CompTIA Security+ SY0-701 Security Compliance Practice Test

 

Topic 26 focuses on Security Compliance for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes reporting produced for management, governance, or internal control owners about adherence to requirements?

  1. Regulatory fine
  2. Contractual impact
  3. Reputational damage
  4. Internal compliance reporting

Correct Answer: D

 

Correct Answer

Answer D is correct because Internal compliance reporting means reporting produced for management, governance, or internal control owners about adherence to requirements.

Incorrect Answers

Answer A is incorrect because Regulatory fine addresses a different requirement. Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement.

Answer B is incorrect because Contractual impact would fit a different scenario. Contractual impact refers to financial, legal, or business consequence caused by failing contractual security requirements.

Answer C is incorrect because Reputational damage represents a different security function. Reputational damage refers to loss of trust or credibility resulting from security or compliance failure.

 

Question 2

To demonstrate adherence to obligations beyond the organization, which security approach should be selected?

  1. Regulatory fine
  2. External compliance reporting
  3. Contractual impact
  4. Data inventory and retention

Correct Answer: B

 

Correct Answer

Answer B is correct because External compliance reporting means reporting delivered to regulators, customers, auditors, or other outside parties.

Incorrect Answers

Answer A is incorrect because Regulatory fine addresses a different security requirement. Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement.

Answer C is incorrect because Contractual impact would fit a different scenario. Contractual impact refers to financial, legal, or business consequence caused by failing contractual security requirements.

Answer D is incorrect because Data inventory and retention addresses a different requirement. Data inventory and retention refers to documentation of what data exists, where it is stored, why it is kept, and when it should be deleted.

 

Question 3

Which term describes monetary penalty imposed for violating a regulatory requirement?

  1. Data subject
  2. Privacy legal requirement
  3. Regulatory fine
  4. Reputational damage

Correct Answer: C

 

Correct Answer

Answer C is correct because Regulatory fine means monetary penalty imposed for violating a regulatory requirement.

Incorrect Answers

Answer A is incorrect because Data subject addresses a different requirement. Data subject refers to the individual to whom personal data relates.

Answer B is incorrect because Privacy legal requirement would fit a different scenario. Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Answer D is incorrect because Reputational damage represents a different security function. Reputational damage refers to loss of trust or credibility resulting from security or compliance failure.

 

Question 4

To understand that non-compliance consequences can extend beyond fines, which security approach should be selected?

  1. External compliance reporting
  2. Attestation
  3. Sanction
  4. Data subject

Correct Answer: C

 

Correct Answer

Answer C is correct because Sanction means a non-monetary or broader punitive action imposed by an authority.

Incorrect Answers

Answer A is incorrect because External compliance reporting addresses a different requirement. External compliance reporting refers to reporting delivered to regulators, customers, auditors, or other outside parties.

Answer B is incorrect because Attestation addresses a different security requirement. Attestation refers to formal assertion that specified compliance conditions or controls are met.

Answer D is incorrect because Data subject would fit a different scenario. Data subject refers to the individual to whom personal data relates.

 

Question 5

Which term describes loss of trust or credibility resulting from security or compliance failure?

  1. Loss of license
  2. Internal compliance reporting
  3. Regulatory fine
  4. Reputational damage

Correct Answer: D

 

Correct Answer

Answer D is correct because Reputational damage means loss of trust or credibility resulting from security or compliance failure.

Incorrect Answers

Answer A is incorrect because Loss of license addresses a different requirement. Loss of license refers to revocation or suspension of authorization needed to operate in a regulated activity or market.

Answer B is incorrect because Internal compliance reporting represents a different security function. Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements.

Answer C is incorrect because Regulatory fine would fit a different scenario. Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement.

 

Question 6

To recognize severe compliance consequences that can halt business operations, which security approach should be selected?

  1. Right to be forgotten
  2. Loss of license
  3. Sanction
  4. Reputational damage

Correct Answer: B

 

Correct Answer

Answer B is correct because Loss of license means revocation or suspension of authorization needed to operate in a regulated activity or market.

Incorrect Answers

Answer A is incorrect because Right to be forgotten addresses a different security requirement. Right to be forgotten refers to a privacy right that may allow an individual to request deletion of personal data under applicable conditions.

Answer C is incorrect because Sanction would fit a different scenario. Sanction refers to a non-monetary or broader punitive action imposed by an authority.

Answer D is incorrect because Reputational damage addresses a different requirement. Reputational damage refers to loss of trust or credibility resulting from security or compliance failure.

 

Question 7

Which term describes financial, legal, or business consequence caused by failing contractual security requirements?

  1. Controller-processor distinction
  2. Compliance automation
  3. Contractual impact
  4. Internal compliance reporting

Correct Answer: C

 

Correct Answer

Answer C is correct because Contractual impact means financial, legal, or business consequence caused by failing contractual security requirements.

Incorrect Answers

Answer A is incorrect because Controller-processor distinction addresses a different requirement. Controller-processor distinction refers to privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf.

Answer B is incorrect because Compliance automation represents a different security function. Compliance automation refers to use of technology to continuously or repeatedly evaluate controls and produce evidence.

Answer D is incorrect because Internal compliance reporting would fit a different scenario. Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements.

 

Question 8

To show that the organization both understood obligations and acted appropriately, which security approach should be selected?

  1. Due diligence and due care
  2. Regulatory fine
  3. Privacy legal requirement
  4. Right to be forgotten

Correct Answer: A

 

Correct Answer

Answer A is correct because Due diligence and due care means the combination of investigating risks and then taking reasonable protective actions based on that knowledge.

Incorrect Answers

Answer B is incorrect because Regulatory fine addresses a different requirement. Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement.

Answer C is incorrect because Privacy legal requirement would fit a different scenario. Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Answer D is incorrect because Right to be forgotten addresses a different security requirement. Right to be forgotten refers to a privacy right that may allow an individual to request deletion of personal data under applicable conditions.

 

Question 9

Which term describes formal assertion that specified compliance conditions or controls are met?

  1. Attestation
  2. Controller-processor distinction
  3. Internal compliance reporting
  4. Compliance automation

Correct Answer: A

 

Correct Answer

Answer A is correct because Attestation means formal assertion that specified compliance conditions or controls are met.

Incorrect Answers

Answer B is incorrect because Controller-processor distinction addresses a different requirement. Controller-processor distinction refers to privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf.

Answer C is incorrect because Internal compliance reporting would fit a different scenario. Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements.

Answer D is incorrect because Compliance automation represents a different security function. Compliance automation refers to use of technology to continuously or repeatedly evaluate controls and produce evidence.

 

Question 10

To reduce manual effort and identify non-compliance sooner, which security approach should be selected?

  1. Regulatory fine
  2. Privacy legal requirement
  3. Due diligence and due care
  4. Compliance automation

Correct Answer: D

 

Correct Answer

Answer D is correct because Compliance automation means use of technology to continuously or repeatedly evaluate controls and produce evidence.

Incorrect Answers

Answer A is incorrect because Regulatory fine addresses a different requirement. Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement.

Answer B is incorrect because Privacy legal requirement addresses a different security requirement. Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Answer C is incorrect because Due diligence and due care would fit a different scenario. Due diligence and due care refers to the combination of investigating risks and then taking reasonable protective actions based on that knowledge.

 

Question 11

What is an obligation governing collection, processing, storage, sharing, or deletion of personal information?

  1. Data subject
  2. Regulatory fine
  3. Privacy legal requirement
  4. Internal compliance reporting

Correct Answer: C

 

Correct Answer

Answer C is correct because Privacy legal requirement means an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Incorrect Answers

Answer A is incorrect because Data subject represents a different security function. Data subject refers to the individual to whom personal data relates.

Answer B is incorrect because Regulatory fine addresses a different requirement. Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement.

Answer D is incorrect because Internal compliance reporting would fit a different scenario. Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements.

 

Question 12

To identify whose rights and information are protected by privacy requirements, which security approach should be selected?

  1. External compliance reporting
  2. Attestation
  3. Internal compliance reporting
  4. Data subject

Correct Answer: D

 

Correct Answer

Answer D is correct because Data subject means the individual to whom personal data relates.

Incorrect Answers

Answer A is incorrect because External compliance reporting addresses a different security requirement. External compliance reporting refers to reporting delivered to regulators, customers, auditors, or other outside parties.

Answer B is incorrect because Attestation addresses a different requirement. Attestation refers to formal assertion that specified compliance conditions or controls are met.

Answer C is incorrect because Internal compliance reporting would fit a different scenario. Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements.

 

Question 13

Which term describes privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf?

  1. Controller-processor distinction
  2. Right to be forgotten
  3. Due diligence and due care
  4. Contractual impact

Correct Answer: A

 

Correct Answer

Answer A is correct because Controller-processor distinction means privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf.

Incorrect Answers

Answer B is incorrect because Right to be forgotten represents a different security function. Right to be forgotten refers to a privacy right that may allow an individual to request deletion of personal data under applicable conditions.

Answer C is incorrect because Due diligence and due care would fit a different scenario. Due diligence and due care refers to the combination of investigating risks and then taking reasonable protective actions based on that knowledge.

Answer D is incorrect because Contractual impact addresses a different requirement. Contractual impact refers to financial, legal, or business consequence caused by failing contractual security requirements.

 

Question 14

To support privacy, discovery, minimization, and retention compliance, which security approach should be selected?

  1. Data inventory and retention
  2. Contractual impact
  3. Internal compliance reporting
  4. Privacy legal requirement

Correct Answer: A

 

Correct Answer

Answer A is correct because Data inventory and retention means documentation of what data exists, where it is stored, why it is kept, and when it should be deleted.

Incorrect Answers

Answer B is incorrect because Contractual impact addresses a different requirement. Contractual impact refers to financial, legal, or business consequence caused by failing contractual security requirements.

Answer C is incorrect because Internal compliance reporting addresses a different security requirement. Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements.

Answer D is incorrect because Privacy legal requirement would fit a different scenario. Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information.

 

Question 15

Which privacy right may allow an individual to request deletion of personal data under applicable conditions?

  1. Due diligence and due care
  2. Reputational damage
  3. Privacy legal requirement
  4. Right to be forgotten

Correct Answer: D

 

Correct Answer

Answer D is correct because Right to be forgotten means a privacy right that may allow an individual to request deletion of personal data under applicable conditions.

Incorrect Answers

Answer A is incorrect because Due diligence and due care represents a different security function. Due diligence and due care refers to the combination of investigating risks and then taking reasonable protective actions based on that knowledge.

Answer B is incorrect because Reputational damage would fit a different scenario. Reputational damage refers to loss of trust or credibility resulting from security or compliance failure.

Answer C is incorrect because Privacy legal requirement addresses a different requirement. Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information.

 

Question 16

To track compliance status and remediation inside the organization, which security approach should be selected?

  1. Privacy legal requirement
  2. Regulatory fine
  3. Internal compliance reporting
  4. Compliance automation

Correct Answer: C

 

Correct Answer

Answer C is correct because Internal compliance reporting means reporting produced for management, governance, or internal control owners about adherence to requirements.

Incorrect Answers

Answer A is incorrect because Privacy legal requirement addresses a different requirement. Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Answer B is incorrect because Regulatory fine represents a different security function. Regulatory fine refers to monetary penalty imposed for violating a regulatory requirement.

Answer D is incorrect because Compliance automation would fit a different scenario. Compliance automation refers to use of technology to continuously or repeatedly evaluate controls and produce evidence.

 

Question 17

Which term describes reporting delivered to regulators, customers, auditors, or other outside parties?

  1. Loss of license
  2. External compliance reporting
  3. Controller-processor distinction
  4. Compliance automation

Correct Answer: B

 

Correct Answer

Answer B is correct because External compliance reporting means reporting delivered to regulators, customers, auditors, or other outside parties.

Incorrect Answers

Answer A is incorrect because Loss of license addresses a different security requirement. Loss of license refers to revocation or suspension of authorization needed to operate in a regulated activity or market.

Answer C is incorrect because Controller-processor distinction would fit a different scenario. Controller-processor distinction refers to privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf.

Answer D is incorrect because Compliance automation addresses a different requirement. Compliance automation refers to use of technology to continuously or repeatedly evaluate controls and produce evidence.

 

Question 18

To recognize direct financial consequences of non-compliance, which security approach should be selected?

  1. Controller-processor distinction
  2. Regulatory fine
  3. Reputational damage
  4. Compliance automation

Correct Answer: B

 

Correct Answer

Answer B is correct because Regulatory fine means monetary penalty imposed for violating a regulatory requirement.

Incorrect Answers

Answer A is incorrect because Controller-processor distinction addresses a different requirement. Controller-processor distinction refers to privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf.

Answer C is incorrect because Reputational damage would fit a different scenario. Reputational damage refers to loss of trust or credibility resulting from security or compliance failure.

Answer D is incorrect because Compliance automation represents a different security function. Compliance automation refers to use of technology to continuously or repeatedly evaluate controls and produce evidence.

 

Question 19

What is a non-monetary or broader punitive action imposed by an authority?

  1. Sanction
  2. Right to be forgotten
  3. Controller-processor distinction
  4. Data inventory and retention

Correct Answer: A

 

Correct Answer

Answer A is correct because Sanction means a non-monetary or broader punitive action imposed by an authority.

Incorrect Answers

Answer B is incorrect because Right to be forgotten addresses a different requirement. Right to be forgotten refers to a privacy right that may allow an individual to request deletion of personal data under applicable conditions.

Answer C is incorrect because Controller-processor distinction addresses a different security requirement. Controller-processor distinction refers to privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf.

Answer D is incorrect because Data inventory and retention would fit a different scenario. Data inventory and retention refers to documentation of what data exists, where it is stored, why it is kept, and when it should be deleted.

 

Question 20

To account for business impact that may persist beyond direct penalties, which security approach should be selected?

  1. Reputational damage
  2. Compliance automation
  3. Due diligence and due care
  4. External compliance reporting

Correct Answer: A

 

Correct Answer

Answer A is correct because Reputational damage means loss of trust or credibility resulting from security or compliance failure.

Incorrect Answers

Answer B is incorrect because Compliance automation addresses a different requirement. Compliance automation refers to use of technology to continuously or repeatedly evaluate controls and produce evidence.

Answer C is incorrect because Due diligence and due care would fit a different scenario. Due diligence and due care refers to the combination of investigating risks and then taking reasonable protective actions based on that knowledge.

Answer D is incorrect because External compliance reporting represents a different security function. External compliance reporting refers to reporting delivered to regulators, customers, auditors, or other outside parties.

 

Question 21

Which term describes revocation or suspension of authorization needed to operate in a regulated activity or market?

  1. Data inventory and retention
  2. Loss of license
  3. External compliance reporting
  4. Sanction

Correct Answer: B

 

Correct Answer

Answer B is correct because Loss of license means revocation or suspension of authorization needed to operate in a regulated activity or market.

Incorrect Answers

Answer A is incorrect because Data inventory and retention would fit a different scenario. Data inventory and retention refers to documentation of what data exists, where it is stored, why it is kept, and when it should be deleted.

Answer C is incorrect because External compliance reporting addresses a different security requirement. External compliance reporting refers to reporting delivered to regulators, customers, auditors, or other outside parties.

Answer D is incorrect because Sanction addresses a different requirement. Sanction refers to a non-monetary or broader punitive action imposed by an authority.

 

Question 22

To understand compliance obligations created by customer and partner agreements, which security approach should be selected?

  1. Attestation
  2. Contractual impact
  3. Privacy legal requirement
  4. Loss of license

Correct Answer: B

 

Correct Answer

Answer B is correct because Contractual impact means financial, legal, or business consequence caused by failing contractual security requirements.

Incorrect Answers

Answer A is incorrect because Attestation addresses a different requirement. Attestation refers to formal assertion that specified compliance conditions or controls are met.

Answer C is incorrect because Privacy legal requirement would fit a different scenario. Privacy legal requirement refers to an obligation governing collection, processing, storage, sharing, or deletion of personal information.

Answer D is incorrect because Loss of license represents a different security function. Loss of license refers to revocation or suspension of authorization needed to operate in a regulated activity or market.

 

Question 23

Which combination of investigating risks and then taking reasonable protective actions based on knowledge?

  1. Controller-processor distinction
  2. Internal compliance reporting
  3. Due diligence and due care
  4. Reputational damage

Correct Answer: C

 

Correct Answer

Answer C is correct because Due diligence and due care means the combination of investigating risks and then taking reasonable protective actions based on that knowledge.

Incorrect Answers

Answer A is incorrect because Controller-processor distinction addresses a different requirement. Controller-processor distinction refers to privacy distinction between the entity deciding purposes and means of processing and the entity processing data on its behalf.

Answer B is incorrect because Internal compliance reporting addresses a different security requirement. Internal compliance reporting refers to reporting produced for management, governance, or internal control owners about adherence to requirements.

Answer D is incorrect because Reputational damage would fit a different scenario. Reputational damage refers to loss of trust or credibility resulting from security or compliance failure.

 

Question 24

To provide documented confirmation of compliance status, which security approach should be selected?

  1. Loss of license
  2. Right to be forgotten
  3. Sanction
  4. Attestation

Correct Answer: D

 

Correct Answer

Answer D is correct because Attestation means formal assertion that specified compliance conditions or controls are met.

Incorrect Answers

Answer A is incorrect because Loss of license would fit a different scenario. Loss of license refers to revocation or suspension of authorization needed to operate in a regulated activity or market.

Answer B is incorrect because Right to be forgotten addresses a different requirement. Right to be forgotten refers to a privacy right that may allow an individual to request deletion of personal data under applicable conditions.

Answer C is incorrect because Sanction represents a different security function. Sanction refers to a non-monetary or broader punitive action imposed by an authority.

 

Question 25

Which term describes use of technology to continuously or repeatedly evaluate controls and produce evidence?

  1. Compliance automation
  2. Data inventory and retention
  3. Reputational damage
  4. External compliance reporting

Correct Answer: A

 

Correct Answer

Answer A is correct because Compliance automation means use of technology to continuously or repeatedly evaluate controls and produce evidence.

Incorrect Answers

Answer B is incorrect because Data inventory and retention addresses a different requirement. Data inventory and retention refers to documentation of what data exists, where it is stored, why it is kept, and when it should be deleted.

Answer C is incorrect because Reputational damage would fit a different scenario. Reputational damage refers to loss of trust or credibility resulting from security or compliance failure.

Answer D is incorrect because External compliance reporting addresses a different security requirement. External compliance reporting refers to reporting delivered to regulators, customers, auditors, or other outside parties.

img