40 free CompTIA Security+ SY0-701 practice questions for Domain 5, Security Program Management and Oversight, which is about 20% of the exam. Each question has the correct answer and a clear explanation. No account or signup needed.
Last updated July 2026
A single incident is expected to cost $10,000, and it is expected to occur twice per year. What is the annualized loss expectancy (ALE)?
Correct answer: A. $20,000
ALE equals the single loss expectancy (SLE) times the annual rate of occurrence (ARO): $10,000 x 2 = $20,000. The SLE is the cost of one event and the ARO is how many times it happens per year.
Which metric defines the maximum acceptable amount of data loss, measured in time, after an incident?
Correct answer: A. Recovery point objective (RPO)
RPO is how much data, expressed as a time window, the organization can afford to lose, which drives backup frequency. RTO is how quickly service must be restored, and MTTR and MTBF measure repair and failure intervals.
Which assessment identifies the critical functions of an organization and the impact of their disruption in order to set recovery priorities?
Correct answer: A. Business impact analysis (BIA)
A BIA determines which functions are critical and the consequences of downtime, feeding recovery objectives like RTO and RPO. The other options assess security weaknesses, not business impact.
Where does an organization formally record its identified risks along with the owner, severity, and treatment status of each one?
Correct answer: A. Risk register
A risk register is the central document tracking identified risks, owners, scores, and how each is being handled. An SLA defines service commitments, an AUP defines acceptable system use, and a log records events.
Which document is a non-binding agreement that expresses the general intent of two parties to cooperate?
Correct answer: A. Memorandum of understanding (MOU)
An MOU records a mutual, generally non-binding intent to work together. An SLA sets measurable service terms, an NDA enforces confidentiality, and an SOW details specific work to be performed.
Which agreement legally obligates the parties to keep shared sensitive information confidential?
Correct answer: A. Non-disclosure agreement (NDA)
An NDA legally binds parties to protect confidential information they exchange. An MOU is a statement of intent, an SLA sets service levels, and an AUP governs how employees use systems.
Which policy defines what employees are and are not permitted to do with company systems, networks, and Internet access?
Correct answer: A. Acceptable use policy (AUP)
An AUP sets the rules for proper use of company technology. A business continuity plan keeps operations running during a disruption, an NDA protects confidentiality, and an SLA defines service commitments.
Requiring that two different employees each complete part of a sensitive financial transaction, so no single person can commit fraud alone, is which principle?
Correct answer: A. Separation of duties
Separation of duties splits a sensitive task so no one person controls it end to end, reducing fraud. Least privilege limits permissions, while job rotation and mandatory vacation help expose fraud over time.
Which United States regulation specifically protects the privacy and security of personal health information?
Correct answer: A. HIPAA
HIPAA governs the protection of health information in the United States. PCI DSS covers payment card data, GDPR is the European Union privacy regulation, and SOX addresses financial reporting.
The incident response team gathers in a room and verbally walks through how they would handle a ransomware scenario, without touching live systems. This exercise is a?
Correct answer: A. Tabletop exercise
A tabletop exercise is a discussion-based walkthrough of a scenario to validate the plan and roles. A full-scale test actually fails over systems, while penetration tests and vulnerability scans assess technical weaknesses.
A security manager wants a high-level document that states management's commitment to information security and assigns overall accountability. Which governance artifact is this?
Correct answer: D. Security policy
A security policy is a management-level statement of intent and accountability. Runbooks give operational steps, baselines define secure settings, and diagrams show topology, not governance commitment.
An organization requires that every security control implementation follow detailed, step-by-step instructions. Which document type provides that level of detail?
Correct answer: D. Procedure
Procedures are mandatory, ordered steps for performing a task. Guidelines are recommended practices, frameworks are broad structures, and mission statements describe purpose, not how-to steps.
Which role is primarily responsible for day-to-day handling, storage, and protection of data according to the rules set by management?
Correct answer: A. Data custodian
The data custodian implements protection and operational care of data. The subject is the individual the data describes, auditors assess controls, and marketing is not the stewardship role.
Which document gives optional best-practice recommendations that teams may adapt, rather than mandatory requirements?
Correct answer: A. Guideline
Guidelines are flexible recommendations. Standards set mandatory technical requirements, regulations are external legal mandates, and contracts create binding obligations between parties.
Senior leadership sets a rule that all production systems must use approved encryption algorithms. What type of governance document is this requirement?
Correct answer: A. Security standard
Standards define mandatory technical or operational requirements such as approved crypto. Timelines, packet captures, and user stories support investigations or development, not governance requirements.
A risk team scores likelihood and impact using categories like high, medium, and low without dollar estimates. Which analysis method is this?
Correct answer: C. Qualitative analysis
Qualitative analysis uses descriptive ratings. Quantitative analysis uses numerical financial measures. Regression testing and packet analysis are technical activities, not risk scoring methods.
Before any controls are applied, a critical system faces a high level of exposure. What is that starting risk level called?
Correct answer: B. Inherent risk
Inherent risk is the risk present without considering controls. Accepted risk is risk leadership chooses to live with, transfer shifts impact to another party, and an audit finding is a reported issue.
Leadership will tolerate only limited financial loss from cyber events each year. What concept describes that limit?
Correct answer: A. Risk appetite
Risk appetite is how much risk an organization is willing to take. Attack surface is exposure, MTTD is a detection metric, and port density is a network design detail.
A single theft of a laptop is expected to cost $4,000, and similar thefts occur about three times per year. What is the single loss expectancy (SLE)?
Correct answer: B. $4,000
SLE is the expected loss from one occurrence, here $4,000. $12,000 would be ALE if ARO is 3. The other figures mix annual and per-event values incorrectly.
After reviewing a low-impact risk, management documents that no further action will be taken and monitors it. Which risk response is this?
Correct answer: B. Risk acceptance
Acceptance knowingly retains a risk without new controls. Avoidance stops the activity, mitigation reduces risk with controls, and extinction is not a standard risk response term.
An organization installs multifactor authentication and network segmentation to reduce account-takeover risk. Which risk response best describes this?
Correct answer: A. Risk mitigation
Applying controls such as MFA and segmentation reduces likelihood or impact, which is mitigation. Transfer shifts the cost to another party such as an insurer, avoidance stops the risky activity entirely, and acceptance retains the risk unchanged.
A contract allows the customer to review a vendor's security controls and evidence on a scheduled basis. Which clause enables this?
Correct answer: B. Right-to-audit clause
A right-to-audit clause grants permission to assess the vendor. Non-compete limits competition, force majeure covers extraordinary events, and severability keeps a contract valid if one part fails.
Before onboarding a payroll SaaS provider, security sends a questionnaire covering encryption, access control, and incident handling. What process is this part of?
Correct answer: D. Vendor risk assessment
A security questionnaire sent to a prospective provider is part of vendor (third-party) risk assessment. A penetration test exploits systems, a BIA ranks internal functions by disruption impact, and a tabletop rehearses incident response.
A company relies on a cloud vendor that itself depends on an unreviewed subcontractor. What risk concern does this raise?
Correct answer: D. Supply chain risk
A vendor that depends on its own unreviewed subcontractors extends your supply chain, and every link in it can introduce exposure you never assessed. Side channels, hash collisions, and race conditions are technical vulnerability classes, not third-party layers.
Which report is commonly requested from a service provider to show independent assurance about security controls over a period of time?
Correct answer: B. SOC 2 Type II report
A SOC 2 Type II report is an independent auditor's assessment of how a provider's controls operated over a period, which is why customers request it for assurance. Marketing material, internal SLA stats, and self-attestations carry no independent weight.
An organization ends a contract with a managed IT provider. What third-party risk step should occur promptly?
Correct answer: D. Revoke accounts and recover company data
Offboarding a provider means promptly removing every access path it had and getting company data returned or destroyed. Leaving VPN access, granting standing admin rights, or waiting months leaves an open door nobody is watching.
Which agreement typically sets overarching legal terms for an ongoing commercial relationship that many work orders will reference?
Correct answer: B. Master service agreement
A master service agreement sets the overarching legal terms that individual statements of work then reference. An SLA defines measurable service targets, an SOW scopes one specific engagement, and an NDA covers confidentiality only.
A retailer must protect cardholder data environments and complete regular assessments under industry rules. Which standard is most directly in scope?
Correct answer: C. PCI DSS
PCI DSS is the industry standard governing cardholder data environments and their regular assessments. HIPAA covers health information, FERPA covers student records, and SOX covers financial reporting controls at public companies.
Under a privacy law, an individual asks an organization to delete personal data it holds about them, when allowed. What right is being exercised?
Correct answer: D. Right to erasure
Asking an organization to delete personal data exercises the right to erasure, often called the right to be forgotten. Access lets you see the data, rectification corrects it, and portability lets you take a copy elsewhere.
A company publishes how long different record types are kept before secure disposal. Which compliance program element is this?
Correct answer: C. Data retention policy
Retention policies define keep and dispose timelines for records. Honeynets, jitter, and banner grabbing relate to deception, timing, or reconnaissance, not retention compliance.
Which U.S. law requires public companies to maintain accurate financial reporting controls that often affect IT and access management?
Correct answer: C. Sarbanes-Oxley Act (SOX)
SOX requires public companies to maintain accurate financial reporting controls, which pulls IT access management and change control into audit scope. HIPAA covers health data, GLBA covers financial institutions' customer privacy, and FISMA covers federal agencies.
An independent firm reviews whether controls operated effectively throughout the past year and issues an opinion. What engagement is this?
Correct answer: C. External audit
An external audit is an independent examination of controls over a period or at a point in time. Tabletop and red team work test readiness, and UAT validates software features.
Internal staff evaluate control design against a framework but do not attempt exploitation. Which assessment best matches this?
Correct answer: B. Control self-assessment
When internal staff evaluate control design against a framework without attempting exploitation, that is a control self-assessment. An external audit is independent, a penetration test exploits, and a bug bounty invites outside researchers.
A SOC 2 Type I report differs from a Type II report mainly because Type I focuses on what?
Correct answer: A. Control design at a point in time
A Type I report evaluates whether controls are suitably designed at a moment in time. Operating effectiveness over a period is exactly what distinguishes a Type II, and neither report is limited to physical or privacy controls.
Auditors request system configurations, access reviews, and ticket histories as support for their conclusions. What are these materials called?
Correct answer: D. Audit evidence
Audit evidence is documentation used to support findings and opinions. Payloads, beacons, and implants are malware or attacker concepts, not assurance documentation.
Which assessment is performed by staff employed by the organization rather than by an outside firm?
Correct answer: D. Internal audit
An internal audit is performed by the organization's own audit function. External audits, regulatory exams, and third-party attestations are all conducted by people outside the organization.
Security sends realistic fake phishing emails and tracks who clicks or reports them. Which awareness practice is this?
Correct answer: A. Phishing simulation
Phishing simulations train and measure user response to deceptive mail. Revocation, degaussing, and VLAN hopping address crypto status, media sanitization, or network attacks.
Developers receive extra training on secure coding, while reception staff practice visitor escort rules. What training approach is this?
Correct answer: D. Role-based awareness training
Role-based training matches content to job duties. Teaching root access, shared passwords, or disabling MFA would weaken security rather than support awareness goals.
An employee receives an unexpected USB drive in the mail labeled as a free gift and is unsure whether to plug it in. What should awareness training emphasize?
Correct answer: D. Report it and do not connect unknown media
Unknown removable media is a common delivery vector, so users should report and avoid connecting it. Running as admin, sharing, or disabling protection increases infection risk.
After quarterly awareness campaigns, leadership wants a metric that shows whether fewer users fail simulated phishing. Which measure is most useful?
Correct answer: B. Click rate trend over time
Click rate trends indicate whether phishing awareness is improving. Firewall ports, disk speed, and cable colors do not measure human security behavior.
SecPlus Mastery covers all five SY0-701 domains with over 1,000 practice questions, timed mock exams, and spaced review that targets your weak spots so you walk in ready.
Original practice questions aligned to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.