CompTIA Security+ SY0-701 Security Compliance Practice Test 2

 

Topic 26 Practice Test 2 covers Security Compliance for CompTIA Security+ SY0-701 and maps to objective 5.4: Summarize elements of effective security compliance. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.

Question 1

To identify whose rights and information are protected by privacy requirements, which security approach should be selected?

  1. Data subject
  2. Internal compliance reporting
  3. Attestation
  4. External compliance reporting

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Data subject means the individual to whom personal data relates. The requirement maps directly to this function, whereas External compliance reporting is aimed at reporting delivered to regulators, customers, auditors, or other outside parties.

Incorrect Answers

 

Answer B is incorrect because Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements. The question is not asking for this function. It is testing the individual to whom personal data relates, so Data subject is the stronger fit.

Answer C is incorrect because Attestation refers to formal assertion that specified compliance conditions or controls are met. The question is not asking for this function. It is testing the individual to whom personal data relates, so Data subject is the stronger fit.

Answer D is incorrect because External compliance reporting refers to reporting delivered to regulators, customers, auditors, or other outside parties. The question is not asking for this function. It is testing the individual to whom personal data relates, so Data subject is the stronger fit.

 

Question 2

As part of a compliance program review, reviewers identify a need for reporting delivered to regulators, customers, auditors, or other outside parties. Which option should they select?

  1. Right to be forgotten
  2. External compliance reporting
  3. Contractual impact
  4. Data inventory and retention

Correct Answer: B

Correct Answer

 

 

Answer B is correct because External compliance reporting means reporting delivered to regulators, customers, auditors, or other outside parties. This is the precise fit for the scenario. Right to be forgotten serves the different purpose of a privacy right that may allow an individual to request deletion of personal data under applicable conditions.

Incorrect Answers

 

Answer A is incorrect because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. That concept can be valid in another scenario, but this question is testing reporting delivered to regulators, customers, auditors, or other outside parties; External compliance reporting therefore fits the requirement more directly.

Answer C is incorrect because Contractual impact means financial, legal, or business consequence caused by failing contractual security requirements. The key mismatch is functional: External compliance reporting addresses reporting delivered to regulators, customers, auditors, or other outside parties, the need stated by the question.

Answer D is incorrect because Data inventory and retention means documentation of what data exists, where it is stored, why it is kept, and when it should be deleted. This could be appropriate elsewhere, but the required function is reporting delivered to regulators, customers, auditors, or other outside parties; that makes External compliance reporting the precise choice.

 

Question 3

During a compliance program review, the team has two independent requirements: (1) revocation or suspension of authorization needed to operate in a regulated activity or market; and (2) privacy right that may allow an individual to request deletion of personal data under applicable conditions. Which TWO choices best satisfy those requirements? Choose TWO.

  1. External compliance reporting
  2. Contractual impact
  3. Loss of license
  4. Reputational damage
  5. Right to be forgotten

Correct Answers: C, E

Correct Answers

 

 

Answer C is correct because Loss of license means revocation or suspension of authorization needed to operate in a regulated activity or market. It belongs in the fixed-count answer set because it covers one of the stated requirements. External compliance reporting instead serves reporting delivered to regulators, customers, auditors, or other outside parties and cannot replace this function.

Answer E is correct because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. This option satisfies a specific requirement in the stem; Contractual impact serves financial, legal, or business consequence caused by failing contractual security requirements and therefore is not interchangeable with it.

Incorrect Answers

 

Answer A is incorrect because External compliance reporting means reporting delivered to regulators, customers, auditors, or other outside parties. The scenario calls for Loss of license, Right to be forgotten. Selecting this option would leave one of those required functions uncovered.

Answer B is incorrect because Contractual impact means financial, legal, or business consequence caused by failing contractual security requirements. The fixed-count answer set is Loss of license, Right to be forgotten; this option does not fill one of those named functions.

Answer D is incorrect because Reputational damage means loss of trust or credibility resulting from security or compliance failure. The scenario calls for Loss of license, Right to be forgotten. Selecting this option would leave one of those required functions uncovered.

 

Question 4

To track compliance status and remediation inside the organization, which security approach should be selected?

  1. Compliance automation
  2. Regulatory fine
  3. Internal compliance reporting
  4. Privacy legal requirement

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Internal compliance reporting means reporting produced for management, governance, or internal control owners about adherence to requirements. This is the precise fit for the scenario. Privacy legal requirement serves the different purpose of an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Incorrect Answers

 

Answer A is incorrect because Compliance automation refers to use of technology to continuously or repeatedly evaluate controls and produce evidence. The concept is valid, but it does not match this stem. The required function is reporting produced for management, governance, or internal control owners about adherence to requirements, which maps to Internal compliance reporting.

Answer B is incorrect because Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement. This could be appropriate elsewhere, but the required function is reporting produced for management, governance, or internal control owners about adherence to requirements; that makes Internal compliance reporting the precise choice.

Answer D is incorrect because Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information. The key mismatch is functional: Internal compliance reporting addresses reporting produced for management, governance, or internal control owners about adherence to requirements, the need stated by the question.

 

Question 5

To reduce manual effort and identify non-compliance sooner, which security approach should be selected?

  1. Regulatory fine
  2. Due diligence and due care
  3. Privacy legal requirement
  4. Compliance automation

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Compliance automation means use of technology to continuously or repeatedly evaluate controls and produce evidence. That is the function the question is testing. Privacy legal requirement would instead be used for an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Incorrect Answers

 

Answer A is incorrect because Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement. The concept is valid, but it does not match this stem. The required function is use of technology to continuously or repeatedly evaluate controls and produce evidence, which maps to Compliance automation.

Answer B is incorrect because Due diligence and due care refers to the combination of investigating risks and then taking reasonable protective actions based on that knowledge. The scenario instead requires use of technology to continuously or repeatedly evaluate controls and produce evidence, which is why Compliance automation is the better answer; this option serves the different function defined above.

Answer C is incorrect because Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information. This could be appropriate elsewhere, but the required function is use of technology to continuously or repeatedly evaluate controls and produce evidence; that makes Compliance automation the precise choice.

 

Question 6

During a compliance program review, the team needs revocation or suspension of authorization needed to operate in a regulated activity or market. Which option best meets this requirement?

  1. Loss of license
  2. Data inventory and retention
  3. Right to be forgotten
  4. Compliance automation

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Loss of license means revocation or suspension of authorization needed to operate in a regulated activity or market. That makes it the best answer here; Compliance automation addresses use of technology to continuously or repeatedly evaluate controls and produce evidence, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because Data inventory and retention means documentation of what data exists, where it is stored, why it is kept, and when it should be deleted. The concept is valid, but it does not match this stem. The required function is revocation or suspension of authorization needed to operate in a regulated activity or market, which maps to Loss of license.

Answer C is incorrect because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. The scenario instead requires revocation or suspension of authorization needed to operate in a regulated activity or market, which is why Loss of license is the better answer; this option serves the different function defined above.

Answer D is incorrect because Compliance automation means use of technology to continuously or repeatedly evaluate controls and produce evidence. That concept can be valid in another scenario, but this question is testing revocation or suspension of authorization needed to operate in a regulated activity or market; Loss of license therefore fits the requirement more directly.

 

Question 7

Which privacy right may allow an individual to request deletion of personal data under applicable conditions?

  1. Privacy legal requirement
  2. Reputational damage
  3. Due diligence and due care
  4. Right to be forgotten

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. That is the function the question is testing. Privacy legal requirement would instead be used for an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Incorrect Answers

 

Answer A is incorrect because Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information. The concept is valid, but it does not match this stem. The required function is a privacy right that may allow an individual to request deletion of personal data under applicable conditions, which maps to Right to be forgotten.

Answer B is incorrect because Reputational damage refers to loss of trust or credibility resulting from security or compliance failure. The key mismatch is functional: Right to be forgotten addresses a privacy right that may allow an individual to request deletion of personal data under applicable conditions, the need stated by the question.

Answer C is incorrect because Due diligence and due care refers to the combination of investigating risks and then taking reasonable protective actions based on that knowledge. The concept is valid, but it does not match this stem. The required function is a privacy right that may allow an individual to request deletion of personal data under applicable conditions, which maps to Right to be forgotten.

 

Question 8

As part of a compliance program review, reviewers identify a need for obligation governing collection, processing, storage, sharing, or deletion of personal information. Which option should they select?

  1. Sanction
  2. External compliance reporting
  3. Right to be forgotten
  4. Privacy legal requirement

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Privacy legal requirement means an obligation governing collection, processing, storage, sharing, or deletion of personal information. The requirement maps directly to this function, whereas External compliance reporting is aimed at reporting delivered to regulators, customers, auditors, or other outside parties.

Incorrect Answers

 

Answer A is incorrect because Sanction means a non-monetary or broader punitive action imposed by an authority. The question is not asking for this function. It is testing an obligation governing collection, processing, storage, sharing, or deletion of personal information, so Privacy legal requirement is the stronger fit.

Answer B is incorrect because External compliance reporting means reporting delivered to regulators, customers, auditors, or other outside parties. The concept is valid, but it does not match this stem. The required function is an obligation governing collection, processing, storage, sharing, or deletion of personal information, which maps to Privacy legal requirement.

Answer C is incorrect because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. The scenario instead requires an obligation governing collection, processing, storage, sharing, or deletion of personal information, which is why Privacy legal requirement is the better answer; this option serves the different function defined above.

 

Question 9

Two requirements remain open in a compliance program review: formal assertion that specified compliance conditions or controls are met; privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf. Which TWO options close those specific gaps? Choose TWO.

  1. Attestation
  2. Controller-processor distinction
  3. Right to be forgotten
  4. Compliance automation
  5. Data subject

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Attestation means formal assertion that specified compliance conditions or controls are met. One required function is exactly what this option provides. Data subject may be useful elsewhere, but it is used for the individual to whom personal data relates. This question specifically tests the combined requirements represented by Attestation and Controller-processor distinction.

Answer B is correct because Controller-processor distinction means privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf. This selection maps directly to one of the named needs. Right to be forgotten addresses a privacy right that may allow an individual to request deletion of personal data under applicable conditions, so it does not satisfy the same slot.

Incorrect Answers

 

Answer C is incorrect because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. The required choices are Attestation, Controller-processor distinction. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Compliance automation means use of technology to continuously or repeatedly evaluate controls and produce evidence. The required choices are Attestation, Controller-processor distinction. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Data subject means the individual to whom personal data relates. The required choices are Attestation, Controller-processor distinction. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 10

To show that the organization both understood obligations and acted appropriately, which security approach should be selected?

  1. Right to be forgotten
  2. Due diligence and due care
  3. Privacy legal requirement
  4. Regulatory fine

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Due diligence and due care means the combination of investigating risks and then taking reasonable protective actions based on that knowledge. The requirement maps directly to this function, whereas Privacy legal requirement is aimed at an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Incorrect Answers

 

Answer A is incorrect because Right to be forgotten refers to a privacy right that may allow an individual to request deletion of personal data under applicable conditions. The concept is valid, but it does not match this stem. The required function is the combination of investigating risks and then taking reasonable protective actions based on that knowledge, which maps to Due diligence and due care.

Answer C is incorrect because Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information. This could be appropriate elsewhere, but the required function is the combination of investigating risks and then taking reasonable protective actions based on that knowledge; that makes Due diligence and due care the precise choice.

Answer D is incorrect because Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement. The concept is valid, but it does not match this stem. The required function is the combination of investigating risks and then taking reasonable protective actions based on that knowledge, which maps to Due diligence and due care.

 

Question 11

Which combination of investigating risks and then taking reasonable protective actions based on knowledge?

  1. Controller-processor distinction
  2. Due diligence and due care
  3. Internal compliance reporting
  4. Reputational damage

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Due diligence and due care means the combination of investigating risks and then taking reasonable protective actions based on that knowledge. The requirement maps directly to this function, whereas Reputational damage is aimed at loss of trust or credibility resulting from security or compliance failure.

Incorrect Answers

 

Answer A is incorrect because Controller-processor distinction refers to privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf. That concept can be valid in another scenario, but this question is testing the combination of investigating risks and then taking reasonable protective actions based on that knowledge; Due diligence and due care therefore fits the requirement more directly.

Answer C is incorrect because Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements. That concept can be valid in another scenario, but this question is testing the combination of investigating risks and then taking reasonable protective actions based on that knowledge; Due diligence and due care therefore fits the requirement more directly.

Answer D is incorrect because Reputational damage refers to loss of trust or credibility resulting from security or compliance failure. That concept can be valid in another scenario, but this question is testing the combination of investigating risks and then taking reasonable protective actions based on that knowledge; Due diligence and due care therefore fits the requirement more directly.

 

Question 12

To understand that non-compliance consequences can extend beyond fines, which security approach should be selected?

  1. Sanction
  2. External compliance reporting
  3. Attestation
  4. Data subject

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Sanction means a non-monetary or broader punitive action imposed by an authority. That makes it the best answer here; Attestation addresses formal assertion that specified compliance conditions or controls are met, not the function requested in the stem.

Incorrect Answers

 

Answer B is incorrect because External compliance reporting refers to reporting delivered to regulators, customers, auditors, or other outside parties. The scenario instead requires a non-monetary or broader punitive action imposed by an authority, which is why Sanction is the better answer; this option serves the different function defined above.

Answer C is incorrect because Attestation refers to formal assertion that specified compliance conditions or controls are met. The concept is valid, but it does not match this stem. The required function is a non-monetary or broader punitive action imposed by an authority, which maps to Sanction.

Answer D is incorrect because Data subject refers to the individual to whom personal data relates. The scenario instead requires a non-monetary or broader punitive action imposed by an authority, which is why Sanction is the better answer; this option serves the different function defined above.

 

Question 13

Which term describes privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf?

  1. Right to be forgotten
  2. Due diligence and due care
  3. Controller-processor distinction
  4. Contractual impact

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Controller-processor distinction means privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf. The requirement maps directly to this function, whereas Due diligence and due care is aimed at the combination of investigating risks and then taking reasonable protective actions based on that knowledge.

Incorrect Answers

 

Answer A is incorrect because Right to be forgotten refers to a privacy right that may allow an individual to request deletion of personal data under applicable conditions. This could be appropriate elsewhere, but the required function is privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf; that makes Controller-processor distinction the precise choice.

Answer B is incorrect because Due diligence and due care refers to the combination of investigating risks and then taking reasonable protective actions based on that knowledge. The concept is valid, but it does not match this stem. The required function is privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf, which maps to Controller-processor distinction.

Answer D is incorrect because Contractual impact refers to financial, legal, or business consequence caused by failing contractual security requirements. The concept is valid, but it does not match this stem. The required function is privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf, which maps to Controller-processor distinction.

 

Question 14

Two requirements remain open in a compliance program review: non-monetary or broader punitive action imposed by an authority; documentation of what data exists, where it is stored, why it is kept, and when it should be deleted. Which TWO options close those specific gaps? Choose TWO.

  1. Data inventory and retention
  2. Sanction
  3. Right to be forgotten
  4. Compliance automation
  5. Data subject

Correct Answers: A, B

Correct Answers

 

 

Answer A is correct because Data inventory and retention means documentation of what data exists, where it is stored, why it is kept, and when it should be deleted. The fixed-count item needs this function in the answer set. Right to be forgotten covers a privacy right that may allow an individual to request deletion of personal data under applicable conditions, a different requirement.

Answer B is correct because Sanction means a non-monetary or broader punitive action imposed by an authority. The fixed-count item needs this function in the answer set. Compliance automation covers use of technology to continuously or repeatedly evaluate controls and produce evidence, a different requirement.

Incorrect Answers

 

Answer C is incorrect because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. The required choices are Sanction, Data inventory and retention. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer D is incorrect because Compliance automation means use of technology to continuously or repeatedly evaluate controls and produce evidence. The fixed-count answer set is Sanction, Data inventory and retention; this option does not fill one of those named functions.

Answer E is incorrect because Data subject means the individual to whom personal data relates. The question requires exactly 2 selections: Sanction, Data inventory and retention. This option falls outside that required set. For example, Data inventory and retention is required for documentation of what data exists, where it is stored, why it is kept, and when it should be deleted.

 

Question 15

During a compliance program review, the team has two independent requirements: (1) loss of trust or credibility resulting from security or compliance failure; and (2) documentation of what data exists, where it is stored, why it is kept, and when it should be deleted. Which TWO choices best satisfy those requirements? Choose TWO.

  1. Reputational damage
  2. Controller-processor distinction
  3. Right to be forgotten
  4. External compliance reporting
  5. Data inventory and retention

Correct Answers: A, E

Correct Answers

 

 

Answer A is correct because Reputational damage means loss of trust or credibility resulting from security or compliance failure. One required function is exactly what this option provides. External compliance reporting may be useful elsewhere, but it is used for reporting delivered to regulators, customers, auditors, or other outside parties.

Answer E is correct because Data inventory and retention means documentation of what data exists, where it is stored, why it is kept, and when it should be deleted. This option satisfies a specific requirement in the stem; External compliance reporting serves reporting delivered to regulators, customers, auditors, or other outside parties and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because Controller-processor distinction means privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf. The fixed-count answer set is Reputational damage, Data inventory and retention; this option does not fill one of those named functions.

Answer C is incorrect because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions. Every answer slot must map to a stated requirement. The correct set is Reputational damage, Data inventory and retention, so this option cannot replace one of those selections.

Answer D is incorrect because External compliance reporting means reporting delivered to regulators, customers, auditors, or other outside parties. The required choices are Reputational damage, Data inventory and retention. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 16

During a compliance program review, three requirements must be addressed: (1) loss of trust or credibility resulting from security or compliance failure; (2) revocation or suspension of authorization needed to operate in a regulated activity or market; and (3) use of technology to continuously or repeatedly evaluate controls and produce evidence. Which THREE choices best satisfy them? Choose THREE.

  1. Loss of license
  2. Data subject
  3. Compliance automation
  4. Reputational damage
  5. Sanction
  6. Regulatory fine

Correct Answers: A, C, D

Correct Answers

 

 

Answer A is correct because Loss of license means revocation or suspension of authorization needed to operate in a regulated activity or market. This selection maps directly to one of the named needs. Regulatory fine addresses monetary penalty imposed for violating a regulatory requirement, so it does not satisfy the same slot.

Answer C is correct because Compliance automation means use of technology to continuously or repeatedly evaluate controls and produce evidence. This option satisfies a specific requirement in the stem; Data subject serves the individual to whom personal data relates and therefore is not interchangeable with it.

Answer D is correct because Reputational damage means loss of trust or credibility resulting from security or compliance failure. The fixed-count item needs this function in the answer set. Regulatory fine covers monetary penalty imposed for violating a regulatory requirement, a different requirement.

Incorrect Answers

 

Answer B is incorrect because Data subject means the individual to whom personal data relates. The required choices are Compliance automation, Loss of license, Reputational damage. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Sanction means a non-monetary or broader punitive action imposed by an authority. The required choices are Compliance automation, Loss of license, Reputational damage. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer F is incorrect because Regulatory fine means monetary penalty imposed for violating a regulatory requirement. The required choices are Compliance automation, Loss of license, Reputational damage. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

 

Question 17

Which term describes monetary penalty imposed for violating a regulatory requirement?

  1. Data subject
  2. Regulatory fine
  3. Privacy legal requirement
  4. Reputational damage

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Regulatory fine means monetary penalty imposed for violating a regulatory requirement. The requirement maps directly to this function, whereas Data subject is aimed at the individual to whom personal data relates.

Incorrect Answers

 

Answer A is incorrect because Data subject refers to the individual to whom personal data relates. The scenario instead requires monetary penalty imposed for violating a regulatory requirement, which is why Regulatory fine is the better answer; this option serves the different function defined above.

Answer C is incorrect because Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information. This could be appropriate elsewhere, but the required function is monetary penalty imposed for violating a regulatory requirement; that makes Regulatory fine the precise choice.

Answer D is incorrect because Reputational damage refers to loss of trust or credibility resulting from security or compliance failure. The question is not asking for this function. It is testing monetary penalty imposed for violating a regulatory requirement, so Regulatory fine is the stronger fit.

 

Question 18

A review during a compliance program review identifies two gaps. One requires revocation or suspension of authorization needed to operate in a regulated activity or market. The other requires combination of investigating risks and then taking reasonable protective actions based on that knowledge. Which TWO options should be included in the remediation plan? Choose TWO.

  1. Loss of license
  2. External compliance reporting
  3. Controller-processor distinction
  4. Due diligence and due care
  5. Reputational damage

Correct Answers: A, D

Correct Answers

 

 

Answer A is correct because Loss of license means revocation or suspension of authorization needed to operate in a regulated activity or market. It belongs in the fixed-count answer set because it covers one of the stated requirements. Controller-processor distinction instead serves privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf and cannot replace this function.

Answer D is correct because Due diligence and due care means the combination of investigating risks and then taking reasonable protective actions based on that knowledge. This option satisfies a specific requirement in the stem; External compliance reporting serves reporting delivered to regulators, customers, auditors, or other outside parties and therefore is not interchangeable with it.

Incorrect Answers

 

Answer B is incorrect because External compliance reporting means reporting delivered to regulators, customers, auditors, or other outside parties. The scenario calls for Due diligence and due care, Loss of license. Selecting this option would leave one of those required functions uncovered.

Answer C is incorrect because Controller-processor distinction means privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf. The required choices are Due diligence and due care, Loss of license. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.

Answer E is incorrect because Reputational damage means loss of trust or credibility resulting from security or compliance failure. The scenario calls for Due diligence and due care, Loss of license. Selecting this option would leave one of those required functions uncovered.

 

Question 19

Which term describes reporting produced for management, governance, or internal control owners about adherence to requirements?

  1. Contractual impact
  2. Regulatory fine
  3. Internal compliance reporting
  4. Reputational damage

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Internal compliance reporting means reporting produced for management, governance, or internal control owners about adherence to requirements. This matches the requirement as written. Reputational damage can be valid in another context, but it is used for loss of trust or credibility resulting from security or compliance failure.

Incorrect Answers

 

Answer A is incorrect because Contractual impact refers to financial, legal, or business consequence caused by failing contractual security requirements. This could be appropriate elsewhere, but the required function is reporting produced for management, governance, or internal control owners about adherence to requirements; that makes Internal compliance reporting the precise choice.

Answer B is incorrect because Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement. This could be appropriate elsewhere, but the required function is reporting produced for management, governance, or internal control owners about adherence to requirements; that makes Internal compliance reporting the precise choice. This question specifically tests the requirement represented by Internal compliance reporting.

Answer D is incorrect because Reputational damage refers to loss of trust or credibility resulting from security or compliance failure. The key mismatch is functional: Internal compliance reporting addresses reporting produced for management, governance, or internal control owners about adherence to requirements, the need stated by the question.

 

Question 20

To support privacy, discovery, minimization, and retention compliance, which security approach should be selected?

  1. Data inventory and retention
  2. Privacy legal requirement
  3. Internal compliance reporting
  4. Contractual impact

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Data inventory and retention means documentation of what data exists, where it is stored, why it is kept, and when it should be deleted. This is the precise fit for the scenario. Internal compliance reporting serves the different purpose of reporting produced for management, governance, or internal control owners about adherence to requirements.

Incorrect Answers

 

Answer B is incorrect because Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information. The question is not asking for this function. It is testing documentation of what data exists, where it is stored, why it is kept, and when it should be deleted, so Data inventory and retention is the stronger fit.

Answer C is incorrect because Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements. The concept is valid, but it does not match this stem. The required function is documentation of what data exists, where it is stored, why it is kept, and when it should be deleted, which maps to Data inventory and retention.

Answer D is incorrect because Contractual impact refers to financial, legal, or business consequence caused by failing contractual security requirements. That concept can be valid in another scenario, but this question is testing documentation of what data exists, where it is stored, why it is kept, and when it should be deleted; Data inventory and retention therefore fits the requirement more directly.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!