Free Security+ Security Program Management and Oversight practice test questions
8 questions from this domain with answers and explanations - different from the samples on the main CompTIA Security+ SY0-701 page. Sign up free to practice the full set.
-
Which of the following BEST describes the concept of data sovereignty?
- AThe requirement that data is subject to the laws of the country where it is storedCorrect
- BThe practice of encrypting all data at rest and in transit
- CThe practice of maintaining multiple copies of data for redundancy
- DThe process of classifying data based on its sensitivity level
✓ Correct answer: AData sovereignty is correct because it specifically concerns which country's laws and regulatory authority govern data based on the physical location where that data is stored, which is exactly what option A describes. This matters heavily for multinational organizations and cloud providers, because storing data in a given country can subject it to that country's search warrants, disclosure requirements, and privacy law, such as the EU's GDPR restricting where personal data of EU residents may reside. Architects must therefore choose data-center regions deliberately, sometimes duplicating infrastructure per jurisdiction, to keep regulated data under the correct legal authority. The closest distractor, encrypting data at rest and in transit, is a technical protection measure and says nothing about which nation's laws apply to the data; a fully encrypted dataset stored in the wrong jurisdiction still violates data sovereignty requirements. Classification and redundancy address different governance and availability concerns entirely.
Why the other options are wrong- BEncrypting data everywhere is a protection technique, not a matter of legal jurisdiction over the data.
- CKeeping redundant copies describes data redundancy or backup, which supports availability rather than jurisdiction.
- DClassifying data by sensitivity is data classification, a separate governance activity from sovereignty.
-
An organization wants to evaluate the security practices of its cloud service provider before signing a contract. Which of the following would be MOST useful for this assessment?
- AThe provider's employee handbook
- BA SOC 2 Type II audit reportCorrect
- CThe provider's marketing brochure
- DThe provider's annual financial report
✓ Correct answer: BA SOC 2 Type II report is issued by an independent CPA firm that audits a service organization's controls against the AICPA Trust Services Criteria over an extended period, typically six to twelve months, providing evidence that security controls were both properly designed and operating effectively over time rather than assessed at a single point. This sustained, independently verified evidence makes it the most meaningful document for evaluating a prospective cloud provider's security maturity before signing a contract, since it comes from an outside auditor rather than the provider describing itself. An employee handbook addresses internal HR policy, a marketing brochure is unverified self-promotion, and a financial report discloses business performance; none of these three provide any evidence about whether the provider's security controls actually protect customer data.
Why the other options are wrong- AAn employee handbook describes internal HR policy and workplace conduct; it provides no evidence of security control effectiveness or compliance.
- CA marketing brochure is unverified, self-promotional content produced by the provider and cannot substitute for independently audited security evidence.
- DAn annual financial report discloses revenue and business performance; it reveals nothing about the adequacy of security controls protecting data.
-
A prospective enterprise customer asks a SaaS vendor for an assurance report that demonstrates its security controls operated effectively across the past six months, not just on one day. Which report BEST satisfies this request?
- ASOC 2 Type I report
- BSOC 2 Type II reportCorrect
- CSOC 1 report
- DPenetration test summary
✓ Correct answer: BA SOC 2 Type II engagement tests whether a service organization's controls were both appropriately designed and operating effectively over an extended review period, typically six to twelve months, which is exactly the sustained evidence the prospective customer is asking for rather than a snapshot from a single day. A SOC 2 Type I report, by contrast, only attests to control design at one point in time and says nothing about whether those controls actually functioned correctly over an extended period. A SOC 1 report focuses specifically on controls relevant to financial reporting rather than general security operations, and a penetration test summary reflects a point-in-time technical assessment of exploitable vulnerabilities rather than an ongoing attestation of control operating effectiveness across months of activity.
Why the other options are wrong- AA SOC 2 Type I report attests only to control design at a single point in time, not sustained operating effectiveness.
- CA SOC 1 report addresses controls relevant to financial reporting, not general security operating effectiveness over time.
- DA penetration test summary reflects a point-in-time technical assessment, not an ongoing attestation of control effectiveness across months.
-
What is the purpose of a data classification policy?
- ATo categorize data by sensitivity and set handling rulesCorrect
- BTo automatically delete all data older than one calendar year
- CTo convert all organizational data to a standard format
- DTo encrypt all organizational data by default at rest
✓ Correct answer: AOption A is correct because a data classification policy establishes sensitivity tiers, such as Public, Internal, Confidential, and Restricted, and prescribes the handling requirements for each tier, including who may access the data, how it must be stored and transmitted, whether encryption is required, and how it must be securely disposed of. Mapping every information asset to a tier ensures that controls are applied proportionately to actual sensitivity rather than uniformly, which is the policy's core purpose. This is distinct from option B, a retention policy, which sets how long data is kept rather than how sensitive it is; option C, a format-conversion concern unrelated to security; and option D, blanket encryption, which classification scopes selectively rather than mandating universally.
Why the other options are wrong- BAutomatically deleting data older than one year describes a data retention policy's retention schedule, not classification by sensitivity.
- CConverting all organizational data to a standard format is a data-management interoperability concern, entirely separate from security classification.
- DMandating encryption for all data by default is overly broad; classification identifies which specific categories require encryption rather than applying it universally.
-
A company outsources its email hosting to a cloud provider. The provider experiences a data breach that exposes the company's confidential emails. Who is ultimately responsible for the protection of the company's data?
- AThe cloud provider exclusively
- BNeither party is responsible
- CThe company (data owner) retains ultimate responsibilityCorrect
- DThe government regulatory body overseeing that industry's data protection laws
✓ Correct answer: COption C is correct because under the shared responsibility model, and under regulations like GDPR, the data owner or controller always retains ultimate accountability for the protection of its data, even when a cloud provider processes or hosts it on the company's behalf. Outsourcing purchases a service, it does not transfer legal or regulatory responsibility, which is why vendor due diligence, contractual security requirements, and ongoing monitoring of the provider remain the company's obligation both before and after a breach occurs. This is why option A, holding the provider exclusively responsible, is wrong: the provider bears only the portion of responsibility defined in the contract, while the data owner cannot fully offload accountability, and options B and D misplace or omit accountability entirely.
Why the other options are wrong- AThe cloud provider is only responsible for the portion of security defined in the contract or shared responsibility model; ultimate accountability for the data cannot be fully transferred away from its owner.
- BBoth parties hold defined responsibilities under contract and regulation; accountability for protecting the data is always assigned to someone, not left unowned by either party.
- DA regulatory body enforces compliance and can impose penalties after the fact, but it does not itself bear responsibility for protecting the organization's outsourced data.
-
A CISO is establishing security oversight through governance structures. Which TWO of the following are recognized governance structure models used to direct and oversee a security program? (Choose two.)
- ABoard of directors providing strategic oversightCorrect
- BA government regulatory body enforcing privacy law
- CSteering committees coordinating cross-departmental decisionsCorrect
- DAn automated SIEM correlation rule
✓ Correct answer: A, CBoards of directors and steering committees are both recognized internal governance structures because they provide human oversight bodies that set strategic direction, approve policy, allocate resources, and coordinate cross-departmental security decisions, ensuring the security program stays aligned with business objectives and risk appetite. A board typically operates at the highest strategic level, reviewing enterprise risk and holding executives accountable, while a steering committee operates more tactically, bringing together stakeholders from IT, legal, HR, and business units to prioritize initiatives. Neither of the other options is a governance body: one is an external party enforcing law from outside the organization, and the other is an automated technical control that detects threats rather than directing the program.
Why the other options are wrong- BA government regulatory body enforces external legal and compliance requirements on the organization; it is an outside authority the organization must answer to, not an internal governance structure.
- DA SIEM correlation rule is an automated technical detection mechanism that flags suspicious activity; it is a security tool, not a human governance body that sets direction or oversight.
-
When litigation is anticipated, an organization must suspend its routine data-destruction schedule to preserve potentially relevant information. What is this obligation called?
- AA legal hold (litigation hold)Correct
- BData classification
- CData minimization
- DThe right to be forgotten
✓ Correct answer: AA legal hold, or litigation hold, is a formal directive that suspends an organization's routine data-retention and destruction schedules the moment litigation is reasonably anticipated, whether or not a lawsuit has actually been filed yet, so that any information potentially relevant to that matter is preserved rather than automatically purged on schedule. Failing to issue or honor a legal hold can lead to spoliation of evidence, which courts can sanction severely, including adverse-inference instructions to a jury or monetary penalties. Data classification instead labels information by sensitivity level to guide handling, unrelated to preserving records for litigation. Data minimization pushes in the opposite direction, limiting how much data is collected and retained in the first place. The right to be forgotten grants individuals a right to request deletion, which would directly conflict with a hold's preservation requirement.
Why the other options are wrong- BData classification labels information by sensitivity to guide handling and protection; it does not preserve records specifically for anticipated litigation.
- CData minimization limits how much data is collected and retained in the first place, the opposite emphasis from a hold's requirement to preserve existing data.
- DThe right to be forgotten lets individuals request deletion of their personal data, which would directly conflict with a hold's preservation requirement rather than describe it.
-
A healthcare clinic stores patient names, diagnoses, and treatment histories together with the credit cards used to pay for visits. A security analyst is categorizing the data. Which statement correctly distinguishes the categories present?
- ADiagnoses and treatment histories are PHI, while the stored credit card numbers are PCI cardholder dataCorrect
- BAll of the stored data is broadly classified as PII, and none of it separately qualifies as protected PHI
- CThe credit card numbers count as PHI, because they are recorded within the patient's medical record file
- DThe diagnoses are treated as PCI cardholder data, since they directly influence the visit's billing amount
✓ Correct answer: AProtected health information covers individually identifiable health data such as diagnoses and treatment histories, and it is regulated under HIPAA regardless of what other data sits alongside it in the same record. Payment card numbers are separately governed by the PCI DSS standard, which applies to cardholder data wherever it is stored, processed, or transmitted, and that classification does not change simply because the card number happens to be filed next to a medical record for billing convenience. Personally identifiable information is a broader umbrella term that both PHI and cardholder data can fall under in a general sense, but PII is not itself a regulatory category with its own distinct compliance regime the way HIPAA and PCI DSS are, so calling everything just PII glosses over the specific protections each data type actually requires.
Why the other options are wrong- BHealth diagnoses and treatment histories are specifically PHI under HIPAA, so it is incorrect to claim none of the stored data separately qualifies as protected PHI.
- CA credit card number does not become PHI merely by physical or logical proximity to a medical record; it remains PCI cardholder data governed by PCI DSS.
- DDiagnoses are clinical PHI regardless of how they affect billing; influencing the charge amount does not reclassify health information as payment card data.
How Security Program Management and Oversight is tested
This domain holds 188 of the 990 questions in the Security+ bank, about 19%. The mix is 160 single-answer multiple choice and 28 multiple-response, so it is worth practising the formats as well as the content.
Once you have a few attempts recorded, CertGrid scores every domain separately and points you at the weakest one, so you can drill Security Program Management and Oversight on its own rather than re-running full-length mocks.
Other Security+ exam domains
- General Security Concepts125 questions
- Threats, Vulnerabilities, and Mitigations216 questions
- Security Architecture176 questions
- Security Operations285 questions
- All Security+ practice questions990 total
- Security Program Management and Oversight study notesKey concepts
- Security practice examsAll Security
Security+ Security Program Management and Oversight FAQ
How many Security+ practice questions are there on Security Program Management and Oversight?
CertGrid has 188 Security+ practice questions mapped to Security Program Management and Oversight, which is about 19% of the 990-question Security+ bank. Every one carries a full explanation covering why the right answer is right and why each wrong option is wrong.
Can I practice only the Security Program Management and Oversight domain?
Yes. Inside CertGrid you can run a focused drill on a single exam objective rather than the whole bank, and the app picks your weakest domain automatically once you have attempts to measure. The button on this page starts a Security Program Management and Oversight drill directly.
How is Security Program Management and Oversight tested on the Security+ exam?
In this bank the domain is made up of 160 single-answer multiple choice and 28 multiple-response questions, and it accounts for roughly 19% of the practice pool. Mapping follows the current published exam objectives; CertGrid is an independent practice platform and these are not official exam questions.
What CertGrid is (and is not)
CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.
Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by CompTIA. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.