SY0-701 - Security Program Management and Oversight (20% of the exam) - Section 5.1

Summarize elements of effective security governance.

Describe how policies, standards, and procedures form a hierarchy that translates executive direction into operational security behaviour, and how governance structures assign clear roles and responsibilities across the organisation. Recognise how regulatory considerations shape governance requirements, and distinguish the board-level accountability function of governance from the day-to-day management of security operations.

policiesstandards and proceduresgovernance structuresroles and responsibilitiesregulatory considerations

Practice question for this objective

Free sampleSecurity Program Management and Oversightmedium

A regional building society has appointed a compliance lead and must prepare for an external auditor who will judge whether the firm's security compliance programme is effective. The lead has a long list of candidate activities and must distinguish elements that directly evidence effective security compliance from operational security tasks that, while useful, do not by themselves demonstrate compliance to the auditor. Which TWO activities most directly constitute elements of effective security compliance? Select TWO.

  • AProducing a periodic attestation that an independent party signs, formally stating that the in-scope controls were designed and operating effectively across the review window. Correct
  • BOperating a documented data retention schedule that defines how long each record class is kept and triggers verifiable, logged destruction once the legally required period expires. Correct
  • CDeploying an inline intrusion prevention sensor at the perimeter so that known exploit signatures are dropped before they reach the application servers in scope.
  • DRotating the data encryption keys protecting the backup repository every ninety days so that a stolen key cannot decrypt records captured in an earlier window.
  • ERunning a quarterly simulated phishing campaign and publishing the click-through rate so that staff susceptibility is tracked against the previous quarter.
Effective security compliance is evidenced by elements such as attestation and data retention, distinct from operational technical controls and awareness activities. Security compliance is demonstrated through programme elements that produce auditable evidence: attestation gives an independent, signed statement of control effectiveness over a period, and a data retention schedule with logged destruction proves records are held only for the legally required time. Technical controls and awareness exercises support security but do not by themselves evidence compliance.

Why A is correct: Attestation is a named element of effective security compliance: a signed statement of control effectiveness over a period is exactly the independent evidence an external auditor relies on.

Why B is correct: Data retention is a core compliance element; a documented schedule with logged destruction proves the firm holds records only as long as the law allows, which auditors check directly.

Why C is wrong: An IPS is a worthwhile technical mitigation and may sit within scope, but it is an operational control, not an element of the compliance programme itself, so it does not demonstrate compliance.

Why D is wrong: Key rotation is sound cryptographic hygiene and tempting to list, but it is a technical control activity rather than a compliance element such as attestation, reporting, or retention.

Why E is wrong: Phishing simulation belongs to security awareness, not the compliance programme; it measures behaviour and is tempting, but it is not the compliance evidence an auditor assesses.

See more SY0-701 practice questions, answers explained.

Exam traps in Security Program Management and Oversight

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • A board-approved information security policy that states the firm will respond to ransomware in a timely and proportionate manner.

    Why it is wrong: A policy expresses managerial intent and accountability at a high level; it does not prescribe the ordered operational steps responders need, which is exactly the gap the incident review surfaced.

  • Regulations replace the organisation's internal policies wholesale, so once a sector regulator publishes its handbook the firm no longer needs its own information security policy set.

    Why it is wrong: Regulations are inputs that internal policies must reflect, not substitutes for them, because each organisation still needs context-specific direction for its own systems and staff, so wholesale replacement misreads the relationship.

  • The board writes the technical configuration baselines for systems, while the chief information security officer reviews them quarterly for board sign-off.

    Why it is wrong: Boards do not author technical baselines, which are operational artefacts produced by security and engineering teams, so this misallocates a task that belongs well below board level.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.