SY0-701 - Security Operations (28% of the exam) - Section 4.2

Explain the security implications of proper hardware, software, and data asset management.

Describe how maintaining an accurate asset inventory, assigning clear ownership, and following secure acquisition and procurement practices reduce the risk of unmanaged or shadow assets. Explain why secure disposal and data sanitisation are the final critical step, recognising that improperly decommissioned hardware can expose sensitive data even after an asset leaves the organisation.

acquisition/procurementasset inventoryownershipsecure disposaldata sanitization

Practice question for this objective

Free sampleSecurity Operationseasy

Which statement best describes the primary security purpose of maintaining a complete and accurate hardware and software asset inventory in an enterprise?

  • AIt records the purchase price of each device so that finance can calculate annual depreciation for the company accounts.
  • BIt gives the security team a definitive list of what must be protected, patched, and monitored, so that no system is missed during vulnerability and incident response activities. Correct
  • CIt replaces the need for a separate configuration management database by storing the running configuration of every device in a single shared spreadsheet.
  • DIt allows users to self-register any device they bring from home so that the helpdesk can ship support tickets directly to the device owner.
Recognise that an accurate asset inventory is the foundation for protecting, patching, and monitoring every system the organisation owns. Security controls such as patching, vulnerability scanning, monitoring, and incident response can only be applied to assets that defenders know about. A complete and accurate inventory of hardware and software ensures that no system falls outside coverage, which is why frameworks consistently list inventory as a foundational control.

Why A is wrong: Tracking depreciation is a finance and accounting outcome, not the security purpose of an asset inventory, so this misframes the control even though inventories often feed cost reporting.

Why B is correct: An accurate inventory is the foundation for protecting, patching, and monitoring assets, because controls cannot be applied to systems that defenders do not know exist.

Why C is wrong: Inventories list assets and their owners, not full running configurations, and they complement a configuration management database rather than replacing it, so this overstates the inventory's role.

Why D is wrong: Self-registration of personal devices is a bring-your-own-device workflow, not the security purpose of an enterprise asset inventory, which exists to give defenders authoritative coverage of corporate assets.

See more SY0-701 practice questions, answers explained.

Exam traps in Security Operations

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • Acquisition is primarily a financial process, so security teams should only become involved once new equipment has been delivered and is ready to be configured for production use.

    Why it is wrong: Treating acquisition as a finance-only activity defers security input until risks such as supplier integrity and built-in defaults are already locked in, which is exactly the failure pattern this control category addresses.

  • They make sure that retired hardware is collected by an external waste contractor on a published schedule, so that no equipment is left in storerooms for more than ninety days.

    Why it is wrong: Timely collection by a waste contractor is a logistics concern; on its own it does not address the risk that residual data on the device could be recovered after disposal.

  • Cryptographically erase or degauss the internal drives before any user receives the laptop.

    Why it is wrong: This is tempting because sanitisation is a genuine asset management control, but it belongs to the secure disposal stage at end of life, not to intake of brand-new devices that hold no data yet.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.