CompTIA Security+ Domain 5: Security Program Management & Oversight
20% of the SY0-701 exam
Practice — Domain 5
5.1 Governance
A security team wants to publish a mandatory, high-level document that states management's intent that all company data be encrypted, without specifying which algorithms or key lengths to use. Which governance artifact best fits this need?
Answer
Correct answerC · A policy expressing mandatory management intent
A policy is the high-level, mandatory document that communicates management's intent and direction without dictating specific technical implementation details like algorithms.
Why the other options are wrong
AA procedure gives prescriptive step-by-step instructions for a task, which is far more granular than a high-level statement of management intent.
BA guideline provides discretionary, non-mandatory advice, but the requirement here is explicitly mandatory management intent, so a guideline does not fit.
DA standard specifies the mandatory technical details such as algorithms and key lengths, which is precisely what this document is meant to omit.
After a quantitative risk assessment, a retailer decides the residual likelihood of a costly data breach is still too high to absorb, so it purchases a cyber-insurance policy to cover potential breach losses. Which risk response does this represent?
Answer
Correct answerA · Transfer, shifting financial impact to a third party
Buying insurance moves the financial consequences of the risk to another party, which is the defining characteristic of the transfer response.
Why the other options are wrong
BAvoidance means eliminating the risky activity entirely; the retailer keeps operating and merely offsets cost, so this is not avoidance.
CAcceptance means knowingly retaining the risk without further action, but here the retailer takes action by buying coverage rather than absorbing it.
DMitigation reduces likelihood or impact through technical or administrative controls, whereas insurance does not lower the breach probability itself.
A hospital is finalizing a contract with a managed cloud provider and wants a binding clause guaranteeing 99.9% uptime with financial penalties if the provider fails to meet that availability target. Which agreement document should contain this commitment?
Answer
Correct answerD · Service level agreement specifying measurable targets
An SLA defines the measurable performance commitments, including uptime percentages and remedies or penalties when the provider misses agreed targets.
Why the other options are wrong
AAn MOU records broad mutual intentions and is typically non-binding, so it cannot enforce measurable uptime targets backed by penalties.
BA BPA governs the business relationship and responsibilities between partners, not specific measurable service performance levels like guaranteed uptime.
CAn NDA restricts disclosure of confidential information and says nothing about availability metrics or penalties for missed performance targets.
SLA defines measurable service targets and penalties. SY0-701 Obj 5.3
5.4 Compliance
An online bookstore decides what customer data to collect and why, then hires an external email-marketing firm that processes that data strictly under the bookstore's documented instructions. Under common privacy regulations, what is the marketing firm's role?
Answer
Correct answerB · Data processor acting on the controller's instructions
A processor handles personal data only on the controller's documented instructions, which exactly describes the marketing firm's limited role in this scenario.
Why the other options are wrong
AThe controller decides the purposes and means of processing; that is the bookstore here, not the firm acting on its instructions.
CThe data subject is the individual the personal data is about, such as the customers, not the company processing the records.
DThe data owner is an internal accountable role within the controlling organization, not an external third party processing data under contract.
Processor handles data on the controller's instructions. SY0-701 Obj 5.4
5.5 Audits and assessments
Before launching any active scans, a penetration tester gathers employee names, email formats, and public IP ranges using only search engines, social media, and WHOIS records, never touching the target's systems directly. Which activity is the tester performing?
Answer
Correct answerA · Passive reconnaissance using publicly available sources
Passive reconnaissance collects information from public sources without interacting with target systems, exactly matching the search-engine and WHOIS gathering described here.
Why the other options are wrong
BActive reconnaissance sends packets to or interacts with the target's systems, but the tester explicitly avoids touching those systems in this scenario.
CPrivilege escalation occurs after a foothold is gained and raises permissions, which is unrelated to pre-engagement public information gathering.
DLateral movement happens post-exploitation as the tester pivots across an internal network, not during external open-source information collection.
Public OSINT without touching systems = passive recon. SY0-701 Obj 5.5
5.6 Security awareness
An employee receives an urgent email appearing to be from the CEO, asking them to buy gift cards immediately and reply with the codes. Following the company's security awareness training, what is the best first action the employee should take?
Answer
Correct answerC · Report the message to security using the reporting process
Reporting the suspicious message through the established channel lets security investigate and warn others, which is the trained response to phishing.
Why the other options are wrong
AReplying engages the potential attacker and may confirm the address is active, while still trusting an unverified channel that could be spoofed.
BComplying immediately is exactly the outcome a business email compromise scam seeks, causing direct financial loss before any verification occurs.
DDeleting silently stops this user from acting but denies the security team visibility to protect coworkers who may receive the same attack.
Suspected phishing should be reported through the official process. SY0-701 Obj 5.6
5.1 Summarize elements of effective security governance (governance roles)
A database administrator configures the backup schedule, access permissions, and encryption settings for a customer database exactly as directed by the business unit that is accountable for that data. Which governance role is the administrator filling?
Answer
Correct answerB · Data custodian enforcing the controls
A data custodian performs the hands-on protective tasks such as backups, permissions, and encryption under the owner's direction, which exactly matches the administrator's implementing role described in the scenario.
Why the other options are wrong
AThe data owner is the senior accountable role that classifies the data and sets policy, which the directing business unit holds, not the administrator who merely carries out instructions.
CA data controller decides why and how data is processed at an organizational level, which is a determining role rather than the technical implementer following the owner's instructions here.
DA data processor is an external party handling data per a contract, but this administrator is an internal employee enforcing controls, so the processor label does not fit the situation.
rule + SY0-701 Obj 5.1
5.2 Explain elements of the risk management process (quantitative analysis)
An asset worth $200,000 is expected to lose 25% of its value each time a particular flood occurs, and historical records show the flood happens about twice per year. Using quantitative risk analysis, what is the annualized loss expectancy?
Answer
Correct answerC · $100,000, the annual loss value
Single loss expectancy is asset value times exposure factor, 200,000 times 0.25 equals 50,000; multiplying by the annual rate of two events yields the 100,000 annualized loss expectancy.
Why the other options are wrong
A$50,000 is the single loss expectancy from asset value times exposure factor, but the question asks for the annualized figure, which must also multiply by the annual rate of occurrence.
B$25,000 wrongly applies only the exposure factor to one share of the value and ignores both the single loss expectancy formula and the annual occurrence rate of two events.
D$400,000 multiplies the full asset value by the two events and never applies the exposure factor, badly overstating the loss because only a quarter of value is lost per flood.
rule + SY0-701 Obj 5.2
5.3 Explain processes associated with third-party risk assessment (agreements)
A bank wants a contractual provision that lets it, at any point during the engagement, inspect a cloud vendor's security controls and request evidence of compliance directly from the vendor. Which provision should the bank insist on?
Answer
Correct answerA · Insist on a right-to-audit clause
A right-to-audit clause grants the customer contractual permission to inspect the vendor's controls and demand compliance evidence on an ongoing basis, which is exactly the oversight power the bank wants.
Why the other options are wrong
BA memorandum of understanding records broad, often non-binding intentions between parties and does not by itself grant any enforceable standing right to inspect a vendor's internal security controls.
CA statement of work defines the specific deliverables, tasks, and timelines for an engagement, but it does not establish a recurring right to audit the vendor's compliance evidence on demand.
DA nondisclosure agreement restricts how shared confidential information may be disclosed and protects secrecy, yet it provides no mechanism for the bank to inspect or audit the vendor's controls.
rule + SY0-701 Obj 5.3
5.4 Summarize elements of effective security compliance (privacy)
A customer in a jurisdiction with strong privacy law emails a retailer demanding that all of their personal data be permanently deleted from the company's systems because they are withdrawing consent. Which privacy right is the customer exercising?
Answer
Correct answerD · Right to erasure of the data
The right to be forgotten, or erasure, lets a subject who withdraws consent require the controller to permanently delete their personal data, which exactly matches the customer's demand here.
Why the other options are wrong
AData portability lets a subject receive their data in a usable format to transfer to another provider, but this customer is demanding deletion, not a transferable copy of their records.
BBreach notification is the controller's duty to inform regulators and subjects after a security incident, which is unrelated to a customer's request to erase their personal data on demand.
CThe right of access lets a subject obtain confirmation and a copy of data held about them, whereas this customer wants the records removed entirely rather than merely viewing them.
rule + SY0-701 Obj 5.4
5.5 Explain types and purposes of audits and assessments (penetration testing)
A company hires testers and provides them with no prior knowledge of the network, no IP addresses, no architecture diagrams, and no credentials, to simulate an external attacker discovering everything from scratch. Which type of penetration test is this?
Answer
Correct answerB · Unknown environment, no details
An unknown environment, or black-box, test withholds all internal details so the testers must discover the network from scratch like an outside attacker, exactly as the scenario describes for this engagement.
Why the other options are wrong
AA known environment, or white-box, test gives the testers full documentation, credentials, and architecture details up front, which is the opposite of the no-information conditions described in this engagement.
CA partially known, or gray-box, test supplies the testers with some limited information such as user-level credentials, but here they are deliberately given absolutely nothing to start from.
DAn integrated exercise continuously combines offensive and defensive teams throughout operations, which describes a program model rather than the level of prior knowledge given to the testers here.
A normally nine-to-five employee begins logging in at 3 a.m. and downloading large volumes of files from outside their department, just days after being passed over for a promotion. Awareness training teaches staff to recognize and report this as what?
Answer
Correct answerC · A potential insider threat
Off-hours access, bulk downloads outside one's role, and a recent grievance are classic indicators of a potential insider threat that awareness programs train staff to recognize and report promptly.
Why the other options are wrong
APhishing involves a deceptive inbound message luring the user to click or reveal data, but the described pattern is the employee's own unusual activity, not an external social-engineering lure aimed at them.
BRoutine maintenance is scheduled, authorized work, whereas unannounced 3 a.m. logins and bulk downloads from another department after a grievance are unauthorized indicators rather than legitimate maintenance activity.
DA removable-media violation involves unauthorized USB or external storage use, but nothing here mentions external media; the real concern is anomalous account behavior signaling a possible insider threat.
rule + SY0-701 Obj 5.6
5.1 Summarize elements of effective security governance (policy vs standard vs procedure vs guideline)
A security architect publishes a mandatory document stating that every internet-facing server must enforce TLS 1.2 or higher and AES-256 encryption for data at rest. It dictates specific required technical settings rather than intent or step-by-step actions. Which governance document type is this?
Answer
Correct answerD · Standard
A standard defines the mandatory specific technical requirements, such as exact protocol versions and encryption strengths, that support a broader policy and must be uniformly enforced.
Why the other options are wrong
AA policy states high-level management intent and broad direction, but it deliberately avoids naming specific technical values like exact cipher suites or required minimum encryption strengths.
BA procedure lays out the ordered step-by-step actions someone follows to complete a task, rather than declaring the mandatory technical configuration values that systems must meet.
CA guideline offers optional recommended best practice that staff may adapt, so it cannot impose the mandatory enforceable technical requirements that this document clearly establishes for servers.
NIST SP 800-12 Rev.1 §5.1 · SY0-701 Obj 5.1
5.2 Explain elements of the risk management process (quantitative ARO/SLE/ALE)
An analyst values each field laptop at $4,000. If one is lost, the entire device is considered a total loss with an exposure factor of one hundred percent. Loss records show three laptops disappear every year. Using quantitative risk analysis, what is the annualized loss expectancy?
Answer
Correct answerB · $12,000
Single loss expectancy of $4,000 multiplied by the annualized rate of occurrence of three incidents per year correctly produces an annualized loss expectancy of twelve thousand dollars.
Why the other options are wrong
AThis figure is only the single loss expectancy for one device, calculated from asset value times exposure factor, and ignores how often the loss happens each year.
CThis wrongly divides the asset value by the rate of occurrence, inverting the formula; annualized loss expectancy multiplies the per-incident loss by frequency rather than dividing.
DThis incorrectly adds the asset value and an unrelated figure together; the annualized loss expectancy formula requires multiplying single loss expectancy by the annual occurrence rate.
5.3 Explain types of agreements used in third-party risk management (MOU vs MSA vs SOW vs BPA)
Two universities want to record their shared intention to collaborate on a joint research program. The document expresses mutual goals and general understanding but is deliberately non-binding, with no payment, deliverables, or enforceable legal obligations attached. Which agreement type best matches this need?
Answer
Correct answerA · Memorandum of understanding (MOU)
A memorandum of understanding records the shared intentions and mutual expectations of parties in a non-binding way, exactly fitting a collaboration with no enforceable deliverables or payment terms.
Why the other options are wrong
BA statement of work defines the specific deliverables, timelines, and tasks for a particular engagement, making it far too detailed and binding for a general non-binding declaration of intent.
CA master service agreement establishes the overarching contractual terms governing future paid engagements between parties, which is binding and transactional rather than a simple statement of shared intent.
DA business partners agreement defines how two profit-sharing partners run a joint venture and split responsibilities, which exceeds the simple non-binding research collaboration described in the scenario.
NIST SP 800-47 Rev.1 (MOU) · SY0-701 Obj 5.3
5.4 Summarize elements of effective security compliance (due care vs due diligence)
Before signing a contract, a company thoroughly investigates a prospective cloud provider by reviewing its SOC 2 report, financial stability, and breach history to confirm the vendor is trustworthy. This investigative vetting performed prior to the decision best illustrates which concept?
Answer
Correct answerC · Due diligence
Due diligence is the research and investigation conducted before a decision to verify a vendor's trustworthiness, precisely matching reviewing audit reports, finances, and breach history pre-contract.
Why the other options are wrong
ADue care refers to the ongoing reasonable actions an organization takes to protect assets after a decision, not the upfront investigation performed to evaluate a vendor beforehand.
BSeparation of duties splits a sensitive task among multiple people to prevent fraud, which concerns internal control design and has nothing to do with researching an external vendor.
DA gap analysis compares current controls against a target framework to find shortfalls, which measures internal compliance posture rather than vetting an outside provider before engagement.
5.5 Explain types and purposes of audits and assessments (penetration test environment knowledge)
A company hires a penetration tester and provides absolutely no internal information: no credentials, no source code, and no network diagrams. The tester must discover the entire attack surface independently, simulating an external adversary with zero prior knowledge. Which testing environment does this describe?
Answer
Correct answerD · Unknown environment
An unknown environment test withholds all internal information so the tester must enumerate everything from scratch, accurately simulating an outside attacker with zero prior knowledge of the target.
Why the other options are wrong
AA known environment test supplies the tester full internal details like architecture diagrams and credentials, which directly contradicts the scenario where absolutely no information is provided beforehand.
BA partially known environment gives the tester some limited information such as a user account or basic diagrams, but here the tester receives no internal details at all.
CA bug bounty crowdsources many independent researchers to find flaws for rewards, describing a sourcing model rather than the knowledge level granted to a single contracted tester.
5.6 Implement security awareness practices (insider-threat indicators and reporting)
During security awareness training, staff learn to recognize and report behaviors that may signal a malicious insider. Of the following observed employee behaviors, which one is the strongest indicator that should be escalated as a potential insider threat?
Answer
Correct answerB · Bulk-copying confidential files unrelated to the role onto a personal USB drive
Bulk exfiltration of sensitive data outside one's job duties onto removable personal media is a classic insider-threat indicator that warrants immediate escalation and investigation.
Why the other options are wrong
ANeeding a password reset after extended leave is routine account maintenance expected of returning staff, so it is not a meaningful indicator of malicious insider activity.
CReporting suspected phishing is exactly the positive security behavior training encourages, demonstrating vigilance rather than signaling any malicious intent that would require escalation as a threat.
DCompleting mandatory recurring awareness training is normal expected compliance with company policy and reflects good security hygiene, not behavior suggesting a potential malicious insider.
5.1 Summarize elements of effective security governance (data roles: controller vs processor vs custodian vs steward)
A retail company decides which customer personal data to collect and the exact purposes for collecting it, then hires an external marketing firm to handle that data only as instructed. Under data-governance roles, what is the retail company?
Answer
Correct answerA · Data controller
Correct: the party that determines the purposes and means of processing personal data is the controller, regardless of who physically handles or stores the records.
Why the other options are wrong
BIncorrect because the processor only acts on the controller's documented instructions; here the marketing firm, not the retailer, fills that subordinate processing role.
CIncorrect because a custodian merely implements and maintains technical controls protecting data; it does not decide why personal data is collected or processed.
DIncorrect because a steward oversees data quality and policy compliance day to day, not the legal purpose-setting authority that defines the controller role.
EU Commission GDPR (controller/processor) + CompTIA SY0-701 Obj 5.1
5.2 Explain elements of the risk management process (BIA terms RTO/RPO/MTTR/MTBF)
A backup administrator is told the business can tolerate losing at most four hours of transaction data if the database fails, so backups must run at least that frequently. Which business-impact metric does this four-hour limit define?
Answer
Correct answerC · Recovery point objective
Correct: RPO specifies the maximum acceptable amount of data loss expressed in time, which directly drives how frequently backups must be taken.
Why the other options are wrong
AIncorrect because RTO defines how quickly a system must be restored after an outage, not the amount of data loss tolerable before the failure.
BIncorrect because MTTR measures the average time needed to fix a failed component, not the permissible window of lost data measured in time.
DIncorrect because MTBF estimates average operational time between failures for reliability planning, not the tolerable amount of data loss after an incident.
5.3 Explain the processes associated with third-party risk assessment and management (agreement types)
A company is finalizing a cloud contract and wants a document that legally commits the vendor to 99.9% monthly uptime, with service credits owed whenever that target is missed. Which agreement should they use?
Answer
Correct answerB · Service-level agreement
Correct: an SLA defines measurable performance commitments such as uptime percentages and the specific remedies or credits owed when those metrics are not met.
Why the other options are wrong
AIncorrect because an MOU expresses non-binding intent to cooperate and rarely defines enforceable performance metrics or financial penalties for missed service targets.
CIncorrect because an NDA governs how confidential information shared between parties is protected, not measurable operational performance or guaranteed uptime levels.
DIncorrect because an SOW details specific deliverables, tasks, and timelines for a project, not ongoing operational performance thresholds like monthly uptime.
5.4 Summarize elements of effective security compliance (compliance monitoring: attestation)
During a compliance review, an organization's CISO must formally sign a statement affirming to external auditors that the required security controls are implemented and operating effectively. This signed affirmation is an example of what?
Answer
Correct answerD · Attestation
Correct: attestation is a formal signed statement affirming that controls or conditions are accurate and effective, often supplied to support compliance reporting.
Why the other options are wrong
AIncorrect because an acknowledgement merely confirms a person received or read a policy, not a formal signed assertion that controls are operating effectively.
BIncorrect because due diligence is the investigative effort to assess risk before acting, not the signed affirmation of control effectiveness produced afterward.
CIncorrect because an internal audit is the independent examination staff perform; the signed assertion of control status is a separate compliance output.
NIST Glossary (ISO/IEC 17000:2020 via EO 14028) + CompTIA SY0-701 Obj 5.4/5.5
5.5 Explain types and purposes of audits and assessments (penetration testing: offensive/defensive/integrated teams)
To improve detection, an organization runs an exercise where its offensive testers and defensive analysts collaborate in real time, sharing attack techniques and tuning alerts together as the simulation unfolds. Which team approach is this?
Answer
Correct answerC · Purple team
Correct: a purple team integrates offensive and defensive personnel so they continuously share findings, improving detection and response together throughout the exercise.
Why the other options are wrong
AIncorrect because a red team works adversarially and independently to breach defenses, without openly collaborating with defenders while the exercise is underway.
BIncorrect because the blue team focuses solely on defense and monitoring; this scenario describes joint offensive and defensive collaboration rather than defense alone.
DIncorrect because the white team referees and coordinates an exercise's rules and scope; it does not perform the combined attack-and-defend tuning described here.
5.6 Implement security awareness practices (phishing campaigns and recognition)
A security awareness team periodically sends simulated phishing emails to all employees and tracks who clicks, then uses the results to target follow-up training and measure improvement over time. What is this activity called?
Answer
Correct answerB · Phishing campaign
Correct: a phishing campaign sends controlled simulated phishing messages to test and train user recognition, tracking click rates to measure awareness improvement over time.
Why the other options are wrong
AIncorrect because a vulnerability scan probes systems for technical weaknesses automatically, not employees' susceptibility to deceptive emails through controlled social engineering.
CIncorrect because a security audit formally evaluates controls and compliance against standards, not employees' real-time responses to simulated phishing messages.
DIncorrect because a tabletop exercise is a discussion-based walkthrough of an incident scenario, not an active test of users clicking simulated emails.
Ad slot · in-content rectangle (336×280 / responsive)Below the quiz card, inside the article body — well clear of answer buttons
About this domain
Where the other four domains are hands-on, Security Program Management & Oversight zooms out to the governance level — and it carries 20% of the SY0-701 exam. Instead of configuring a firewall or analyzing malware, here you are asked who signs off on policy, how risk gets measured and treated, and what a contract must say before data ever reaches a vendor. The exam tests whether you can tell a policy from a standard, procedure, or guideline, and whether you understand the governance roles and data roles, such as controller, processor, custodian, and steward, that decide who is accountable for what.
Risk management is heavily quantitative. Expect to calculate SLE, ARO, and ALE, weigh risk responses such as accept, avoid, transfer, and mitigate, and recognize when buying cyber insurance is a transfer decision rather than a fix. Business impact terms like RTO, RPO, MTTR, and MTBF show up alongside third-party agreements, where you must match the right document, MOU, MSA, SOW, BPA, or an SLA with uptime penalties, to the right situation.
The domain closes with compliance topics like privacy, due care versus due diligence, and attestation, plus audits and assessments including penetration testing team types, and security awareness practices such as phishing campaigns and insider-threat recognition.
What Domain 5 covers
5.1 Governance: roles, and policy vs standard vs procedure vs guideline
5.1 Data roles: controller, processor, custodian, and steward
5.2 Risk management process and quantitative analysis (SLE, ARO, ALE)
5.2 Risk responses and business impact terms (RTO, RPO, MTTR, MTBF)