Topic 23 Practice Test 2 covers Security Governance for CompTIA Security+ SY0-701 and maps to objective 5.1: Summarize elements of effective security governance. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
To make security processes repeatable and operationally consistent, which security approach should be selected?
- Business continuity policy
- Acceptable use policy
- Security procedure
- Disaster recovery policy
Correct Answer: C
Correct Answer
Answer C is correct because Security procedure means step-by-step instructions for performing a specific task in accordance with policy and standards. That makes it the best answer here; Disaster recovery policy addresses governance direction for restoring technology and services after a major disruption, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Business continuity policy refers to governance direction for maintaining critical business functions during disruption. The key mismatch is functional: Security procedure addresses step-by-step instructions for performing a specific task in accordance with policy and standards, the need stated by the question.
Answer B is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. The question is not asking for this function. It is testing step-by-step instructions for performing a specific task in accordance with policy and standards, so Security procedure is the stronger fit.
Answer D is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The question is not asking for this function. It is testing step-by-step instructions for performing a specific task in accordance with policy and standards, so Security procedure is the stronger fit.
Question 2
The control set for a governance framework review must address both governance direction for restoring technology and services after a major disruption and role accountable for decisions about classification, access, and acceptable use of data. Which TWO choices map directly to those needs? Choose TWO.
- Acceptable use policy
- Disaster recovery policy
- Data processor
- Data owner
- Security standard
Correct Answers: B, D
Correct Answers
Answer B is correct because Disaster recovery policy means governance direction for restoring technology and services after a major disruption. The fixed-count item needs this function in the answer set. Security standard covers a mandatory specific requirement supporting policy, such as an encryption level or password parameter, a different requirement.
Answer D is correct because Data owner means the role accountable for decisions about classification, access, and acceptable use of data. One required function is exactly what this option provides. Data processor may be useful elsewhere, but it is used for an entity that processes personal data on behalf of a controller.
Incorrect Answers
Answer A is incorrect because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information. The required choices are Data owner, Disaster recovery policy. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Data processor means an entity that processes personal data on behalf of a controller. The question requires exactly 2 selections: Data owner, Disaster recovery policy. This option falls outside that required set. For example, Disaster recovery policy is required for governance direction for restoring technology and services after a major disruption.
Answer E is incorrect because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter. The fixed-count answer set is Data owner, Disaster recovery policy; this option does not fill one of those named functions.
Question 3
A review during a governance framework review identifies two gaps. One requires mandatory specific requirement supporting policy, such as an encryption level or password parameter. The other requires entity that processes personal data on behalf of a controller. Which TWO options should be included in the remediation plan? Choose TWO.
- SDLC policy
- Data processor
- Acceptable use policy
- Security standard
- Security procedure
Correct Answers: B, D
Correct Answers
Answer B is correct because Data processor means an entity that processes personal data on behalf of a controller. It belongs in the fixed-count answer set because it covers one of the stated requirements. Security procedure instead serves step-by-step instructions for performing a specific task in accordance with policy and standards and cannot replace this function.
Answer D is correct because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter. It belongs in the fixed-count answer set because it covers one of the stated requirements. Security procedure instead serves step-by-step instructions for performing a specific task in accordance with policy and standards and cannot replace this function.
Incorrect Answers
Answer A is incorrect because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance. The fixed-count answer set is Data processor, Security standard; this option does not fill one of those named functions.
Answer C is incorrect because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information. The fixed-count answer set is Data processor, Security standard; this option does not fill one of those named functions.
Answer E is incorrect because Security procedure means step-by-step instructions for performing a specific task in accordance with policy and standards. The fixed-count answer set is Data processor, Security standard; this option does not fill one of those named functions.
Question 4
To perform data-processing activities under the controller’s instructions, which security approach should be selected?
- Security procedure
- Data processor
- Security committee
- Security policy
Correct Answer: B
Correct Answer
Answer B is correct because Data processor means an entity that processes personal data on behalf of a controller. The requirement maps directly to this function, whereas Security procedure is aimed at step-by-step instructions for performing a specific task in accordance with policy and standards.
Incorrect Answers
Answer A is incorrect because Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards. That concept can be valid in another scenario, but this question is testing an entity that processes personal data on behalf of a controller; Data processor therefore fits the requirement more directly.
Answer C is incorrect because Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight. The scenario instead requires an entity that processes personal data on behalf of a controller, which is why Data processor is the better answer; this option serves the different function defined above.
Answer D is incorrect because Security policy refers to management-approved statement of required direction, expectations, and responsibilities. The scenario instead requires an entity that processes personal data on behalf of a controller, which is why Data processor is the better answer; this option serves the different function defined above.
Question 5
Which term describes step-by-step instructions for performing a specific task in accordance with policy and standards?
- Acceptable use policy
- Security standard
- Security procedure
- SDLC policy
Correct Answer: C
Correct Answer
Answer C is correct because Security procedure means step-by-step instructions for performing a specific task in accordance with policy and standards. That is the function the question is testing. SDLC policy would instead be used for security requirements that apply across software planning, development, testing, release, and maintenance.
Incorrect Answers
Answer A is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. The key mismatch is functional: Security procedure addresses step-by-step instructions for performing a specific task in accordance with policy and standards, the need stated by the question.
Answer B is incorrect because Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter. The question is not asking for this function. It is testing step-by-step instructions for performing a specific task in accordance with policy and standards, so Security procedure is the stronger fit.
Answer D is incorrect because SDLC policy refers to security requirements that apply across software planning, development, testing, release, and maintenance. The scenario instead requires step-by-step instructions for performing a specific task in accordance with policy and standards, which is why Security procedure is the better answer; this option serves the different function defined above.
Question 6
To help teams make consistent security decisions when some discretion is appropriate, which security approach should be selected?
- Security guideline
- Data owner
- Acceptable use policy
- Regulatory requirement
Correct Answer: A
Correct Answer
Answer A is correct because Security guideline means recommended practice that provides flexible guidance rather than a mandatory exact requirement. The requirement maps directly to this function, whereas Regulatory requirement is aimed at a security obligation imposed by a government or regulatory authority.
Incorrect Answers
Answer B is incorrect because Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data. That concept can be valid in another scenario, but this question is testing recommended practice that provides flexible guidance rather than a mandatory exact requirement; Security guideline therefore fits the requirement more directly.
Answer C is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. The key mismatch is functional: Security guideline addresses recommended practice that provides flexible guidance rather than a mandatory exact requirement, the need stated by the question.
Answer D is incorrect because Regulatory requirement refers to a security obligation imposed by a government or regulatory authority. The concept is valid, but it does not match this stem. The required function is recommended practice that provides flexible guidance rather than a mandatory exact requirement, which maps to Security guideline.
Question 7
An architect working on a governance framework review needs one capability that provides predefined set of response or operational actions for a known scenario and another that provides entity that determines the purposes and means of processing personal data. Which TWO selections are the best match? Choose TWO.
- Security committee
- Playbook
- Data owner
- Data controller
- Regulatory requirement
Correct Answers: B, D
Correct Answers
Answer B is correct because Playbook means a predefined set of response or operational actions for a known scenario. This option satisfies a specific requirement in the stem; Security committee serves a cross-functional or specialized group that coordinates decisions, priorities, and oversight and therefore is not interchangeable with it.
Answer D is correct because Data controller means an entity that determines the purposes and means of processing personal data. One required function is exactly what this option provides. Security committee may be useful elsewhere, but it is used for a cross-functional or specialized group that coordinates decisions, priorities, and oversight.
Incorrect Answers
Answer A is incorrect because Security committee means a cross-functional or specialized group that coordinates decisions, priorities, and oversight. The question requires exactly 2 selections: Data controller, Playbook. This option falls outside that required set. For example, Playbook is required for a predefined set of response or operational actions for a known scenario.
Answer C is incorrect because Data owner means the role accountable for decisions about classification, access, and acceptable use of data. The question requires exactly 2 selections: Data controller, Playbook. This option falls outside that required set. For example, Data controller is required for an entity that determines the purposes and means of processing personal data.
Answer E is incorrect because Regulatory requirement means a security obligation imposed by a government or regulatory authority. The fixed-count answer set is Data controller, Playbook; this option does not fill one of those named functions. For example, Data controller is required for an entity that determines the purposes and means of processing personal data.
Question 8
What is a predefined set of response or operational actions for a known scenario?
- Playbook
- Data owner
- Incident response policy
- Security committee
Correct Answer: A
Correct Answer
Answer A is correct because Playbook means a predefined set of response or operational actions for a known scenario. That is the function the question is testing. Incident response policy would instead be used for governance direction defining authority, responsibilities, and expectations for handling security incidents.
Incorrect Answers
Answer B is incorrect because Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data. The concept is valid, but it does not match this stem. The required function is a predefined set of response or operational actions for a known scenario, which maps to Playbook.
Answer C is incorrect because Incident response policy refers to governance direction defining authority, responsibilities, and expectations for handling security incidents. That concept can be valid in another scenario, but this question is testing a predefined set of response or operational actions for a known scenario; Playbook therefore fits the requirement more directly.
Answer D is incorrect because Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight. The question is not asking for this function. It is testing a predefined set of response or operational actions for a known scenario, so Playbook is the stronger fit.
Question 9
Which term describes periodic review of policies and governance structures to keep them effective and current?
- Disaster recovery policy
- Security policy
- Governance monitoring and revision
- Acceptable use policy
Correct Answer: C
Correct Answer
Answer C is correct because Governance monitoring and revision means periodic review of policies and governance structures to keep them effective and current. The requirement maps directly to this function, whereas Acceptable use policy is aimed at policy defining permitted and prohibited use of organizational systems, networks, and information.
Incorrect Answers
Answer A is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The concept is valid, but it does not match this stem. The required function is periodic review of policies and governance structures to keep them effective and current, which maps to Governance monitoring and revision.
Answer B is incorrect because Security policy refers to management-approved statement of required direction, expectations, and responsibilities. The key mismatch is functional: Governance monitoring and revision addresses periodic review of policies and governance structures to keep them effective and current, the need stated by the question.
Answer D is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. This could be appropriate elsewhere, but the required function is periodic review of policies and governance structures to keep them effective and current; that makes Governance monitoring and revision the precise choice.
Question 10
The control set for a governance framework review must address both security obligation imposed by a government or regulatory authority and entity that determines the purposes and means of processing personal data. Which TWO choices map directly to those needs? Choose TWO.
- Data controller
- SDLC policy
- Playbook
- Regulatory requirement
- Data owner
Correct Answers: A, D
Correct Answers
Answer A is correct because Data controller means an entity that determines the purposes and means of processing personal data. The fixed-count item needs this function in the answer set. Playbook covers a predefined set of response or operational actions for a known scenario, a different requirement.
Answer D is correct because Regulatory requirement means a security obligation imposed by a government or regulatory authority. This selection maps directly to one of the named needs. Playbook addresses a predefined set of response or operational actions for a known scenario, so it does not satisfy the same slot.
Incorrect Answers
Answer B is incorrect because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance. Every answer slot must map to a stated requirement. The correct set is Data controller, Regulatory requirement, so this option cannot replace one of those selections.
Answer C is incorrect because Playbook means a predefined set of response or operational actions for a known scenario. The scenario calls for Data controller, Regulatory requirement. Selecting this option would leave one of those required functions uncovered. For example, Regulatory requirement is required for a security obligation imposed by a government or regulatory authority.
Answer E is incorrect because Data owner means the role accountable for decisions about classification, access, and acceptable use of data. The fixed-count answer set is Data controller, Regulatory requirement; this option does not fill one of those named functions.
Question 11
A security plan created during a governance framework review must provide governance direction for restoring technology and services after a major disruption, governance exercised by a board or equivalent senior governing body, and entity that determines the purposes and means of processing personal data. Which THREE options should be selected? Choose THREE.
- Disaster recovery policy
- Data processor
- Data owner
- SDLC policy
- Data controller
- Board oversight
Correct Answers: A, E, F
Correct Answers
Answer A is correct because Disaster recovery policy means governance direction for restoring technology and services after a major disruption. The fixed-count item needs this function in the answer set. Data owner covers the role accountable for decisions about classification, access, and acceptable use of data, a different requirement.
Answer E is correct because Data controller means an entity that determines the purposes and means of processing personal data. One required function is exactly what this option provides. Data owner may be useful elsewhere, but it is used for the role accountable for decisions about classification, access, and acceptable use of data.
Answer F is correct because Board oversight means governance exercised by a board or equivalent senior governing body. It belongs in the fixed-count answer set because it covers one of the stated requirements. SDLC policy instead serves security requirements that apply across software planning, development, testing, release, and maintenance and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Data processor means an entity that processes personal data on behalf of a controller. The scenario calls for Disaster recovery policy, Data controller, Board oversight. Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Data owner means the role accountable for decisions about classification, access, and acceptable use of data. The fixed-count answer set is Disaster recovery policy, Data controller, Board oversight; this option does not fill one of those named functions.
Answer D is incorrect because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance. The fixed-count answer set is Disaster recovery policy, Data controller, Board oversight; this option does not fill one of those named functions.
Question 12
To translate broad policy into measurable implementation requirements, which security approach should be selected?
- Disaster recovery policy
- Security standard
- Board oversight
- Security policy
Correct Answer: B
Correct Answer
Answer B is correct because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter. This is the precise fit for the scenario. Board oversight serves the different purpose of governance exercised by a board or equivalent senior governing body.
Incorrect Answers
Answer A is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The concept is valid, but it does not match this stem. The required function is a mandatory specific requirement supporting policy, such as an encryption level or password parameter, which maps to Security standard.
Answer C is incorrect because Board oversight refers to governance exercised by a board or equivalent senior governing body. The concept is valid, but it does not match this stem. The required function is a mandatory specific requirement supporting policy, such as an encryption level or password parameter, which maps to Security standard.
Answer D is incorrect because Security policy refers to management-approved statement of required direction, expectations, and responsibilities. The question is not asking for this function. It is testing a mandatory specific requirement supporting policy, such as an encryption level or password parameter, so Security standard is the stronger fit.
Question 13
To define recovery expectations and responsibilities for IT capabilities, which security approach should be selected?
- Governance monitoring and revision
- Disaster recovery policy
- Security standard
- Security guideline
Correct Answer: B
Correct Answer
Answer B is correct because Disaster recovery policy means governance direction for restoring technology and services after a major disruption. That is the function the question is testing. Security standard would instead be used for a mandatory specific requirement supporting policy, such as an encryption level or password parameter.
Incorrect Answers
Answer A is incorrect because Governance monitoring and revision refers to periodic review of policies and governance structures to keep them effective and current. That concept can be valid in another scenario, but this question is testing governance direction for restoring technology and services after a major disruption; Disaster recovery policy therefore fits the requirement more directly.
Answer C is incorrect because Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter. The key mismatch is functional: Disaster recovery policy addresses governance direction for restoring technology and services after a major disruption, the need stated by the question.
Answer D is incorrect because Security guideline refers to recommended practice that provides flexible guidance rather than a mandatory exact requirement. The question is not asking for this function. It is testing governance direction for restoring technology and services after a major disruption, so Disaster recovery policy is the stronger fit.
Question 14
To require planning and capability for continuity of essential operations, which security approach should be selected?
- Disaster recovery policy
- Playbook
- Acceptable use policy
- Business continuity policy
Correct Answer: D
Correct Answer
Answer D is correct because Business continuity policy means governance direction for maintaining critical business functions during disruption. This is the precise fit for the scenario. Acceptable use policy serves the different purpose of policy defining permitted and prohibited use of organizational systems, networks, and information.
Incorrect Answers
Answer A is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The question is not asking for this function. It is testing governance direction for maintaining critical business functions during disruption, so Business continuity policy is the stronger fit.
Answer B is incorrect because Playbook refers to a predefined set of response or operational actions for a known scenario. The key mismatch is functional: Business continuity policy addresses governance direction for maintaining critical business functions during disruption, the need stated by the question.
Answer C is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. The question is not asking for this function. It is testing governance direction for maintaining critical business functions during disruption, so Business continuity policy is the stronger fit.
Question 15
A review during a governance framework review identifies two gaps. One requires governance direction defining authority, responsibilities, and expectations for handling security incidents. The other requires role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements. Which TWO options should be included in the remediation plan? Choose TWO.
- Acceptable use policy
- Data controller
- Data custodian
- Incident response policy
- Security guideline
Correct Answers: C, D
Correct Answers
Answer C is correct because Data custodian means a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements. This option satisfies a specific requirement in the stem; Security guideline serves recommended practice that provides flexible guidance rather than a mandatory exact requirement and therefore is not interchangeable with it.
Answer D is correct because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents. One required function is exactly what this option provides. Acceptable use policy may be useful elsewhere, but it is used for policy defining permitted and prohibited use of organizational systems, networks, and information.
Incorrect Answers
Answer A is incorrect because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information. The required choices are Incident response policy, Data custodian. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer B is incorrect because Data controller means an entity that determines the purposes and means of processing personal data. The fixed-count answer set is Incident response policy, Data custodian; this option does not fill one of those named functions.
Answer E is incorrect because Security guideline means recommended practice that provides flexible guidance rather than a mandatory exact requirement. Every answer slot must map to a stated requirement. The correct set is Incident response policy, Data custodian, so this option cannot replace one of those selections.
Question 16
Which term describes governance direction for restoring technology and services after a major disruption?
- Data custodian
- Industry requirement
- Disaster recovery policy
- Business continuity policy
Correct Answer: C
Correct Answer
Answer C is correct because Disaster recovery policy means governance direction for restoring technology and services after a major disruption. This is the precise fit for the scenario. Data custodian serves the different purpose of a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.
Incorrect Answers
Answer A is incorrect because Data custodian refers to a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements. The concept is valid, but it does not match this stem. The required function is governance direction for restoring technology and services after a major disruption, which maps to Disaster recovery policy.
Answer B is incorrect because Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks. The concept is valid, but it does not match this stem. The required function is governance direction for restoring technology and services after a major disruption, which maps to Disaster recovery policy.
Answer D is incorrect because Business continuity policy refers to governance direction for maintaining critical business functions during disruption. The question is not asking for this function. It is testing governance direction for restoring technology and services after a major disruption, so Disaster recovery policy is the stronger fit.
Question 17
To embed security responsibilities into application lifecycle processes, which security approach should be selected?
- Regulatory requirement
- SDLC policy
- Board oversight
- Governance monitoring and revision
Correct Answer: B
Correct Answer
Answer B is correct because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance. The deciding point is functional fit: this option covers the stated need, while Regulatory requirement addresses a security obligation imposed by a government or regulatory authority.
Incorrect Answers
Answer A is incorrect because Regulatory requirement refers to a security obligation imposed by a government or regulatory authority. This could be appropriate elsewhere, but the required function is security requirements that apply across software planning, development, testing, release, and maintenance; that makes SDLC policy the precise choice.
Answer C is incorrect because Board oversight refers to governance exercised by a board or equivalent senior governing body. The scenario instead requires security requirements that apply across software planning, development, testing, release, and maintenance, which is why SDLC policy is the better answer; this option serves the different function defined above.
Answer D is incorrect because Governance monitoring and revision refers to periodic review of policies and governance structures to keep them effective and current. The scenario instead requires security requirements that apply across software planning, development, testing, release, and maintenance, which is why SDLC policy is the better answer; this option serves the different function defined above.
Question 18
What is a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements?
- Disaster recovery policy
- Industry requirement
- Data owner
- Data custodian
Correct Answer: D
Correct Answer
Answer D is correct because Data custodian means a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements. This matches the requirement as written. Disaster recovery policy can be valid in another context, but it is used for governance direction for restoring technology and services after a major disruption.
Incorrect Answers
Answer A is incorrect because Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption. The scenario instead requires a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements, which is why Data custodian is the better answer; this option serves the different function defined above.
Answer B is incorrect because Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks. This could be appropriate elsewhere, but the required function is a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements; that makes Data custodian the precise choice.
Answer C is incorrect because Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data. That concept can be valid in another scenario, but this question is testing a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements; Data custodian therefore fits the requirement more directly.
Question 19
To set protection requirements according to business value and risk, which security approach should be selected?
- Data owner
- Acceptable use policy
- Security policy
- Business continuity policy
Correct Answer: A
Correct Answer
Answer A is correct because Data owner means the role accountable for decisions about classification, access, and acceptable use of data. This is the precise fit for the scenario. Security policy serves the different purpose of management-approved statement of required direction, expectations, and responsibilities.
Incorrect Answers
Answer B is incorrect because Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information. This could be appropriate elsewhere, but the required function is the role accountable for decisions about classification, access, and acceptable use of data; that makes Data owner the precise choice.
Answer C is incorrect because Security policy refers to management-approved statement of required direction, expectations, and responsibilities. This could be appropriate elsewhere, but the required function is the role accountable for decisions about classification, access, and acceptable use of data; that makes Data owner the precise choice.
Answer D is incorrect because Business continuity policy refers to governance direction for maintaining critical business functions during disruption. The question is not asking for this function. It is testing the role accountable for decisions about classification, access, and acceptable use of data, so Data owner is the stronger fit.
Question 20
What is a security obligation imposed by a government or regulatory authority?
- Data owner
- Security committee
- Security policy
- Regulatory requirement
Correct Answer: D
Correct Answer
Answer D is correct because Regulatory requirement means a security obligation imposed by a government or regulatory authority. This is the precise fit for the scenario. Security committee serves the different purpose of a cross-functional or specialized group that coordinates decisions, priorities, and oversight.
Incorrect Answers
Answer A is incorrect because Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data. The scenario instead requires a security obligation imposed by a government or regulatory authority, which is why Regulatory requirement is the better answer; this option serves the different function defined above.
Answer B is incorrect because Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight. The scenario instead requires a security obligation imposed by a government or regulatory authority, which is why Regulatory requirement is the better answer; this option serves the different function defined above.
Answer C is incorrect because Security policy refers to management-approved statement of required direction, expectations, and responsibilities. The question is not asking for this function. It is testing a security obligation imposed by a government or regulatory authority, so Regulatory requirement is the stronger fit.