CompTIA Security+ SY0-701 Security Governance Practice Test

 

Topic 23 focuses on Security Governance for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes recommended practice that provides flexible guidance rather than a mandatory exact requirement?

  1. Business continuity policy
  2. Data processor
  3. Incident response policy
  4. Security guideline

Correct Answer: D

 

Correct Answer

Answer D is correct because Security guideline means recommended practice that provides flexible guidance rather than a mandatory exact requirement.

Incorrect Answers

Answer A is incorrect because Business continuity policy addresses a different requirement. Business continuity policy refers to governance direction for maintaining critical business functions during disruption.

Answer B is incorrect because Data processor would fit a different scenario. Data processor refers to an entity that processes personal data on behalf of a controller.

Answer C is incorrect because Incident response policy represents a different security function. Incident response policy refers to governance direction defining authority, responsibilities, and expectations for handling security incidents.

 

Question 2

To define mandatory organizational security intent, which security approach should be selected?

  1. Board oversight
  2. Security policy
  3. Disaster recovery policy
  4. Playbook

Correct Answer: B

 

Correct Answer

Answer B is correct because Security policy means management-approved statement of required direction, expectations, and responsibilities.

Incorrect Answers

Answer A is incorrect because Board oversight addresses a different security requirement. Board oversight refers to governance exercised by a board or equivalent senior governing body.

Answer C is incorrect because Disaster recovery policy addresses a different requirement. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

Answer D is incorrect because Playbook would fit a different scenario. Playbook refers to a predefined set of response or operational actions for a known scenario.

 

Question 3

Which term describes policy defining permitted and prohibited use of organizational systems, networks, and information?

  1. Regulatory requirement
  2. Security standard
  3. Acceptable use policy
  4. Security committee

Correct Answer: C

 

Correct Answer

Answer C is correct because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information.

Incorrect Answers

Answer A is incorrect because Regulatory requirement addresses a different requirement. Regulatory requirement refers to a security obligation imposed by a government or regulatory authority.

Answer B is incorrect because Security standard represents a different security function. Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter.

Answer D is incorrect because Security committee would fit a different scenario. Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight.

 

Question 4

To require planning and capability for continuity of essential operations, which security approach should be selected?

  1. Playbook
  2. Acceptable use policy
  3. Business continuity policy
  4. Disaster recovery policy

Correct Answer: C

 

Correct Answer

Answer C is correct because Business continuity policy means governance direction for maintaining critical business functions during disruption.

Incorrect Answers

Answer A is incorrect because Playbook addresses a different requirement. Playbook refers to a predefined set of response or operational actions for a known scenario.

Answer B is incorrect because Acceptable use policy would fit a different scenario. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

Answer D is incorrect because Disaster recovery policy addresses a different security requirement. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

 

Question 5

Which term describes governance direction for restoring technology and services after a major disruption?

  1. Business continuity policy
  2. Data custodian
  3. Industry requirement
  4. Disaster recovery policy

Correct Answer: D

 

Correct Answer

Answer D is correct because Disaster recovery policy means governance direction for restoring technology and services after a major disruption.

Incorrect Answers

Answer A is incorrect because Business continuity policy addresses a different requirement. Business continuity policy refers to governance direction for maintaining critical business functions during disruption.

Answer B is incorrect because Data custodian represents a different security function. Data custodian refers to a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.

Answer C is incorrect because Industry requirement would fit a different scenario. Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks.

 

Question 6

To ensure incidents are managed consistently and with clear accountability, which security approach should be selected?

  1. Data owner
  2. Incident response policy
  3. Regulatory requirement
  4. Data processor

Correct Answer: B

 

Correct Answer

Answer B is correct because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents.

Incorrect Answers

Answer A is incorrect because Data owner addresses a different requirement. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

Answer C is incorrect because Regulatory requirement addresses a different security requirement. Regulatory requirement refers to a security obligation imposed by a government or regulatory authority.

Answer D is incorrect because Data processor would fit a different scenario. Data processor refers to an entity that processes personal data on behalf of a controller.

 

Question 7

Which term describes security requirements that apply across software planning, development, testing, release, and maintenance?

  1. Board oversight
  2. Data processor
  3. SDLC policy
  4. Governance monitoring and revision

Correct Answer: C

 

Correct Answer

Answer C is correct because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance.

Incorrect Answers

Answer A is incorrect because Board oversight addresses a different requirement. Board oversight refers to governance exercised by a board or equivalent senior governing body.

Answer B is incorrect because Data processor represents a different security function. Data processor refers to an entity that processes personal data on behalf of a controller.

Answer D is incorrect because Governance monitoring and revision would fit a different scenario. Governance monitoring and revision refers to periodic review of policies and governance structures to keep them effective and current.

 

Question 8

To translate broad policy into measurable implementation requirements, which security approach should be selected?

  1. Security standard
  2. Board oversight
  3. Disaster recovery policy
  4. Security policy

Correct Answer: A

 

Correct Answer

Answer A is correct because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter.

Incorrect Answers

Answer B is incorrect because Board oversight addresses a different security requirement. Board oversight refers to governance exercised by a board or equivalent senior governing body.

Answer C is incorrect because Disaster recovery policy addresses a different requirement. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

Answer D is incorrect because Security policy would fit a different scenario. Security policy refers to management-approved statement of required direction, expectations, and responsibilities.

 

Question 9

Which term describes step-by-step instructions for performing a specific task in accordance with policy and standards?

  1. Security procedure
  2. Acceptable use policy
  3. Security standard
  4. SDLC policy

Correct Answer: A

 

Correct Answer

Answer A is correct because Security procedure means step-by-step instructions for performing a specific task in accordance with policy and standards.

Incorrect Answers

Answer B is incorrect because Acceptable use policy would fit a different scenario. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

Answer C is incorrect because Security standard represents a different security function. Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter.

Answer D is incorrect because SDLC policy addresses a different requirement. SDLC policy refers to security requirements that apply across software planning, development, testing, release, and maintenance.

 

Question 10

To guide teams through common security events with less improvisation, which security approach should be selected?

  1. Acceptable use policy
  2. Industry requirement
  3. SDLC policy
  4. Playbook

Correct Answer: D

 

Correct Answer

Answer D is correct because Playbook means a predefined set of response or operational actions for a known scenario.

Incorrect Answers

Answer A is incorrect because Acceptable use policy addresses a different requirement. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

Answer B is incorrect because Industry requirement would fit a different scenario. Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks.

Answer C is incorrect because SDLC policy addresses a different security requirement. SDLC policy refers to security requirements that apply across software planning, development, testing, release, and maintenance.

 

Question 11

What is a security obligation imposed by a government or regulatory authority?

  1. Security policy
  2. Security committee
  3. Data owner
  4. Regulatory requirement

Correct Answer: D

 

Correct Answer

Answer D is correct because Regulatory requirement means a security obligation imposed by a government or regulatory authority.

Incorrect Answers

Answer A is incorrect because Security policy represents a different security function. Security policy refers to management-approved statement of required direction, expectations, and responsibilities.

Answer B is incorrect because Security committee would fit a different scenario. Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight.

Answer C is incorrect because Data owner addresses a different requirement. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

 

Question 12

To align controls with obligations or norms specific to a business sector, which security approach should be selected?

  1. SDLC policy
  2. Industry requirement
  3. Security policy
  4. Disaster recovery policy

Correct Answer: B

 

Correct Answer

Answer B is correct because Industry requirement means a security expectation arising from sector standards, contracts, or common industry frameworks.

Incorrect Answers

Answer A is incorrect because SDLC policy would fit a different scenario. SDLC policy refers to security requirements that apply across software planning, development, testing, release, and maintenance.

Answer C is incorrect because Security policy addresses a different security requirement. Security policy refers to management-approved statement of required direction, expectations, and responsibilities.

Answer D is incorrect because Disaster recovery policy addresses a different requirement. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

 

Question 13

Which term describes periodic review of policies and governance structures to keep them effective and current?

  1. Governance monitoring and revision
  2. Disaster recovery policy
  3. Security policy
  4. Acceptable use policy

Correct Answer: A

 

Correct Answer

Answer A is correct because Governance monitoring and revision means periodic review of policies and governance structures to keep them effective and current.

Incorrect Answers

Answer B is incorrect because Disaster recovery policy addresses a different requirement. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

Answer C is incorrect because Security policy represents a different security function. Security policy refers to management-approved statement of required direction, expectations, and responsibilities.

Answer D is incorrect because Acceptable use policy would fit a different scenario. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

 

Question 14

To provide high-level accountability and direction for organizational risk, which security approach should be selected?

  1. Board oversight
  2. Regulatory requirement
  3. Data processor
  4. Security procedure

Correct Answer: A

 

Correct Answer

Answer A is correct because Board oversight means governance exercised by a board or equivalent senior governing body.

Incorrect Answers

Answer B is incorrect because Regulatory requirement addresses a different requirement. Regulatory requirement refers to a security obligation imposed by a government or regulatory authority.

Answer C is incorrect because Data processor addresses a different security requirement. Data processor refers to an entity that processes personal data on behalf of a controller.

Answer D is incorrect because Security procedure would fit a different scenario. Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards.

 

Question 15

Which cross-functional or specialized group coordinates decisions, priorities, and oversight?

  1. Acceptable use policy
  2. Security guideline
  3. Security committee
  4. Data processor

Correct Answer: C

 

Correct Answer

Answer C is correct because Security committee means a cross-functional or specialized group that coordinates decisions, priorities, and oversight.

Incorrect Answers

Answer A is incorrect because Acceptable use policy addresses a different requirement. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

Answer B is incorrect because Security guideline represents a different security function. Security guideline refers to recommended practice that provides flexible guidance rather than a mandatory exact requirement.

Answer D is incorrect because Data processor would fit a different scenario. Data processor refers to an entity that processes personal data on behalf of a controller.

 

Question 16

To set protection requirements according to business value and risk, which security approach should be selected?

  1. Data owner
  2. Business continuity policy
  3. Security policy
  4. Acceptable use policy

Correct Answer: A

 

Correct Answer

Answer A is correct because Data owner means the role accountable for decisions about classification, access, and acceptable use of data.

Incorrect Answers

Answer B is incorrect because Business continuity policy addresses a different security requirement. Business continuity policy refers to governance direction for maintaining critical business functions during disruption.

Answer C is incorrect because Security policy would fit a different scenario. Security policy refers to management-approved statement of required direction, expectations, and responsibilities.

Answer D is incorrect because Acceptable use policy addresses a different requirement. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

 

Question 17

Which entity determines the purposes and means of processing personal data?

  1. Data controller
  2. Acceptable use policy
  3. Data owner
  4. Data custodian

Correct Answer: A

 

Correct Answer

Answer A is correct because Data controller means an entity that determines the purposes and means of processing personal data.

Incorrect Answers

Answer B is incorrect because Acceptable use policy represents a different security function. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

Answer C is incorrect because Data owner would fit a different scenario. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

Answer D is incorrect because Data custodian addresses a different requirement. Data custodian refers to a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.

 

Question 18

To perform data-processing activities under the controller’s instructions, which security approach should be selected?

  1. Security committee
  2. Data processor
  3. Security procedure
  4. Security policy

Correct Answer: B

 

Correct Answer

Answer B is correct because Data processor means an entity that processes personal data on behalf of a controller.

Incorrect Answers

Answer A is incorrect because Security committee addresses a different security requirement. Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight.

Answer C is incorrect because Security procedure would fit a different scenario. Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards.

Answer D is incorrect because Security policy addresses a different requirement. Security policy refers to management-approved statement of required direction, expectations, and responsibilities.

 

Question 19

What is a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements?

  1. Data custodian
  2. Disaster recovery policy
  3. Data owner
  4. Industry requirement

Correct Answer: A

 

Correct Answer

Answer A is correct because Data custodian means a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.

Incorrect Answers

Answer B is incorrect because Disaster recovery policy represents a different security function. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

Answer C is incorrect because Data owner addresses a different requirement. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

Answer D is incorrect because Industry requirement would fit a different scenario. Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks.

 

Question 20

To help teams make consistent security decisions when some discretion is appropriate, which security approach should be selected?

  1. Acceptable use policy
  2. Regulatory requirement
  3. Security guideline
  4. Data owner

Correct Answer: C

 

Correct Answer

Answer C is correct because Security guideline means recommended practice that provides flexible guidance rather than a mandatory exact requirement.

Incorrect Answers

Answer A is incorrect because Acceptable use policy would fit a different scenario. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

Answer B is incorrect because Regulatory requirement represents a different security function. Regulatory requirement refers to a security obligation imposed by a government or regulatory authority.

Answer D is incorrect because Data owner addresses a different requirement. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

 

Question 21

Which term describes management-approved statement of required direction, expectations, and responsibilities?

  1. Security guideline
  2. Security policy
  3. Industry requirement
  4. Playbook

Correct Answer: B

 

Correct Answer

Answer B is correct because Security policy means management-approved statement of required direction, expectations, and responsibilities.

Incorrect Answers

Answer A is incorrect because Security guideline addresses a different security requirement. Security guideline refers to recommended practice that provides flexible guidance rather than a mandatory exact requirement.

Answer C is incorrect because Industry requirement addresses a different requirement. Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks.

Answer D is incorrect because Playbook would fit a different scenario. Playbook refers to a predefined set of response or operational actions for a known scenario.

 

Question 22

To set user expectations for responsible technology use, which security approach should be selected?

  1. Governance monitoring and revision
  2. Security standard
  3. Regulatory requirement
  4. Acceptable use policy

Correct Answer: D

 

Correct Answer

Answer D is correct because Acceptable use policy means policy defining permitted and prohibited use of organizational systems, networks, and information.

Incorrect Answers

Answer A is incorrect because Governance monitoring and revision addresses a different requirement. Governance monitoring and revision refers to periodic review of policies and governance structures to keep them effective and current.

Answer B is incorrect because Security standard would fit a different scenario. Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter.

Answer C is incorrect because Regulatory requirement represents a different security function. Regulatory requirement refers to a security obligation imposed by a government or regulatory authority.

 

Question 23

Which term describes governance direction for maintaining critical business functions during disruption?

  1. Security procedure
  2. Security standard
  3. Playbook
  4. Business continuity policy

Correct Answer: D

 

Correct Answer

Answer D is correct because Business continuity policy means governance direction for maintaining critical business functions during disruption.

Incorrect Answers

Answer A is incorrect because Security procedure would fit a different scenario. Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards.

Answer B is incorrect because Security standard addresses a different security requirement. Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter.

Answer C is incorrect because Playbook addresses a different requirement. Playbook refers to a predefined set of response or operational actions for a known scenario.

 

Question 24

To define recovery expectations and responsibilities for IT capabilities, which security approach should be selected?

  1. Security standard
  2. Governance monitoring and revision
  3. Security guideline
  4. Disaster recovery policy

Correct Answer: D

 

Correct Answer

Answer D is correct because Disaster recovery policy means governance direction for restoring technology and services after a major disruption.

Incorrect Answers

Answer A is incorrect because Security standard would fit a different scenario. Security standard refers to a mandatory specific requirement supporting policy, such as an encryption level or password parameter.

Answer B is incorrect because Governance monitoring and revision addresses a different requirement. Governance monitoring and revision refers to periodic review of policies and governance structures to keep them effective and current.

Answer C is incorrect because Security guideline represents a different security function. Security guideline refers to recommended practice that provides flexible guidance rather than a mandatory exact requirement.

 

Question 25

Which term describes governance direction defining authority, responsibilities, and expectations for handling security incidents?

  1. Data owner
  2. Incident response policy
  3. Disaster recovery policy
  4. Data custodian

Correct Answer: B

 

Correct Answer

Answer B is correct because Incident response policy means governance direction defining authority, responsibilities, and expectations for handling security incidents.

Incorrect Answers

Answer A is incorrect because Data owner would fit a different scenario. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

Answer C is incorrect because Disaster recovery policy addresses a different requirement. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

Answer D is incorrect because Data custodian addresses a different security requirement. Data custodian refers to a role responsible for day-to-day handling, storage, or technical protection of data according to owner requirements.

 

Question 26

To embed security responsibilities into application lifecycle processes, which security approach should be selected?

  1. Board oversight
  2. SDLC policy
  3. Governance monitoring and revision
  4. Regulatory requirement

Correct Answer: B

 

Correct Answer

Answer B is correct because SDLC policy means security requirements that apply across software planning, development, testing, release, and maintenance.

Incorrect Answers

Answer A is incorrect because Board oversight addresses a different requirement. Board oversight refers to governance exercised by a board or equivalent senior governing body.

Answer C is incorrect because Governance monitoring and revision represents a different security function. Governance monitoring and revision refers to periodic review of policies and governance structures to keep them effective and current.

Answer D is incorrect because Regulatory requirement would fit a different scenario. Regulatory requirement refers to a security obligation imposed by a government or regulatory authority.

 

Question 27

What is a mandatory specific requirement supporting policy, such as an encryption level or password parameter?

  1. Data owner
  2. Security standard
  3. Security procedure
  4. Industry requirement

Correct Answer: B

 

Correct Answer

Answer B is correct because Security standard means a mandatory specific requirement supporting policy, such as an encryption level or password parameter.

Incorrect Answers

Answer A is incorrect because Data owner would fit a different scenario. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

Answer C is incorrect because Security procedure addresses a different security requirement. Security procedure refers to step-by-step instructions for performing a specific task in accordance with policy and standards.

Answer D is incorrect because Industry requirement addresses a different requirement. Industry requirement refers to a security expectation arising from sector standards, contracts, or common industry frameworks.

 

Question 28

To make security processes repeatable and operationally consistent, which security approach should be selected?

  1. Disaster recovery policy
  2. Business continuity policy
  3. Security procedure
  4. Acceptable use policy

Correct Answer: C

 

Correct Answer

Answer C is correct because Security procedure means step-by-step instructions for performing a specific task in accordance with policy and standards.

Incorrect Answers

Answer A is incorrect because Disaster recovery policy represents a different security function. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

Answer B is incorrect because Business continuity policy addresses a different requirement. Business continuity policy refers to governance direction for maintaining critical business functions during disruption.

Answer D is incorrect because Acceptable use policy would fit a different scenario. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

 

Question 29

What is a predefined set of response or operational actions for a known scenario?

  1. Security committee
  2. Data owner
  3. Playbook
  4. Incident response policy

Correct Answer: C

 

Correct Answer

Answer C is correct because Playbook means a predefined set of response or operational actions for a known scenario.

Incorrect Answers

Answer A is incorrect because Security committee would fit a different scenario. Security committee refers to a cross-functional or specialized group that coordinates decisions, priorities, and oversight.

Answer B is incorrect because Data owner addresses a different requirement. Data owner refers to the role accountable for decisions about classification, access, and acceptable use of data.

Answer D is incorrect because Incident response policy addresses a different security requirement. Incident response policy refers to governance direction defining authority, responsibilities, and expectations for handling security incidents.

 

Question 30

To ensure controls satisfy binding external rules, which security approach should be selected?

  1. Regulatory requirement
  2. Acceptable use policy
  3. Disaster recovery policy
  4. Incident response policy

Correct Answer: A

 

Correct Answer

Answer A is correct because Regulatory requirement means a security obligation imposed by a government or regulatory authority.

Incorrect Answers

Answer B is incorrect because Acceptable use policy would fit a different scenario. Acceptable use policy refers to policy defining permitted and prohibited use of organizational systems, networks, and information.

Answer C is incorrect because Disaster recovery policy represents a different security function. Disaster recovery policy refers to governance direction for restoring technology and services after a major disruption.

Answer D is incorrect because Incident response policy addresses a different requirement. Incident response policy refers to governance direction defining authority, responsibilities, and expectations for handling security incidents.

img