CompTIA Security+ SY0-701 Security Governance Practice Test 1

 

Topic 23 Practice Test 1 covers Security Governance for CompTIA Security+ SY0-701 and maps to objective 5.1: Summarize elements of effective security governance. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

To ensure controls satisfy binding external rules, which security approach should be selected?

  1. Acceptable use policy
  2. Regulatory requirement
  3. Incident response policy
  4. Disaster recovery policy

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Regulatory requirement means a security obligation imposed by a government or regulatory authority. That makes it the best answer here; Disaster recovery policy addresses governance direction for restoring technology and services after a major disruption, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. The key mismatch is functional: Regulatory requirement addresses a security obligation imposed by a government or regulatory authority, the need stated by the question.

Answer C is incorrect because Incident response policy refers to governance direction defining authority, responsibilities, and expectations for handling security incidents. That concept can be valid in another scenario, but this question is testing a security obligation imposed by a government or regulatory authority; Regulatory requirement therefore fits the requirement more directly.

Answer D is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. That concept can be valid in another scenario, but this question is testing a security obligation imposed by a government or regulatory authority; Regulatory requirement therefore fits the requirement more directly.

 

Question 2

To provide high-level accountability and direction for organizational risk, which security approach should be selected?

  1. Board oversight
  2. Security procedure
  3. Regulatory requirement
  4. Data processor

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Board oversight means governance exercised by a board or equivalent senior governing body. The deciding point is functional fit: this option covers the stated need, while Data processor addresses an entity that processes personal data on behalf of a controller.

Incorrect Answers

 

Answer B is incorrect because Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards. The key mismatch is functional: Board oversight addresses governance exercised by a board or equivalent senior governing body, the need stated by the question.

Answer C is incorrect because Regulatory requirement refers to a security obligation imposed by a government or regulatory authority. The question is not asking for this function. It is testing governance exercised by a board or equivalent senior governing body, so Board oversight is the stronger fit.

Answer D is incorrect because Data processor refers to an entity that processes personal data on behalf of a controller. This could be appropriate elsewhere, but the required function is governance exercised by a board or equivalent senior governing body; that makes Board oversight the precise choice.

 

Question 3

The control set for a governance framework review must address both recommended practice that provides flexible guidance rather than a mandatory exact requirement and management-approved statement of required direction, expectations, and responsibilities. Which TWO choices map directly to those needs? Choose TWO.

  1. Industry requirement
  2. Security policy
  3. Playbook
  4. SDLC policy
  5. Security guideline

Correct Answers: B, E

Correct Answers

 

 

Answer B is correct because Security policy means management-approved statement of required direction, expectations, and responsibilities. The fixed-count item needs this function in the answer set. Industry requirement covers a security expectation arising from sector standards, contracts, or common industry frameworks, a different requirement.

Answer E is correct because Security guideline means recommended practice that provides flexible guidance rather than a mandatory exact requirement. One required function is exactly what this option provides. Playbook may be useful elsewhere, but it is used for a predefined set of response or operational actions for a known scenario.

Incorrect Answers

 

Answer A is incorrect because Industry requirement means a security expectation arising from sector standards, contracts, or common industry frameworks. The question requires exactly 2 selections: Security guideline, Security policy. This option falls outside that required set. For example, Security guideline is required for recommended practice that provides flexible guidance rather than a mandatory exact requirement.

Answer C is incorrect because Playbook means a predefined set of response or operational actions for a known scenario. The fixed-count answer set is Security guideline, Security policy; this option does not fill one of those named functions. For example, Security guideline is required for recommended practice that provides flexible guidance rather than a mandatory exact requirement.

Answer D is incorrect because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance. The required choices are Security guideline, Security policy. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 4

To guide teams through common security events with less improvisation, which security approach should be selected?

  1. Playbook
  2. Industry requirement
  3. Acceptable use policy
  4. SDLC policy

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Playbook means a predefined set of response or operational actions for a known scenario. The requirement maps directly to this function, whereas Industry requirement is aimed at a security expectation arising from sector standards, contracts, or common industry frameworks.

Incorrect Answers

 

Answer B is incorrect because Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks. The scenario instead requires a predefined set of response or operational actions for a known scenario, which is why Playbook is the better answer; this option serves the different function defined above.

Answer C is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. The question is not asking for this function. It is testing a predefined set of response or operational actions for a known scenario, so Playbook is the stronger fit.

Answer D is incorrect because SDLC policy refers to security requirements that apply across software planning, development, testing, release, and maintenance. The question is not asking for this function. It is testing a predefined set of response or operational actions for a known scenario, so Playbook is the stronger fit.

 

Question 5

Which term describes management-approved statement of required direction, expectations, and responsibilities?

  1. Security guideline
  2. Industry requirement
  3. Security policy
  4. Playbook

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Security policy means management-approved statement of required direction, expectations, and responsibilities. This matches the requirement as written. Industry requirement can be valid in another context, but it is used for a security expectation arising from sector standards, contracts, or common industry frameworks.

Incorrect Answers

 

Answer A is incorrect because Security guideline refers to recommended practice that provides flexible guidance rather than a mandatory exact requirement. That concept can be valid in another scenario, but this question is testing management-approved statement of required direction, expectations, and responsibilities; Security policy therefore fits the requirement more directly.

Answer B is incorrect because Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks. The concept is valid, but it does not match this stem. The required function is management-approved statement of required direction, expectations, and responsibilities, which maps to Security policy.

Answer D is incorrect because Playbook refers to a predefined set of response or operational actions for a known scenario. This could be appropriate elsewhere, but the required function is management-approved statement of required direction, expectations, and responsibilities; that makes Security policy the precise choice.

 

Question 6

An architect working on a governance framework review needs one capability that provides governance direction defining authority, responsibilities, and expectations for handling security incidents and another that provides entity that processes personal data on behalf of a controller. Which TWO selections are the best match? Choose TWO.

  1. Data processor
  2. Security committee
  3. Governance monitoring and revision
  4. Incident response policy
  5. Board oversight

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Data processor means an entity that processes personal data on behalf of a controller. It belongs in the fixed-count answer set because it covers one of the stated requirements. Governance monitoring and revision instead serves periodic review of policies and governance structures to keep them effective and current and cannot replace this function.

Answer D is correct because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents. It belongs in the fixed-count answer set because it covers one of the stated requirements. Governance monitoring and revision instead serves periodic review of policies and governance structures to keep them effective and current and cannot replace this function.

Incorrect Answers

 

Answer B is incorrect because Security committee means a cross-functional or specialized group that coordinates decisions, priorities, and oversight. The required choices are Incident response policy, Data processor. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because Governance monitoring and revision means periodic review of policies and governance structures to keep them effective and current. Every answer slot must map to a stated requirement. The correct set is Incident response policy, Data processor, so this option cannot replace one of those selections.

Answer E is incorrect because Board oversight means governance exercised by a board or equivalent senior governing body. The required choices are Incident response policy, Data processor. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 7

A review during a governance framework review identifies two gaps. One requires entity that determines the purposes and means of processing personal data. The other requires entity that processes personal data on behalf of a controller. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Security procedure
  2. Data controller
  3. Incident response policy
  4. Data processor
  5. Data owner

Correct Answers: B, D

Correct Answers

 

 

Answer B is correct because Data controller means an entity that determines the purposes and means of processing personal data. This option satisfies a specific requirement in the stem; Security procedure serves step-by-step instructions for performing a specific task in accordance with policy and standards and therefore is not interchangeable with it.

Answer D is correct because Data processor means an entity that processes personal data on behalf of a controller. One required function is exactly what this option provides. Data owner may be useful elsewhere, but it is used for the role accountable for decisions about classification, access, and acceptable use of data.

Incorrect Answers

 

Answer A is incorrect because Security procedure means step-by-step instructions for performing a specific task in accordance with policy and standards. The scenario calls for Data controller, Data processor. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents. The required choices are Data controller, Data processor. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Data owner means the role accountable for decisions about classification, access, and acceptable use of data. The required choices are Data controller, Data processor. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 8

The control set for a governance framework review must address both governance direction defining authority, responsibilities, and expectations for handling security incidents and step-by-step instructions for performing a specific task in accordance with policy and standards. Which TWO choices map directly to those needs? Choose TWO.

  1. Incident response policy
  2. Security procedure
  3. SDLC policy
  4. Disaster recovery policy
  5. Data processor

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents. This option satisfies a specific requirement in the stem; Disaster recovery policy serves governance direction for restoring technology and services after a major disruption and therefore is not interchangeable with it.

Answer B is correct because Security procedure means step-by-step instructions for performing a specific task in accordance with policy and standards. It belongs in the fixed-count answer set because it covers one of the stated requirements. Disaster recovery policy instead serves governance direction for restoring technology and services after a major disruption and cannot replace this function.

Incorrect Answers

 

Answer C is incorrect because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance. Every answer slot must map to a stated requirement. The correct set is Incident response policy, Security procedure, so this option cannot replace one of those selections.

Answer D is incorrect because Disaster recovery policy means governance direction for restoring technology and services after a major disruption. The scenario calls for Incident response policy, Security procedure. Selecting this option would leave one of those required functions uncovered.

Answer E is incorrect because Data processor means an entity that processes personal data on behalf of a controller. The required choices are Incident response policy, Security procedure. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 9

A security plan created during a governance framework review must provide policy defining permitted and prohibited use of organizational systems, networks, and information, periodic review of policies and governance structures to keep them effective and current, and role accountable for decisions about classification, access, and acceptable use of data. Which THREE options should be selected? Choose THREE.

  1. Data owner
  2. Acceptable use policy
  3. Data custodian
  4. Data processor
  5. Governance monitoring and revision
  6. Security standard

Correct Answers: A, B, E

Correct Answers

 

 

Answer A is correct because Data owner means the role accountable for decisions about classification, access, and acceptable use of data. It belongs in the fixed-count answer set because it covers one of the stated requirements. Security standard instead serves a mandatory specific requirement supporting policy, such as an encryption level or password parameter and cannot replace this function.

Answer B is correct because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information. One required function is exactly what this option provides. Data custodian may be useful elsewhere, but it is used for a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.

Answer E is correct because Governance monitoring and revision means periodic review of policies and governance structures to keep them effective and current. The fixed-count item needs this function in the answer set. Data processor covers an entity that processes personal data on behalf of a controller, a different requirement.

Incorrect Answers

 

Answer C is incorrect because Data custodian means a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements. The scenario calls for Data owner, Governance monitoring and revision, Acceptable use policy. Selecting this option would leave one of those required functions uncovered.

Answer D is incorrect because Data processor means an entity that processes personal data on behalf of a controller. The fixed-count answer set is Data owner, Governance monitoring and revision, Acceptable use policy; this option does not fill one of those named functions.

Answer F is incorrect because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter. The scenario calls for Data owner, Governance monitoring and revision, Acceptable use policy. Selecting this option would leave one of those required functions uncovered.

 

Question 10

Which cross-functional or specialized group coordinates decisions, priorities, and oversight?

  1. Security guideline
  2. Security committee
  3. Data processor
  4. Acceptable use policy

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Security committee means a cross-functional or specialized group that coordinates decisions, priorities, and oversight. That makes it the best answer here; Acceptable use policy addresses policy defining permitted and prohibited use of organizational systems, networks, and information, not the function requested in the stem.

Incorrect Answers

 

Answer A is incorrect because Security guideline refers to recommended practice that provides flexible guidance rather than a mandatory exact requirement. The key mismatch is functional: Security committee addresses a cross-functional or specialized group that coordinates decisions, priorities, and oversight, the need stated by the question.

Answer C is incorrect because Data processor refers to an entity that processes personal data on behalf of a controller. That concept can be valid in another scenario, but this question is testing a cross-functional or specialized group that coordinates decisions, priorities, and oversight; Security committee therefore fits the requirement more directly.

Answer D is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. The key mismatch is functional: Security committee addresses a cross-functional or specialized group that coordinates decisions, priorities, and oversight, the need stated by the question.

 

Question 11

Which term describes governance direction defining authority, responsibilities, and expectations for handling security incidents?

  1. Data custodian
  2. Data owner
  3. Incident response policy
  4. Disaster recovery policy

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents. This matches the requirement as written. Data custodian can be valid in another context, but it is used for a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.

Incorrect Answers

 

Answer A is incorrect because Data custodian refers to a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements. This could be appropriate elsewhere, but the required function is governance direction defining authority, responsibilities, and expectations for handling security incidents; that makes Incident response policy the precise choice.

Answer B is incorrect because Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data. The question is not asking for this function. It is testing governance direction defining authority, responsibilities, and expectations for handling security incidents, so Incident response policy is the stronger fit.

Answer D is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The concept is valid, but it does not match this stem. The required function is governance direction defining authority, responsibilities, and expectations for handling security incidents, which maps to Incident response policy.

 

Question 12

To align controls with obligations or norms specific to a business sector, which security approach should be selected?

  1. Security policy
  2. Industry requirement
  3. Disaster recovery policy
  4. SDLC policy

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Industry requirement means a security expectation arising from sector standards, contracts, or common industry frameworks. The requirement maps directly to this function, whereas Security policy is aimed at management-approved statement of required direction, expectations, and responsibilities.

Incorrect Answers

 

Answer A is incorrect because Security policy refers to management-approved statement of required direction, expectations, and responsibilities. That concept can be valid in another scenario, but this question is testing a security expectation arising from sector standards, contracts, or common industry frameworks; Industry requirement therefore fits the requirement more directly.

Answer C is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The key mismatch is functional: Industry requirement addresses a security expectation arising from sector standards, contracts, or common industry frameworks, the need stated by the question.

Answer D is incorrect because SDLC policy refers to security requirements that apply across software planning, development, testing, release, and maintenance. The concept is valid, but it does not match this stem. The required function is a security expectation arising from sector standards, contracts, or common industry frameworks, which maps to Industry requirement.

 

Question 13

Which term describes recommended practice that provides flexible guidance rather than a mandatory exact requirement?

  1. Incident response policy
  2. Business continuity policy
  3. Security guideline
  4. Data processor

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Security guideline means recommended practice that provides flexible guidance rather than a mandatory exact requirement. The deciding point is functional fit: this option covers the stated need, while Business continuity policy addresses governance direction for maintaining critical business functions during disruption.

Incorrect Answers

 

Answer A is incorrect because Incident response policy refers to governance direction defining authority, responsibilities, and expectations for handling security incidents. The question is not asking for this function. It is testing recommended practice that provides flexible guidance rather than a mandatory exact requirement, so Security guideline is the stronger fit.

Answer B is incorrect because Business continuity policy refers to governance direction for maintaining critical business functions during disruption. The key mismatch is functional: Security guideline addresses recommended practice that provides flexible guidance rather than a mandatory exact requirement, the need stated by the question.

Answer D is incorrect because Data processor refers to an entity that processes personal data on behalf of a controller. The key mismatch is functional: Security guideline addresses recommended practice that provides flexible guidance rather than a mandatory exact requirement, the need stated by the question.

 

Question 14

The control set for a governance framework review must address both security expectation arising from sector standards, contracts, or common industry frameworks and entity that processes personal data on behalf of a controller. Which TWO choices map directly to those needs? Choose TWO.

  1. Data custodian
  2. Security standard
  3. Regulatory requirement
  4. Industry requirement
  5. Data processor

Correct Answers: D, E

Correct Answers

 

 

Answer D is correct because Industry requirement means a security expectation arising from sector standards, contracts, or common industry frameworks. One required function is exactly what this option provides. Data custodian may be useful elsewhere, but it is used for a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.

Answer E is correct because Data processor means an entity that processes personal data on behalf of a controller. It belongs in the fixed-count answer set because it covers one of the stated requirements. Regulatory requirement instead serves a security obligation imposed by a government or regulatory authority and cannot replace this function.

Incorrect Answers

 

Answer A is incorrect because Data custodian means a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements. The fixed-count answer set is Data processor, Industry requirement; this option does not fill one of those named functions.

Answer B is incorrect because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter. The required choices are Data processor, Industry requirement. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer C is incorrect because Regulatory requirement means a security obligation imposed by a government or regulatory authority. The question requires exactly 2 selections: Data processor, Industry requirement. This option falls outside that required set. For example, Data processor is required for an entity that processes personal data on behalf of a controller.

 

Question 15

Which term describes governance direction for maintaining critical business functions during disruption?

  1. Playbook
  2. Security procedure
  3. Security standard
  4. Business continuity policy

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Business continuity policy means governance direction for maintaining critical business functions during disruption. That is the function the question is testing. Security procedure would instead be used for step-by-step instructions for performing a specific task in accordance with policy and standards.

Incorrect Answers

 

Answer A is incorrect because Playbook refers to a predefined set of response or operational actions for a known scenario. The scenario instead requires governance direction for maintaining critical business functions during disruption, which is why Business continuity policy is the better answer; this option serves the different function defined above.

Answer B is incorrect because Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards. The scenario instead requires governance direction for maintaining critical business functions during disruption, which is why Business continuity policy is the better answer; this option serves the different function defined above.

Answer C is incorrect because Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter. This could be appropriate elsewhere, but the required function is governance direction for maintaining critical business functions during disruption; that makes Business continuity policy the precise choice.

 

Question 16

To set user expectations for responsible technology use, which security approach should be selected?

  1. Acceptable use policy
  2. Security standard
  3. Governance monitoring and revision
  4. Regulatory requirement

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information. This is the precise fit for the scenario. Regulatory requirement serves the different purpose of a security obligation imposed by a government or regulatory authority.

Incorrect Answers

 

Answer B is incorrect because Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter. That concept can be valid in another scenario, but this question is testing policy defining permitted and prohibited use of organizational systems, networks, and information; Acceptable use policy therefore fits the requirement more directly.

Answer C is incorrect because Governance monitoring and revision refers to periodic review of policies and governance structures to keep them effective and current. That concept can be valid in another scenario, but this question is testing policy defining permitted and prohibited use of organizational systems, networks, and information; Acceptable use policy therefore fits the requirement more directly.

Answer D is incorrect because Regulatory requirement refers to a security obligation imposed by a government or regulatory authority. The key mismatch is functional: Acceptable use policy addresses policy defining permitted and prohibited use of organizational systems, networks, and information, the need stated by the question.

 

Question 17

Which term describes policy defining permitted and prohibited use of organizational systems, networks, and information?

  1. Security standard
  2. Acceptable use policy
  3. Regulatory requirement
  4. Security committee

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information. The requirement maps directly to this function, whereas Security committee is aimed at a cross-functional or specialized group that coordinates decisions, priorities, and oversight.

Incorrect Answers

 

Answer A is incorrect because Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter. The concept is valid, but it does not match this stem. The required function is policy defining permitted and prohibited use of organizational systems, networks, and information, which maps to Acceptable use policy.

Answer C is incorrect because Regulatory requirement refers to a security obligation imposed by a government or regulatory authority. The scenario instead requires policy defining permitted and prohibited use of organizational systems, networks, and information, which is why Acceptable use policy is the better answer; this option serves the different function defined above.

Answer D is incorrect because Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight. The question is not asking for this function. It is testing policy defining permitted and prohibited use of organizational systems, networks, and information, so Acceptable use policy is the stronger fit.

 

Question 18

To define mandatory organizational security intent, which security approach should be selected?

  1. Playbook
  2. Disaster recovery policy
  3. Board oversight
  4. Security policy

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Security policy means management-approved statement of required direction, expectations, and responsibilities. The deciding point is functional fit: this option covers the stated need, while Board oversight addresses governance exercised by a board or equivalent senior governing body.

Incorrect Answers

 

Answer A is incorrect because Playbook refers to a predefined set of response or operational actions for a known scenario. The concept is valid, but it does not match this stem. The required function is management-approved statement of required direction, expectations, and responsibilities, which maps to Security policy.

Answer B is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The concept is valid, but it does not match this stem. The required function is management-approved statement of required direction, expectations, and responsibilities, which maps to Security policy.

Answer C is incorrect because Board oversight refers to governance exercised by a board or equivalent senior governing body. This could be appropriate elsewhere, but the required function is management-approved statement of required direction, expectations, and responsibilities; that makes Security policy the precise choice.

 

Question 19

What is a mandatory specific requirement supporting policy, such as an encryption level or password parameter?

  1. Security procedure
  2. Data owner
  3. Industry requirement
  4. Security standard

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter. This matches the requirement as written. Security procedure can be valid in another context, but it is used for step-by-step instructions for performing a specific task in accordance with policy and standards.

Incorrect Answers

 

Answer A is incorrect because Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards. The question is not asking for this function. It is testing a mandatory specific requirement supporting policy, such as an encryption level or password parameter, so Security standard is the stronger fit.

Answer B is incorrect because Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data. That concept can be valid in another scenario, but this question is testing a mandatory specific requirement supporting policy, such as an encryption level or password parameter; Security standard therefore fits the requirement more directly.

Answer C is incorrect because Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks. This could be appropriate elsewhere, but the required function is a mandatory specific requirement supporting policy, such as an encryption level or password parameter; that makes Security standard the precise choice.

 

Question 20

To ensure incidents are managed consistently and with clear accountability, which security approach should be selected?

  1. Incident response policy
  2. Data owner
  3. Data processor
  4. Regulatory requirement

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents. The deciding point is functional fit: this option covers the stated need, while Data owner addresses the role accountable for decisions about classification, access, and acceptable use of data.

Incorrect Answers

 

Answer B is incorrect because Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data. The key mismatch is functional: Incident response policy addresses governance direction defining authority, responsibilities, and expectations for handling security incidents, the need stated by the question.

Answer C is incorrect because Data processor refers to an entity that processes personal data on behalf of a controller. That concept can be valid in another scenario, but this question is testing governance direction defining authority, responsibilities, and expectations for handling security incidents; Incident response policy therefore fits the requirement more directly.

Answer D is incorrect because Regulatory requirement refers to a security obligation imposed by a government or regulatory authority. This could be appropriate elsewhere, but the required function is governance direction defining authority, responsibilities, and expectations for handling security incidents; that makes Incident response policy the precise choice.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!