5.0 Security Program Management and Oversight SY0-701 Practice Quiz
447 exam-style questions covering 20% of the SY0-701 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA Security+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
What is a business continuity policy and what key elements must it contain to provide effective governance for the continuity planning program?
- A. Business continuity is an IT function, a BCP policy is a technical document covering only system recovery
- B. A business continuity policy establishes the organization's commitment to maintaining essential business operations during and after disruptive events. Business continuity is broader than IT disaster recovery, it encompasses all critical business functions including operations, communications, HR, and financial operations. Key elements: (1) Scope and purpose, which business units, processes, and geographic locations are within scope; what types of disruptions the program addresses (natural disaster, cyber incident, pandemic, supply chain disruption); (2) Executive commitment, statement of executive leadership's commitment to maintaining operations and investing in continuity capabilities; (3) Roles and responsibilities, who is responsible for developing, maintaining, and activating BCPs; Business Continuity Manager role, departmental BCP owners, executive decision authority for plan activation; (4) Business Impact Analysis (BIA) requirement, mandate that the organization conducts a BIA to identify critical business processes, their dependencies, and the impact of disruptions; (5) Recovery objectives, policy-level commitment to meeting specific Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for critical functions; (6) Testing requirements, frequency and type of continuity testing required (tabletop exercises, functional tests, full-scale exercises); (7) Plan maintenance, frequency of plan reviews and updates; triggers for unscheduled review (significant organizational change, actual activation, test findings)
- C. A business continuity policy is identical to a disaster recovery plan, both address the same scope
- D. Business continuity policies are optional, organizations respond to disruptions without prior planning
Scope and purpose, executive commitment, roles and responsibilities, BIA requirement, recovery objectives (RTO/RPO), testing requirements, and plan maintenance requirements are the key elements of an effective business continuity policy. This is the correct answer.
What is the difference between a disaster recovery (DR) policy and a business continuity policy (BCP) and what specific elements must a DR policy address?
- A. Disaster recovery policy and business continuity policy are interchangeable terms, both refer to the same document and scope
- B. Business Continuity Policy (BCP): broad scope covering all critical business operations during any disruption, encompasses people, processes, facilities, and technology; addresses how the organization maintains essential business functions regardless of recovery technology. Disaster Recovery Policy (DR): specific scope focused on restoring IT systems, data, and technology infrastructure after a disruptive event, a subset of the broader BCP addressing technical recovery specifically. DR policy-specific elements: (1) Scope definition, which IT systems, applications, and data are within DR scope; typically classified as Tier 1 (critical), Tier 2 (important), Tier 3 (standard) with different recovery obligations; (2) Recovery objectives, specific RTO and RPO for each system tier; these drive technical architecture choices; (3) DR site requirements, requirement for maintaining a secondary recovery facility or cloud-based recovery; defines the type of site (hot, warm, cold) required for each system tier; (4) Backup requirements, frequency, retention period, and storage location requirements; offsite or cloud storage requirements; (5) Testing requirements, frequency and type of DR testing; specific requirement that restoration from backup is actually tested (not just that backups exist); (6) Documentation requirements, requirement for up-to-date DR runbooks for each critical system; (7) DR team roles, who is responsible for executing DR procedures
- C. A DR policy is the same as an incident response policy, both address how to respond to adverse events
- D. DR policies are unnecessary, cloud providers guarantee availability eliminating the need for DR planning
DR policy-specific elements include scope and system tier definition, RTO and RPO for each tier, DR site requirements (hot/warm/cold), backup frequency and retention with tested restoration, documentation requirements, and DR team role definitions. This is the correct answer.
An organization has formal information security policies but no accompanying guidelines. Employees frequently ask the security team how to apply policies to specific situations. What is the relationship between guidelines and policies and what security value do guidelines provide?
- A. Guidelines replace policies, organizations should use guidelines instead of formal policies
- B. Guidelines and policies serve complementary but distinct functions. Policies are formal mandatory statements defining what must be done, they carry organizational authority. Guidelines are recommended non-mandatory guidance explaining how to implement policies in specific contexts. Security value of guidelines: (1) Bridge the abstraction gap, policies use general language; guidelines provide specific implementation advice for particular technologies, roles, or scenarios; (2) Reduce security team burden, employees who can self-serve from well-written guidelines contact the security team less frequently; (3) Enable consistent implementation, without guidelines different teams implement the same policy differently; guidelines produce consistent security posture; (4) Accommodate realistic scenarios, guidelines can address situations where strict policy application is impractical while explaining the acceptable approach; (5) Training support, guidelines serve as practical training materials explaining both what to do and why; Example: A password policy requires strong passwords; a password guideline explains how to create memorable strong passphrases, which password manager to use, and what to do when a system doesn't support the minimum length
- C. Guidelines are identical to procedures, both provide step-by-step instructions for completing tasks
- D. Guidelines are unnecessary if policies are clearly written, employees should interpret policies directly
Guidelines provide recommended implementation advice bridging the gap between mandatory policy requirements and specific practical situations, reducing security team burden, enabling consistent implementation, and supporting training. This is the correct answer.
A startup with 200 employees has grown from 10 employees in 18 months and has only a one-page information security policy. The CISO is tasked with developing a comprehensive information security policy program. What policy areas must a comprehensive program cover?
- A. A single comprehensive information security policy covers all security topics, separate policies create fragmentation
- B. Comprehensive information security policy program structure: A mature policy program uses a hierarchical structure with a top-level Information Security Policy establishing the overall framework and domain-specific sub-policies addressing each area. Required policy areas: (1) Information classification and handling, data classification levels, handling requirements, labeling, transmission, storage, and disposal; (2) Access control, how access is granted, reviewed, and revoked; least privilege, role-based access, privileged access; (3) Acceptable use, appropriate use of corporate computing resources; (4) Asset management, hardware and software inventory, lifecycle management, secure disposal; (5) Incident response, how incidents are identified, reported, and handled; (6) Business continuity and disaster recovery, maintaining operations during disruptions; (7) Change management, how changes to systems are controlled and approved; (8) Vendor and third-party management, security requirements for suppliers and service providers; (9) Physical and environmental security, protection of facilities and equipment; (10) Cryptography and key management, when and how encryption is applied; (11) Network security, architecture, perimeter controls, monitoring; (12) Software development security, secure development lifecycle, code review, testing; (13) Human resources security, pre-employment screening, training, termination procedures; (14) Compliance, regulatory and contractual security obligations
- C. Only technical controls require documentation, administrative policies are unnecessary in a technology-focused startup
- D. Create policies for every conceivable scenario, comprehensive coverage requires hundreds of individual policies
Information classification, access control, acceptable use, asset management, incident response, business continuity/DR, change management, vendor management, physical security, cryptography, network security, SDLC, HR security, and compliance are the required policy areas for a comprehensive information security policy program. This is the correct answer.
An organization's business continuity policy sets an RTO of 4 hours for all critical systems. After a major ransomware incident the organization discovers that actually recovering critical systems within 4 hours is technically impossible given their backup and recovery architecture. What does this gap reveal?
- A. RTO commitments in policy are aspirational, actual recovery times are expected to exceed policy targets
- B. What this gap reveals: (1) Policy without validation, the 4-hour RTO was set as a policy requirement without validating whether the current backup and recovery architecture can actually achieve it; policy commitments that cannot be met create false assurance; (2) Untested BCP, the gap was discovered during an actual incident rather than in testing; BCP testing specifically exists to discover these gaps before a real disruption; (3) Architecture-policy misalignment, the recovery architecture was not designed or validated against the policy's RTO requirement. Remediation options: (1) Improve the recovery architecture to meet the existing RTO, implement warm standby systems, improved backup infrastructure, automated recovery runbooks, pre-staged recovery environments; this may require significant investment; (2) Update the policy to reflect realistic achievable RTOs, if 4-hour recovery is not achievable with practical investment, revise the RTO to what is achievable with current or near-term architecture; set a phased improvement roadmap with interim RTOs; (3) Stratify RTOs by system tier, critical systems have a 4-hour RTO supported by architecture; important systems have an 8-hour RTO; standard systems have a 24-hour RTO; each tier validated against its architecture; (4) Conduct regular BCP testing, implement annual minimum testing where recovery from backup is actually performed; the 4-hour clock is started and actual recovery time measured
- C. The policy is correct, the organization must improve its technology to meet the policy requirement
- D. The RTO gap is acceptable, actual recovery times always exceed policy targets during real incidents
The gap reveals policy-without-validation, untested BCP, and architecture-policy misalignment, remediation through improved recovery architecture, realistic RTO revision, tiered RTOs, or mandatory recovery testing addresses each failure. This is the correct answer.
A security team is creating guidelines for remote work security. The organization's Information Security Policy mandates that sensitive data must be protected from unauthorized access. The guideline must translate this into actionable advice for home offices, hotels, and coffee shops. What elements make this guideline effective?
- A. A guideline only needs to restate the policy requirement, employees are responsible for finding their own implementation approach
- B. Elements making a remote work security guideline effective: (1) Context-specific scenarios, the guideline addresses each distinct environment: home office (dedicated work device, no family access to work systems), hotel (VPN required before accessing corporate resources, no work on hotel-provided computers, screen privacy filter in shared spaces), coffee shop (avoid accessing sensitive data, VPN required, Bluetooth disabled); generic advice doesn't address the different risk profiles of each location; (2) Specific and actionable language, 'Use the corporate VPN when outside the office' is actionable; 'protect data appropriately' restates the policy without adding value; (3) Technology-specific guidance, which VPN client to use and how to connect, which approved tools are acceptable for video calls, how to verify a Wi-Fi network is genuine vs. an evil twin; (4) What to do when the ideal is not possible, the guideline addresses realistic scenarios: if you must access email on an untrusted network with no VPN available, what is acceptable and what is not; (5) Examples of compliant and non-compliant behavior, 'Do: use headphones for calls in public. Do not: speak sensitive information aloud in coffee shops'; (6) Contact information for questions, who to contact when a situation is not covered; (7) Risk explanation, briefly explaining why each guidance item matters increases employee compliance
- C. Guidelines must be legally binding to be effective, non-mandatory guidance is ignored
- D. The guideline should be as short as possible, employees do not read long guidelines
Context-specific scenarios for each work location, actionable specific language, technology-specific implementation guidance, advice for non-ideal scenarios, compliant and non-compliant examples, contact information, and risk explanation make a remote work security guideline effective. This is the correct answer.
An organization's security guidelines have not been updated in 4 years. New technologies (cloud services, mobile devices, AI tools) are in use but not addressed in any guideline. Employees are making individual security decisions without guidance. What governance process ensures guidelines remain current and what are the risks of outdated guidelines?
- A. Outdated guidelines are better than no guidelines, any guidance is preferable to none
- B. Governance process for guideline currency: (1) Annual review cycle, assign each guideline a designated owner responsible for annual review; (2) Technology change trigger, new technologies introduced to the organization trigger guideline review or development; the IT acquisition process should include a security team notification step; (3) Incident-triggered review, when an incident occurs involving a guideline-covered area review whether the guideline contributed or would have prevented it; (4) Regulatory change trigger, when compliance requirements change guidelines covering affected areas are reviewed; (5) Version control and changelog, guidelines maintained in a versioned document management system. Risks of outdated guidelines: (1) Security decision vacuum, employees making individual security decisions about new technologies create wildly inconsistent security postures; (2) Policy interpretation errors, a 4-year-old guideline may conflict with the current policy creating confusion; (3) Shadow IT normalization, without guidance on cloud services and AI tools employees may use unapproved tools creating data exposure not knowing the approved alternative; (4) Audit findings, regulatory auditors reviewing guidelines that don't address technologies in production use identify governance gaps; (5) Liability exposure, if an employee causes a breach using an AI tool and no guidance existed about AI tool use the absence of guidance may be cited as a governance failure
- C. Assign all guideline ownership to the CISO, centralized ownership ensures consistent updates
- D. Replace all guidelines with a single comprehensive document, fewer documents are easier to keep current
Annual review cycles with designated owners, technology change triggers, incident-triggered reviews, regulatory change triggers, and version control maintain currency, while security decision vacuums, policy conflicts, shadow IT normalization, audit findings, and liability exposure result from outdated guidelines. This is the correct answer.
An employee is terminated after investigation reveals they used corporate computing resources to operate a side business. The employee argues no policy explicitly prohibited this specific use. The AUP states corporate resources are to be used 'primarily for company business.' How should the AUP be evaluated and updated?
- A. The employee's defense is valid, if the AUP doesn't explicitly prohibit a specific activity it is permitted
- B. AUP evaluation and update: Evaluating the current AUP: the 'primarily for company business' language is imprecise, 'primarily' creates ambiguity about what percentage of non-business use is acceptable; an employee could argue 80% business use with 20% for a side business satisfied the 'primarily' standard. Update approaches: (1) Replace ambiguous qualifiers with clear scope, instead of 'primarily for company business' state 'exclusively for company business purposes and other uses specifically authorized in writing'; 'exclusively' eliminates the ambiguity that 'primarily' creates; (2) Enumerate explicitly prohibited uses with non-exhaustive language, add a specific list: 'Prohibited uses include but are not limited to: operating a business or commercial enterprise, personal financial gain activities...'; non-exhaustive language prevents the 'not specifically listed' defense; (3) Non-exhaustive acknowledgment, include explicit language that the list of examples does not limit the scope of the prohibition; (4) Signed acknowledgment, require employees to read, acknowledge, and sign the updated AUP annually; eliminates 'I did not know' defenses; (5) Specific consequence statement, state that violations may result in disciplinary action up to and including termination
- C. Terminate the employee without updating the AUP, the current policy was sufficient
- D. Remove all AUPs, policy ambiguity creates more legal risk than having no policy
Replacing ambiguous qualifiers with exclusive scope statements, non-exhaustive specific prohibited use lists, signed annual acknowledgment, and specific consequence statements address the permissive interpretation gap. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-security-plus/security-program-management-and-oversight/
<a href="https://quizbuffet.com/comptia-security-plus/security-program-management-and-oversight/">CompTIA Security+ Security Program Management and Oversight practice quiz on QuizBuffet</a>
Other SY0-701 Domains
- 1.0 General Security Concepts
- 2.0 Threats, Vulnerabilities, and Mitigations
- 3.0 Security Architecture
- 4.0 Security Operations
← Back to SY0-701 practice test overview
Questions are written against the published SY0-701 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.