CompTIA Security+ SY0-701 Data Protection Strategies Practice Test

 

Topic 12 focuses on Data Protection Strategies for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes information subject to legal or regulatory handling requirements?

  1. Sensitive classification
  2. Restricted classification
  3. Regulated data
  4. Data sovereignty

Correct Answer: C

 

Correct Answer

Answer C is correct because Regulated data means information subject to legal or regulatory handling requirements.

Incorrect Answers

Answer A is incorrect because Sensitive classification addresses a different requirement. Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm.

Answer B is incorrect because Restricted classification would fit a different scenario. Restricted classification refers to a highly controlled classification for information whose exposure could cause severe harm or violate obligations.

Answer D is incorrect because Data sovereignty represents a different security function. Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction.

 

Question 2

To protect proprietary methods, formulas, designs, or business knowledge, which security approach should be selected?

  1. Permission restriction
  2. Trade secret
  3. Public classification
  4. Data sovereignty

Correct Answer: B

 

Correct Answer

Answer B is correct because Trade secret means confidential business information that derives value from not being generally known.

Incorrect Answers

Answer A is incorrect because Permission restriction addresses a different security requirement. Permission restriction refers to limiting data access according to identity, role, need, and least privilege.

Answer C is incorrect because Public classification would fit a different scenario. Public classification refers to a classification for information approved for unrestricted external disclosure.

Answer D is incorrect because Data sovereignty addresses a different requirement. Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction.

 

Question 3

Which term describes creations or proprietary information protected by legal or business rights?

  1. Trade secret
  2. Data encryption
  3. Intellectual property
  4. Geolocation restriction

Correct Answer: C

 

Correct Answer

Answer C is correct because Intellectual property means creations or proprietary information protected by legal or business rights.

Incorrect Answers

Answer A is incorrect because Trade secret would fit a different scenario. Trade secret refers to confidential business information that derives value from not being generally known.

Answer B is incorrect because Data encryption addresses a different requirement. Data encryption refers to use of cryptography to make information unreadable without authorized key material.

Answer D is incorrect because Geolocation restriction represents a different security function. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

 

Question 4

To protect high-value information that can enable fraud or privacy harm, which security approach should be selected?

  1. Data tokenization
  2. Financial information
  3. Restricted classification
  4. Permission restriction

Correct Answer: B

 

Correct Answer

Answer B is correct because Financial information means data relating to payments, accounts, transactions, or financial status.

Incorrect Answers

Answer A is incorrect because Data tokenization addresses a different requirement. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Answer C is incorrect because Restricted classification would fit a different scenario. Restricted classification refers to a highly controlled classification for information whose exposure could cause severe harm or violate obligations.

Answer D is incorrect because Permission restriction addresses a different security requirement. Permission restriction refers to limiting data access according to identity, role, need, and least privilege.

 

Question 5

What is a label indicating information requires protection because unauthorized disclosure or modification could cause harm?

  1. Sensitive classification
  2. Geolocation restriction
  3. Data tokenization
  4. Regulated data

Correct Answer: A

 

Correct Answer

Answer A is correct because Sensitive classification means a label indicating information requires protection because unauthorized disclosure or modification could cause harm.

Incorrect Answers

Answer B is incorrect because Geolocation restriction would fit a different scenario. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

Answer C is incorrect because Data tokenization represents a different security function. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Answer D is incorrect because Regulated data addresses a different requirement. Regulated data refers to information subject to legal or regulatory handling requirements.

 

Question 6

To limit access and distribution to approved recipients, which security approach should be selected?

  1. Intellectual property
  2. Confidential classification
  3. Trade secret
  4. Data at rest

Correct Answer: B

 

Correct Answer

Answer B is correct because Confidential classification means a restrictive classification for information intended only for specifically authorized users or groups.

Incorrect Answers

Answer A is incorrect because Intellectual property addresses a different security requirement. Intellectual property refers to creations or proprietary information protected by legal or business rights.

Answer C is incorrect because Trade secret addresses a different requirement. Trade secret refers to confidential business information that derives value from not being generally known.

Answer D is incorrect because Data at rest would fit a different scenario. Data at rest refers to data stored on media such as disks, databases, backups, or removable storage.

 

Question 7

What is a classification for information approved for unrestricted external disclosure?

  1. Data in use
  2. Data sovereignty
  3. Restricted classification
  4. Public classification

Correct Answer: D

 

Correct Answer

Answer D is correct because Public classification means a classification for information approved for unrestricted external disclosure.

Incorrect Answers

Answer A is incorrect because Data in use addresses a different requirement. Data in use refers to data actively being processed in memory or by an application.

Answer B is incorrect because Data sovereignty represents a different security function. Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction.

Answer C is incorrect because Restricted classification would fit a different scenario. Restricted classification refers to a highly controlled classification for information whose exposure could cause severe harm or violate obligations.

 

Question 8

To apply the strongest access and handling restrictions, which security approach should be selected?

  1. Confidential classification
  2. Data tokenization
  3. Restricted classification
  4. Public classification

Correct Answer: C

 

Correct Answer

Answer C is correct because Restricted classification means a highly controlled classification for information whose exposure could cause severe harm or violate obligations.

Incorrect Answers

Answer A is incorrect because Confidential classification addresses a different requirement. Confidential classification refers to a restrictive classification for information intended only for specifically authorized users or groups.

Answer B is incorrect because Data tokenization would fit a different scenario. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Answer D is incorrect because Public classification addresses a different security requirement. Public classification refers to a classification for information approved for unrestricted external disclosure.

 

Question 9

Which term describes data stored on media such as disks, databases, backups, or removable storage?

  1. Intellectual property
  2. Geolocation restriction
  3. Confidential classification
  4. Data at rest

Correct Answer: D

 

Correct Answer

Answer D is correct because Data at rest means data stored on media such as disks, databases, backups, or removable storage.

Incorrect Answers

Answer A is incorrect because Intellectual property represents a different security function. Intellectual property refers to creations or proprietary information protected by legal or business rights.

Answer B is incorrect because Geolocation restriction would fit a different scenario. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

Answer C is incorrect because Confidential classification addresses a different requirement. Confidential classification refers to a restrictive classification for information intended only for specifically authorized users or groups.

 

Question 10

To protect communications with encrypted and authenticated protocols, which security approach should be selected?

  1. Data encryption
  2. Data in transit
  3. Geolocation restriction
  4. Trade secret

Correct Answer: B

 

Correct Answer

Answer B is correct because Data in transit means data moving across a network or communication channel.

Incorrect Answers

Answer A is incorrect because Data encryption would fit a different scenario. Data encryption refers to use of cryptography to make information unreadable without authorized key material.

Answer C is incorrect because Geolocation restriction addresses a different security requirement. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

Answer D is incorrect because Trade secret addresses a different requirement. Trade secret refers to confidential business information that derives value from not being generally known.

 

Question 11

Which term describes data actively being processed in memory or by an application?

  1. Data at rest
  2. Restricted classification
  3. Intellectual property
  4. Data in use

Correct Answer: D

 

Correct Answer

Answer D is correct because Data in use means data actively being processed in memory or by an application.

Incorrect Answers

Answer A is incorrect because Data at rest would fit a different scenario. Data at rest refers to data stored on media such as disks, databases, backups, or removable storage.

Answer B is incorrect because Restricted classification addresses a different requirement. Restricted classification refers to a highly controlled classification for information whose exposure could cause severe harm or violate obligations.

Answer C is incorrect because Intellectual property represents a different security function. Intellectual property refers to creations or proprietary information protected by legal or business rights.

 

Question 12

To store and process data in ways consistent with applicable national or regional rules, which security approach should be selected?

  1. Data sovereignty
  2. Data encryption
  3. Data in use
  4. Geolocation restriction

Correct Answer: A

 

Correct Answer

Answer A is correct because Data sovereignty means the principle that data is subject to laws and governance requirements based on jurisdiction.

Incorrect Answers

Answer B is incorrect because Data encryption addresses a different security requirement. Data encryption refers to use of cryptography to make information unreadable without authorized key material.

Answer C is incorrect because Data in use would fit a different scenario. Data in use refers to data actively being processed in memory or by an application.

Answer D is incorrect because Geolocation restriction addresses a different requirement. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

 

Question 13

Which control limits storage, access, or processing according to geographic location?

  1. Geolocation restriction
  2. Permission restriction
  3. Data encryption
  4. Data at rest

Correct Answer: A

 

Correct Answer

Answer A is correct because Geolocation restriction means a control that limits storage, access, or processing according to geographic location.

Incorrect Answers

Answer B is incorrect because Permission restriction represents a different security function. Permission restriction refers to limiting data access according to identity, role, need, and least privilege.

Answer C is incorrect because Data encryption addresses a different requirement. Data encryption refers to use of cryptography to make information unreadable without authorized key material.

Answer D is incorrect because Data at rest would fit a different scenario. Data at rest refers to data stored on media such as disks, databases, backups, or removable storage.

 

Question 14

To protect confidentiality of stored or transmitted information, which security approach should be selected?

  1. Data in use
  2. Sensitive classification
  3. Data encryption
  4. Intellectual property

Correct Answer: C

 

Correct Answer

Answer C is correct because Data encryption means use of cryptography to make information unreadable without authorized key material.

Incorrect Answers

Answer A is incorrect because Data in use addresses a different security requirement. Data in use refers to data actively being processed in memory or by an application.

Answer B is incorrect because Sensitive classification addresses a different requirement. Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm.

Answer D is incorrect because Intellectual property would fit a different scenario. Intellectual property refers to creations or proprietary information protected by legal or business rights.

 

Question 15

Which term describes use of one-way digests to validate that data has not been modified?

  1. Data hashing
  2. Intellectual property
  3. Data at rest
  4. Data masking

Correct Answer: A

 

Correct Answer

Answer A is correct because Data hashing means use of one-way digests to validate that data has not been modified.

Incorrect Answers

Answer B is incorrect because Intellectual property would fit a different scenario. Intellectual property refers to creations or proprietary information protected by legal or business rights.

Answer C is incorrect because Data at rest represents a different security function. Data at rest refers to data stored on media such as disks, databases, backups, or removable storage.

Answer D is incorrect because Data masking addresses a different requirement. Data masking refers to obscuring portions of sensitive data while preserving a usable representation.

 

Question 16

To reduce exposure during support, testing, or analytics, which security approach should be selected?

  1. Data hashing
  2. Data at rest
  3. Data masking
  4. Data encryption

Correct Answer: C

 

Correct Answer

Answer C is correct because Data masking means obscuring portions of sensitive data while preserving a usable representation.

Incorrect Answers

Answer A is incorrect because Data hashing would fit a different scenario. Data hashing refers to use of one-way digests to validate that data has not been modified.

Answer B is incorrect because Data at rest addresses a different security requirement. Data at rest refers to data stored on media such as disks, databases, backups, or removable storage.

Answer D is incorrect because Data encryption addresses a different requirement. Data encryption refers to use of cryptography to make information unreadable without authorized key material.

 

Question 17

Which term describes substitution of sensitive values with non-sensitive tokens linked through a protected mapping system?

  1. Regulated data
  2. Data tokenization
  3. Public classification
  4. Data encryption

Correct Answer: B

 

Correct Answer

Answer B is correct because Data tokenization means substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Incorrect Answers

Answer A is incorrect because Regulated data would fit a different scenario. Regulated data refers to information subject to legal or regulatory handling requirements.

Answer C is incorrect because Public classification addresses a different requirement. Public classification refers to a classification for information approved for unrestricted external disclosure.

Answer D is incorrect because Data encryption represents a different security function. Data encryption refers to use of cryptography to make information unreadable without authorized key material.

 

Question 18

To ensure only approved users and services can read or modify protected information, which security approach should be selected?

  1. Data in transit
  2. Data masking
  3. Data tokenization
  4. Permission restriction

Correct Answer: D

 

Correct Answer

Answer D is correct because Permission restriction means limiting data access according to identity, role, need, and least privilege.

Incorrect Answers

Answer A is incorrect because Data in transit would fit a different scenario. Data in transit refers to data moving across a network or communication channel.

Answer B is incorrect because Data masking addresses a different security requirement. Data masking refers to obscuring portions of sensitive data while preserving a usable representation.

Answer C is incorrect because Data tokenization addresses a different requirement. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

 

Question 19

To apply controls mandated by laws or sector regulations, which security approach should be selected?

  1. Regulated data
  2. Intellectual property
  3. Data tokenization
  4. Sensitive classification

Correct Answer: A

 

Correct Answer

Answer A is correct because Regulated data means information subject to legal or regulatory handling requirements.

Incorrect Answers

Answer B is incorrect because Intellectual property represents a different security function. Intellectual property refers to creations or proprietary information protected by legal or business rights.

Answer C is incorrect because Data tokenization would fit a different scenario. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Answer D is incorrect because Sensitive classification addresses a different security requirement. Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm.

 

Question 20

Which term describes confidential business information that derives value from not being generally known?

  1. Trade secret
  2. Intellectual property
  3. Data tokenization
  4. Geolocation restriction

Correct Answer: A

 

Correct Answer

Answer A is correct because Trade secret means confidential business information that derives value from not being generally known.

Incorrect Answers

Answer B is incorrect because Intellectual property addresses a different requirement. Intellectual property refers to creations or proprietary information protected by legal or business rights.

Answer C is incorrect because Data tokenization addresses a different security requirement. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Answer D is incorrect because Geolocation restriction represents a different security function. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

 

Question 21

To prevent unauthorized use or disclosure of valuable creative and technical assets, which security approach should be selected?

  1. Confidential classification
  2. Trade secret
  3. Regulated data
  4. Intellectual property

Correct Answer: D

 

Correct Answer

Answer D is correct because Intellectual property means creations or proprietary information protected by legal or business rights.

Incorrect Answers

Answer A is incorrect because Confidential classification addresses a different security requirement. Confidential classification refers to a restrictive classification for information intended only for specifically authorized users or groups.

Answer B is incorrect because Trade secret represents a different security function. Trade secret refers to confidential business information that derives value from not being generally known.

Answer C is incorrect because Regulated data would fit a different scenario. Regulated data refers to information subject to legal or regulatory handling requirements.

 

Question 22

Which term describes data relating to payments, accounts, transactions, or financial status?

  1. Permission restriction
  2. Data in use
  3. Data tokenization
  4. Financial information

Correct Answer: D

 

Correct Answer

Answer D is correct because Financial information means data relating to payments, accounts, transactions, or financial status.

Incorrect Answers

Answer A is incorrect because Permission restriction represents a different security function. Permission restriction refers to limiting data access according to identity, role, need, and least privilege.

Answer B is incorrect because Data in use addresses a different requirement. Data in use refers to data actively being processed in memory or by an application.

Answer C is incorrect because Data tokenization addresses a different security requirement. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

 

Question 23

To apply stronger handling controls than those used for public information, which security approach should be selected?

  1. Geolocation restriction
  2. Sensitive classification
  3. Trade secret
  4. Permission restriction

Correct Answer: B

 

Correct Answer

Answer B is correct because Sensitive classification means a label indicating information requires protection because unauthorized disclosure or modification could cause harm.

Incorrect Answers

Answer A is incorrect because Geolocation restriction represents a different security function. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

Answer C is incorrect because Trade secret addresses a different security requirement. Trade secret refers to confidential business information that derives value from not being generally known.

Answer D is incorrect because Permission restriction would fit a different scenario. Permission restriction refers to limiting data access according to identity, role, need, and least privilege.

 

Question 24

Which restrictive classification for information is intended only for specifically authorized users or groups?

  1. Permission restriction
  2. Public classification
  3. Confidential classification
  4. Sensitive classification

Correct Answer: C

 

Correct Answer

Answer C is correct because Confidential classification means a restrictive classification for information intended only for specifically authorized users or groups.

Incorrect Answers

Answer A is incorrect because Permission restriction represents a different security function. Permission restriction refers to limiting data access according to identity, role, need, and least privilege.

Answer B is incorrect because Public classification addresses a different security requirement. Public classification refers to a classification for information approved for unrestricted external disclosure.

Answer D is incorrect because Sensitive classification addresses a different requirement. Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm.

 

Question 25

To avoid unnecessary controls while preserving integrity and availability, which security approach should be selected?

  1. Public classification
  2. Trade secret
  3. Geolocation restriction
  4. Data tokenization

Correct Answer: A

 

Correct Answer

Answer A is correct because Public classification means a classification for information approved for unrestricted external disclosure.

Incorrect Answers

Answer B is incorrect because Trade secret addresses a different security requirement. Trade secret refers to confidential business information that derives value from not being generally known.

Answer C is incorrect because Geolocation restriction would fit a different scenario. Geolocation restriction refers to a control that limits storage, access, or processing according to geographic location.

Answer D is incorrect because Data tokenization represents a different security function. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

 

Question 26

What is a highly controlled classification for information whose exposure could cause severe harm or violate obligations?

  1. Restricted classification
  2. Data sovereignty
  3. Data tokenization
  4. Financial information

Correct Answer: A

 

Correct Answer

Answer A is correct because Restricted classification means a highly controlled classification for information whose exposure could cause severe harm or violate obligations.

Incorrect Answers

Answer B is incorrect because Data sovereignty represents a different security function. Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction.

Answer C is incorrect because Data tokenization addresses a different requirement. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Answer D is incorrect because Financial information addresses a different security requirement. Financial information refers to data relating to payments, accounts, transactions, or financial status.

 

Question 27

To protect stored information through encryption and access controls, which security approach should be selected?

  1. Trade secret
  2. Data at rest
  3. Regulated data
  4. Data in transit

Correct Answer: B

 

Correct Answer

Answer B is correct because Data at rest means data stored on media such as disks, databases, backups, or removable storage.

Incorrect Answers

Answer A is incorrect because Trade secret would fit a different scenario. Trade secret refers to confidential business information that derives value from not being generally known.

Answer C is incorrect because Regulated data addresses a different security requirement. Regulated data refers to information subject to legal or regulatory handling requirements.

Answer D is incorrect because Data in transit represents a different security function. Data in transit refers to data moving across a network or communication channel.

 

Question 28

Which term describes data moving across a network or communication channel?

  1. Data in use
  2. Data in transit
  3. Data encryption
  4. Regulated data

Correct Answer: B

 

Correct Answer

Answer B is correct because Data in transit means data moving across a network or communication channel.

Incorrect Answers

Answer A is incorrect because Data in use addresses a different security requirement. Data in use refers to data actively being processed in memory or by an application.

Answer C is incorrect because Data encryption addresses a different requirement. Data encryption refers to use of cryptography to make information unreadable without authorized key material.

Answer D is incorrect because Regulated data represents a different security function. Regulated data refers to information subject to legal or regulatory handling requirements.

 

Question 29

To protect information while it is accessible to running processes, which security approach should be selected?

  1. Data sovereignty
  2. Sensitive classification
  3. Regulated data
  4. Data in use

Correct Answer: D

 

Correct Answer

Answer D is correct because Data in use means data actively being processed in memory or by an application.

Incorrect Answers

Answer A is incorrect because Data sovereignty represents a different security function. Data sovereignty refers to the principle that data is subject to laws and governance requirements based on jurisdiction.

Answer B is incorrect because Sensitive classification would fit a different scenario. Sensitive classification refers to a label indicating information requires protection because unauthorized disclosure or modification could cause harm.

Answer C is incorrect because Regulated data addresses a different security requirement. Regulated data refers to information subject to legal or regulatory handling requirements.

 

Question 30

Which principle data is subject to laws and governance requirements based on jurisdiction?

  1. Public classification
  2. Data tokenization
  3. Data sovereignty
  4. Data masking

Correct Answer: C

 

Correct Answer

Answer C is correct because Data sovereignty means the principle that data is subject to laws and governance requirements based on jurisdiction.

Incorrect Answers

Answer A is incorrect because Public classification addresses a different security requirement. Public classification refers to a classification for information approved for unrestricted external disclosure.

Answer B is incorrect because Data tokenization represents a different security function. Data tokenization refers to substitution of sensitive values with non-sensitive tokens linked through a protected mapping system.

Answer D is incorrect because Data masking addresses a different requirement. Data masking refers to obscuring portions of sensitive data while preserving a usable representation.

img