SY0-701 · CompTIA · Security Program Management and Oversight · Bank updated 2026-09-20
SY0-701 practice questions: Security Program Management and Oversight
5 free questions from 14 on this area · answer and explanation for each · no sign-up
These 5 questions come from the Security Program Management and Oversight section of our SY0-701 bank (14 questions on this area, which carries 20% of the real exam). Every question is original, with the correct answer explained and linked to the source it is drawn from.
1/5 · Security Program Management and Oversight
An insurer's data centre is destroyed by fire. While the technology is being restored at another site, claims handlers work from printed files and a call script agreed in advance, payments are authorised by two named managers instead of the usual workflow, and branches take new claims on paper. Which document commits the organisation to that way of working?
AThe business continuity policy
BThe disaster recovery policy
CThe incident response policy
DThe information security policy
Show answer & explanation
A is correct. Objective 5.1 lists acceptable use, information security, business continuity, disaster recovery, incident response, software development lifecycle and change management as the policies of a governance programme, and the pair most often collapsed into one is business continuity and disaster recovery. NIST SP 800-34 Rev. 1 draws the line explicitly: the business continuity plan focuses on sustaining the organisation's mission and business processes during and after a disruption, while the disaster recovery plan is an information system-focused plan designed to restore operability of the target system, application or computer facility at an alternate site, and addresses only disruptions that require relocation. Paper claim forms and a standing authorisation exception belong to the first; the servers at the other site belong to the second.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 5: Security Program Management and Oversight
2/5 · Security Program Management and Oversight
A directory team's account-creation walkthrough is the only place in the organisation where a minimum password length is written down. A second team builds accounts for a new application without using that walkthrough and sets shorter passwords. An auditor reviewing both sets of accounts reports that she has no requirement to test them against. Which change BEST closes the gap?
APublish the walkthrough to the second team
BRecord the length in a password standard
CState the intent in the information security policy
DIssue the length as a guideline for both teams
Show answer & explanation
B is correct. Objective 5.1 lists guidelines, policies, standards and procedures as distinct governance elements and names password and access control standards explicitly. The chain runs from intent to mandatory specifics to execution steps, with guidelines as optional advice alongside it. What the item turns on is what an auditor can measure: a value that exists only inside one team's procedure reaches only the people who follow that procedure, a value issued as advice binds nobody, and a statement of intent names no parameter to test, which leaves one artefact in the set that closes the gap.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 5: Security Program Management and Oversight
3/5 · Security Program Management and Oversight
A bank outsources card statement printing, which means handing account data to a supplier. Twice in the past year the bank's risk team has asked to test a specific control at the supplier's premises, and twice the supplier has declined. The bank is preparing the next agreement and wants the same request to succeed under it. Which provision delivers that?
AAn independent assessment the bank commissions
BA right-to-audit clause in the agreement
CA contractual promise of assessment reports
DAn annual security questionnaire from the supplier
Show answer & explanation
B is correct. Objective 5.3 lists penetration testing, right-to-audit clause, evidence of internal audits, independent assessments and supply chain analysis under vendor assessment, alongside the agreement types. Two of these options are written into the agreement and two are not, and being written in is not by itself the answer: a promise to deliver reports obliges the supplier to send the output of work that somebody else scoped, while the clause entitles the bank's own people to test a control of their choosing on the supplier's premises. That is also why it is negotiated before signature and cannot be added by request afterwards.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 5: Security Program Management and Oversight
4/5 · Security Program Management and Oversight
The rules of engagement for an external test give the testing firm one week in which nothing it does may appear in the client's own logs. The client wants an initial picture of its internet exposure built during that week. Which activity fits inside it?
ARequesting a full copy of the zone from its server
BResolving each published address back to a name
CReading certificate transparency and WHOIS entries
DCollecting service and version banners from each host
Show answer & explanation
C is correct. Objective 5.5 lists reconnaissance with passive and active variants under penetration testing. All four options here look like looking rather than probing, which is the point of the item: the line is not how aggressive an activity feels but whose infrastructure answers it. NIST SP 800-115 draws the same boundary for network discovery - passive techniques observe without generating traffic to the target, while active techniques send packets and therefore appear in the target's own logs. A query a client's nameserver, resolver or web host answers is active, however gentle it looks.
↗ CompTIA Security+ SY0-701 Exam Objectives - Domain 5: Security Program Management and Oversight
5/5 · Security Program Management and Oversight
A new training module is built around three short cases: a colleague copying the full client list to a personal drive before a holiday, a finance mailbox that has begun forwarding a copy of every message to an outside address, and a clerk who attaches the wrong spreadsheet to an external email and notices afterwards. Staff are taught to notice each situation and whom to tell. Which awareness element does this module implement?
AAnomalous behavior recognition
BOperational security
CSituational awareness
DPolicy and handbook familiarization
Show answer & explanation
Other SY0-701 areas
The same kind of free sample for every other section of the SY0-701 bank:
Study Security Program Management and Oversight with instant feedback
6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.
Create your free account →
ExamDeck is an independent study tool, not affiliated with, endorsed by, or sponsored by CompTIA. SY0-701 and related marks are trademarks of their respective owners, used for identification only. Exam facts checked against official CompTIA materials (as of September 2026); always confirm current details with the vendor before booking.