoliation of evidence and ensures compliance with laws such as HIPAA or GDPR. Skipping this step can result in severe legal penalties, even if the destruction method itself is secure.
B
Move the forms to an unsecured archive so they can be retrieved later if needed.
Why wrong: Moving paper forms to an unsecured archive fails every records-management control: it provides no access restrictions, no environmental protections, and no audit trail for who can retrieve or view the documents. Because the forms contain personal identifiable information (PII), an unsecured archive increases the risk of unauthorized disclosure and data breaches. This action also does not satisfy secure disposal requirements because the records remain intact and retrievable.
C
Destroy the paper copies with an approved secure method such as cross-cut shredding or pulping.
Once retention and legal-hold checks are complete, cross-cut shredding or pulping is the approved method for destroying paper records because it renders the documents irreversibly unreadable. These techniques physically reduce the media to particles or pulp, making reconstruction practically impossible. This aligns with standards such as NIST SP 800-88 for sanitization of physical media and is a documented, defensible disposal practice.
D
Securely delete the electronic copies from active storage and follow backup-retention rules for residual copies.
For electronic copies, secure deletion from active storage—using tools that overwrite data or perform cryptographic erase—is necessary because ordinary 'delete' commands often leave recoverable data behind. Residual copies in backups must be handled according to the backup-retention schedule, with older backups purged once they exceed their defined retention period. This two-part approach ensures that e-records cannot be resurrected from unmanaged storage and that all copies are accounted for.
E
Keep personal copies because auditors might ask informally later.
Why wrong: Keeping personal copies for potential informal auditor questions bypasses the formal records-management process and creates an untracked, uncontrolled copy of sensitive data. This violates the principle of least privilege and expands the organization's attack surface, because personal files are rarely protected by enterprise security controls like encryption or access monitoring. It also undermines compliance audits by making it impossible to demonstrate that records were disposed of consistently per policy.
A business unit keeps a low-priority legacy tool but adds extra monitoring and patching. The company also buys cyber insurance to reduce the financial effect of a loss. Which two risk treatment strategies are being used? Select two.
Trap 1: Acceptance
Acceptance means the organization knowingly leaves the risk as-is without adding new treatment.
Trap 2: Avoidance
Avoidance would mean stopping the risky activity or removing the legacy tool entirely.
Trap 3: Deterrent
A deterrent discourages behavior, but it is not the same as reducing or transferring the risk.
Based on the exhibit, which control option provides the greatest net annual financial benefit for the organization?
Exhibit
Risk register excerpt for the public payment API
Current estimated annual loss expectancy without additional controls: $260,000
Option A: Tighten change approvals and require admin MFA
Control cost: $40,000
Residual annual loss expectancy: $160,000
Option B: Implement active-active failover between regions
Control cost: $120,000
Residual annual loss expectancy: $40,000
Option C: Purchase cyber insurance for the service
Control cost: $25,000
Residual annual loss expectancy: $220,000
Option D: Add manual fallback processing and user training
Control cost: $10,000
Residual annual loss expectancy: $210,000
Trap 1: Option A, because it reduces loss enough to justify the control…
Effective, but its savings are smaller than Option B's savings once cost is included.
Trap 2: Option C, because transferring the risk is always cheaper than…
Insurance transfers some financial impact, but the residual annual loss remains high and the overall benefit is much lower.
Trap 3: Option D, because low upfront cost makes it the most economical…
Cheap, but it barely reduces the expected annual loss, so its net benefit is far below the better controls.
Option A, because it reduces loss enough to justify the control cost better than the smaller controls.
Why wrong: Effective, but its savings are smaller than Option B's savings once cost is included.
B
Option B, because its large reduction in annual loss outweighs the higher implementation cost.
Reduces annual loss expectancy from $260,000 to $40,000, creating $220,000 in annual savings before cost. After subtracting the $120,000 control cost, it still delivers the highest net benefit among the choices. Quantitative risk decisions should compare expected loss reduction against implementation cost, and this option provides the strongest financial return.
C
Option C, because transferring the risk is always cheaper than engineering a technical fix.
Why wrong: Insurance transfers some financial impact, but the residual annual loss remains high and the overall benefit is much lower.
D
Option D, because low upfront cost makes it the most economical option regardless of residual loss.
Why wrong: Cheap, but it barely reduces the expected annual loss, so its net benefit is far below the better controls.
A security manager issues a mandatory document that requires all corporate laptops to use full-disk encryption, automatic screen lock after 10 minutes, and approved endpoint protection software. The document will be checked during compliance reviews. Which governance artifact is this?
Trap 1: Policy
A policy states intent and high-level direction, but it is usually less specific than mandated technical settings.
Trap 2: Procedure
A procedure describes step-by-step actions to accomplish a task, not the required security posture itself.
Trap 3: Guideline
A guideline is recommended rather than mandatory, so it would not fit a compliance-enforced requirement.
A security manager is creating a document that requires every corporate laptop to use full-disk encryption, automatic screen locking after 10 minutes, and approved antivirus software. Which two governance artifacts best fit those requirements? Select two.
Trap 1: Policy
A policy is a high-level directive that communicates management's intent and overall security goals, such as 'all laptops must be secured.' It deliberately avoids prescribing specific technical settings, because those details belong in lower-level documents. Policies are mandatory in tone but leave room for implementation choices, so they do not define the exact minimum security configuration.
Trap 2: Procedure
A procedure is a sequential, step-by-step set of instructions that describes how to perform a specific task, such as how to apply a security patch or how to configure a laptop. It assumes a particular standard or policy already exists and focuses on the order of operations, not on defining the minimum technical requirements themselves. Therefore, a procedure cannot serve as the document that specifies required laptop security settings.
Trap 3: Guideline
A guideline is a recommended, non-mandatory set of best practices that offers flexibility in implementation. It may suggest possible security settings but explicitly allows for exceptions or alternative controls based on situational judgment. Because guidelines are advisory rather than required, they cannot enforce that all laptops meet a minimum security baseline, which is the manager's goal.
Why wrong: A policy is a high-level directive that communicates management's intent and overall security goals, such as 'all laptops must be secured.' It deliberately avoids prescribing specific technical settings, because those details belong in lower-level documents. Policies are mandatory in tone but leave room for implementation choices, so they do not define the exact minimum security configuration.
B
Standard
A standard is a mandatory, implementation-level rule that specifies exactly what security controls or settings must be in place. For laptop configuration, a standard would list required settings like encryption algorithms, password complexity rules, and patch levels. Standards are enforceable and non-negotiable, making them the appropriate document type when the security manager needs to require that every laptop meets a defined security posture.
C
Procedure
Why wrong: A procedure is a sequential, step-by-step set of instructions that describes how to perform a specific task, such as how to apply a security patch or how to configure a laptop. It assumes a particular standard or policy already exists and focuses on the order of operations, not on defining the minimum technical requirements themselves. Therefore, a procedure cannot serve as the document that specifies required laptop security settings.
D
Guideline
Why wrong: A guideline is a recommended, non-mandatory set of best practices that offers flexibility in implementation. It may suggest possible security settings but explicitly allows for exceptions or alternative controls based on situational judgment. Because guidelines are advisory rather than required, they cannot enforce that all laptops meet a minimum security baseline, which is the manager's goal.
E
Baseline
A baseline is the approved minimum configuration, such as a security configuration baseline that defines the lowest acceptable security settings for a system. It is essentially a specific type of standard, but it focuses on the starting point and the minimum state that must be maintained. While a baseline is correct in spirit, the more general and formal term that encompasses required settings beyond just a starting point is 'standard.'
A security manager is creating a company-wide requirement that all Windows laptops must have full-disk encryption, screen lock after 10 minutes, and approved antivirus enabled. Administrators can choose the exact implementation details, but the minimum settings must be mandatory across the fleet. Which governance artifact should the manager update?
Trap 1: Policy
A policy states broad management intent and rules, but it usually does not define the specific required settings.
Trap 2: Procedure
A procedure explains the step-by-step method for completing a task, not the mandatory security posture itself.
Trap 3: Guideline
A guideline is recommended but optional, so it would not be the right choice for mandatory controls.
A simulated phishing campaign shows that several employees clicked a simulated phishing link. Which action should the security team prioritize next?
Exhibit
Phishing simulation results by department
Finance: 31% clicked invoice lure, 9% reported it
HR: 28% clicked policy-update lure, 8% reported it
Executive Assistants: 39% clicked calendar-invite lure, 4% reported it
Help Desk: 12% clicked, 29% reported
Observation:
Most missed messages closely match each team's daily workflow and terminology.
Trap 1: Send a company-wide reminder to never click links in email,…
A company-wide reminder treats phishing as a simple binary 'do not click' rule, which fails against attacker techniques like display-name spoofing and lookalike domains that mimic legitimate senders. It also provides no concrete workflow for verification or reporting, and because the exhibit shows repeated role-specific lure patterns, a generic email will soon be ignored or forgotten. Without teaching users to inspect URLs, verify via out-of-band channels, or report suspicious messages, this measure offers only a false sense of security.
Trap 2: Focus only on punitive action for users who failed the simulation.
Punitive action for simulation failures creates a climate of fear and blame, which discourages users from reporting real phishing attempts because they worry about disciplinary consequences for clicking a legitimate-looking link. It also does nothing to address the underlying susceptibility to job-themed lures that the exhibit highlights; employees who clicked are simply penalized rather than taught to recognize red flags like urgency, mismatched domains, or unusual requests. This approach reduces incident visibility for the security team, as users will hide mistakes instead of sending suspicious emails to the SOC for analysis, ultimately increasing organizational risk.
Trap 3: Run the same broad awareness module again for all employees at the…
Re-running the same broad awareness module for all employees in a single mass deployment ignores the exhibit's evidence that different departments respond differently to tailored phishing lures, such as finance receiving invoice-based bait and IT receiving credential-reuse bait. A generic, one-size-fits-all session does not align with each role's real threat model, and scheduling it for everyone at the same time prevents the security team from measuring which departments improve under specific training. It also lacks recurring, interval-based reinforcement and built-in reporting practice, so any short-term knowledge gain will decay without retention checks or measurable indicators like click rates and report rates over time.
Send a company-wide reminder to never click links in email, regardless of sender.
Why wrong: A company-wide reminder treats phishing as a simple binary 'do not click' rule, which fails against attacker techniques like display-name spoofing and lookalike domains that mimic legitimate senders. It also provides no concrete workflow for verification or reporting, and because the exhibit shows repeated role-specific lure patterns, a generic email will soon be ignored or forgotten. Without teaching users to inspect URLs, verify via out-of-band channels, or report suspicious messages, this measure offers only a false sense of security.
B
Focus only on punitive action for users who failed the simulation.
Why wrong: Punitive action for simulation failures creates a climate of fear and blame, which discourages users from reporting real phishing attempts because they worry about disciplinary consequences for clicking a legitimate-looking link. It also does nothing to address the underlying susceptibility to job-themed lures that the exhibit highlights; employees who clicked are simply penalized rather than taught to recognize red flags like urgency, mismatched domains, or unusual requests. This approach reduces incident visibility for the security team, as users will hide mistakes instead of sending suspicious emails to the SOC for analysis, ultimately increasing organizational risk.
C
Run the same broad awareness module again for all employees at the same time.
Why wrong: Re-running the same broad awareness module for all employees in a single mass deployment ignores the exhibit's evidence that different departments respond differently to tailored phishing lures, such as finance receiving invoice-based bait and IT receiving credential-reuse bait. A generic, one-size-fits-all session does not align with each role's real threat model, and scheduling it for everyone at the same time prevents the security team from measuring which departments improve under specific training. It also lacks recurring, interval-based reinforcement and built-in reporting practice, so any short-term knowledge gain will decay without retention checks or measurable indicators like click rates and report rates over time.
D
Deploy role-based phishing training, recurring simulations, and a simple reporting workflow.
The metrics show that departments with the most realistic, job-specific lures are clicking more often and reporting less frequently. Role-based training addresses the exact patterns employees encounter, while recurring simulations let the security team measure improvement over time. A clear reporting workflow also increases the chance that suspicious messages reach security quickly for validation and containment.
What does the SY0-701 exam test about Security Program Management and Oversight?
Security Program Management & Oversight covers the governance, risk management, compliance, and business continuity aspects of cybersecurity—how to plan, implement, and improve an organization's security program.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Security Program Management and Oversight questions in a focused session?
Yes — the session launcher on this page draws every question from the Security Program Management and Oversight domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SY0-701 topics?
Use the topic links above to move to related areas, or go back to the SY0-701 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SY0-701 exam covers. They are not copied from any real exam or dump site.
▸Confusing policy vs. procedure: a policy is high-level intent, a procedure is step-by-step; exam may ask which document defines 'acceptable use' (policy) vs. 'how to reset a password' (procedure)
▸Mixing up risk treatment options: avoid (eliminate activity), transfer (buy insurance), mitigate (add controls), accept (acknowledge risk); candidates often pick 'mitigate' when 'avoid' is correct for a high-risk scenario
▸Forgetting that compliance is not the same as security: a company can be compliant with a regulation but still have poor security; exam may present a scenario where a compliant organization is breached and ask what's missing (e.g., risk assessment beyond compliance)
▸Misinterpreting RTO vs. RPO: RTO is time to restore service, RPO is acceptable data loss; exam might describe a backup strategy and ask which metric it satisfies