Security+ Domain 5 Practice Questions: Security Program Management and Oversight
40 free CompTIA Security+ SY0-701 practice questions for Domain 5, Security Program Management and Oversight, which is about 20% of the exam. Each question has the correct answer and a clear explanation. No account or signup needed.
Last updated August 2026
- Question 1
A single incident is expected to cost $10,000, and it is expected to occur twice per year. What is the annualized loss expectancy (ALE)?
- A$10,000
- B$20,000
- C$5,000
- D$40,000
Show answer and explanation
Correct answer: B. $20,000
ALE equals the single loss expectancy (SLE) times the annual rate of occurrence (ARO): $10,000 x 2 = $20,000. The SLE is the cost of one event and the ARO is how many times it happens per year.
- Question 2
Which metric defines the maximum acceptable amount of data loss, measured in time, after an incident?
- ARecovery time objective (RTO)
- BMean time to repair (MTTR)
- CRecovery point objective (RPO)
- DMean time between failures (MTBF)
Show answer and explanation
Correct answer: C. Recovery point objective (RPO)
RPO is how much data, expressed as a time window, the organization can afford to lose, which drives backup frequency. RTO is how quickly service must be restored, and MTTR and MTBF measure repair and failure intervals.
- Question 3
Which assessment identifies the critical functions of an organization and the impact of their disruption in order to set recovery priorities?
- APenetration test
- BGap analysis
- CBusiness impact analysis (BIA)
- DVulnerability scan
Show answer and explanation
Correct answer: C. Business impact analysis (BIA)
A BIA determines which functions are critical and the consequences of downtime, feeding recovery objectives like RTO and RPO. The other options assess security weaknesses, not business impact.
- Question 4
Where does an organization formally record its identified risks along with the owner, severity, and treatment status of each one?
- AService level agreement
- BRisk register
- CAcceptable use policy
- DSystem log
Show answer and explanation
Correct answer: B. Risk register
A risk register is the central document tracking identified risks, owners, scores, and how each is being handled. An SLA defines service commitments, an AUP defines acceptable system use, and a log records events.
- Question 5
Which document is a non-binding agreement that expresses the general intent of two parties to cooperate?
- AMemorandum of understanding (MOU)
- BStatement of work (SOW)
- CNon-disclosure agreement (NDA)
- DService level agreement (SLA)
Show answer and explanation
Correct answer: A. Memorandum of understanding (MOU)
An MOU records a mutual, generally non-binding intent to work together. An SLA sets measurable service terms, an NDA enforces confidentiality, and an SOW details specific work to be performed.
- Question 6
Which agreement legally obligates the parties to keep shared sensitive information confidential?
- ANon-disclosure agreement (NDA)
- BAcceptable use policy (AUP)
- CMemorandum of understanding (MOU)
- DService level agreement (SLA)
Show answer and explanation
Correct answer: A. Non-disclosure agreement (NDA)
An NDA legally binds parties to protect confidential information they exchange. An MOU is a statement of intent, an SLA sets service levels, and an AUP governs how employees use systems.
- Question 7
Which policy defines what employees are and are not permitted to do with company systems, networks, and Internet access?
- ABusiness continuity plan
- BService level agreement
- CAcceptable use policy (AUP)
- DNon-disclosure agreement
Show answer and explanation
Correct answer: C. Acceptable use policy (AUP)
An AUP sets the rules for proper use of company technology. A business continuity plan keeps operations running during a disruption, an NDA protects confidentiality, and an SLA defines service commitments.
- Question 8
Requiring that two different employees each complete part of a sensitive financial transaction, so no single person can commit fraud alone, is which principle?
- ALeast privilege
- BSeparation of duties
- CJob rotation
- DMandatory vacation
Show answer and explanation
Correct answer: B. Separation of duties
Separation of duties splits a sensitive task so no one person controls it end to end, reducing fraud. Least privilege limits permissions, while job rotation and mandatory vacation help expose fraud over time.
- Question 9
Which United States regulation specifically protects the privacy and security of personal health information?
- AHIPAA
- BSOX
- CPCI DSS
- DGDPR
Show answer and explanation
Correct answer: A. HIPAA
HIPAA governs the protection of health information in the United States. PCI DSS covers payment card data, GDPR is the European Union privacy regulation, and SOX addresses financial reporting.
- Question 10
The incident response team gathers in a room and verbally walks through how they would handle a ransomware scenario, without touching live systems. This exercise is a?
- AFull-scale failover test
- BPenetration test
- CVulnerability scan
- DTabletop exercise
Show answer and explanation
Correct answer: D. Tabletop exercise
A tabletop exercise is a discussion-based walkthrough of a scenario to validate the plan and roles. A full-scale test actually fails over systems, while penetration tests and vulnerability scans assess technical weaknesses.
- Question 11
A security manager wants a high-level document that states management's commitment to information security and assigns overall accountability. Which governance artifact is this?
- ASecurity policy
- BRunbook
- CConfiguration baseline
- DNetwork diagram
Show answer and explanation
Correct answer: A. Security policy
A security policy is a management-level statement of intent and accountability. Runbooks give operational steps, baselines define secure settings, and diagrams show topology, not governance commitment.
- Question 12
An organization requires that every security control implementation follow detailed, step-by-step instructions. Which document type provides that level of detail?
- AGuideline
- BProcedure
- CFramework overview
- DMission statement
Show answer and explanation
Correct answer: B. Procedure
Procedures are mandatory, ordered steps for performing a task. Guidelines are recommended practices, frameworks are broad structures, and mission statements describe purpose, not how-to steps.
- Question 13
Which role is primarily responsible for day-to-day handling, storage, and protection of data according to the rules set by management?
- AExternal auditor
- BData subject
- CMarketing stakeholder
- DData custodian
Show answer and explanation
Correct answer: D. Data custodian
The data custodian implements protection and operational care of data. The subject is the individual the data describes, auditors assess controls, and marketing is not the stewardship role.
- Question 14
Which document gives optional best-practice recommendations that teams may adapt, rather than mandatory requirements?
- AGuideline
- BStandard
- CContract
- DRegulation
Show answer and explanation
Correct answer: A. Guideline
Guidelines are flexible recommendations. Standards set mandatory technical requirements, regulations are external legal mandates, and contracts create binding obligations between parties.
- Question 15
Senior leadership sets a rule that all production systems must use approved encryption algorithms. What type of governance document is this requirement?
- ASecurity standard
- BIncident timeline
- CPacket capture
- DUser story
Show answer and explanation
Correct answer: A. Security standard
Standards define mandatory technical or operational requirements such as approved crypto. Timelines, packet captures, and user stories support investigations or development, not governance requirements.
- Question 16
A risk team scores likelihood and impact using categories like high, medium, and low without dollar estimates. Which analysis method is this?
- AQualitative analysis
- BRegression testing
- CPacket analysis
- DQuantitative analysis
Show answer and explanation
Correct answer: A. Qualitative analysis
Qualitative analysis uses descriptive ratings. Quantitative analysis uses numerical financial measures. Regression testing and packet analysis are technical activities, not risk scoring methods.
- Question 17
Before any controls are applied, a critical system faces a high level of exposure. What is that starting risk level called?
- AAccepted risk
- BTransfer risk
- CAudit finding
- DInherent risk
Show answer and explanation
Correct answer: D. Inherent risk
Inherent risk is the risk present without considering controls. Accepted risk is risk leadership chooses to live with, transfer shifts impact to another party, and an audit finding is a reported issue.
- Question 18
Leadership will tolerate only limited financial loss from cyber events each year. What concept describes that limit?
- ARisk appetite
- BAttack surface
- CMean time to detect
- DPort density
Show answer and explanation
Correct answer: A. Risk appetite
Risk appetite is how much risk an organization is willing to take. Attack surface is exposure, MTTD is a detection metric, and port density is a network design detail.
- Question 19
A single theft of a laptop is expected to cost $4,000, and similar thefts occur about three times per year. What is the single loss expectancy (SLE)?
- A$4,000
- B$1,333
- C$7,000
- D$12,000
Show answer and explanation
Correct answer: A. $4,000
SLE is the expected loss from one occurrence, here $4,000. $12,000 would be ALE if ARO is 3. The other figures mix annual and per-event values incorrectly.
- Question 20
After reviewing a low-impact risk, management documents that no further action will be taken and monitors it. Which risk response is this?
- ARisk acceptance
- BRisk mitigation
- CRisk extinction
- DRisk avoidance
Show answer and explanation
Correct answer: A. Risk acceptance
Acceptance knowingly retains a risk without new controls. Avoidance stops the activity, mitigation reduces risk with controls, and extinction is not a standard risk response term.
- Question 21
An organization installs multifactor authentication and network segmentation to reduce account-takeover risk. Which risk response best describes this?
- ARisk acceptance
- BRisk avoidance
- CRisk transfer
- DRisk mitigation
Show answer and explanation
Correct answer: D. Risk mitigation
Applying controls such as MFA and segmentation reduces likelihood or impact, which is mitigation. Transfer shifts the cost to another party such as an insurer, avoidance stops the risky activity entirely, and acceptance retains the risk unchanged.
- Question 22
A contract allows the customer to review a vendor's security controls and evidence on a scheduled basis. Which clause enables this?
- ASeverability clause
- BRight-to-audit clause
- CNon-compete clause
- DForce majeure clause
Show answer and explanation
Correct answer: B. Right-to-audit clause
A right-to-audit clause grants permission to assess the vendor. Non-compete limits competition, force majeure covers extraordinary events, and severability keeps a contract valid if one part fails.
- Question 23
Before onboarding a payroll SaaS provider, security sends a questionnaire covering encryption, access control, and incident handling. What process is this part of?
- AVendor risk assessment
- BBusiness impact analysis
- CPenetration test
- DTabletop exercise
Show answer and explanation
Correct answer: A. Vendor risk assessment
A security questionnaire sent to a prospective provider is part of vendor (third-party) risk assessment. A penetration test exploits systems, a BIA ranks internal functions by disruption impact, and a tabletop rehearses incident response.
- Question 24
A company relies on a cloud vendor that itself depends on an unreviewed subcontractor. What risk concern does this raise?
- ASide-channel risk
- BSupply chain risk
- CRace condition risk
- DCollision risk
Show answer and explanation
Correct answer: B. Supply chain risk
A vendor that depends on its own unreviewed subcontractors extends your supply chain, and every link in it can introduce exposure you never assessed. Side channels, hash collisions, and race conditions are technical vulnerability classes, not third-party layers.
- Question 25
Which report is commonly requested from a service provider to show independent assurance about security controls over a period of time?
- ASOC 2 Type II report
- BInternal helpdesk SLA report
- CVendor marketing whitepaper
- DSelf-signed attestation letter
Show answer and explanation
Correct answer: A. SOC 2 Type II report
A SOC 2 Type II report is an independent auditor's assessment of how a provider's controls operated over a period, which is why customers request it for assurance. Marketing material, internal SLA stats, and self-attestations carry no independent weight.
- Question 26
An organization ends a contract with a managed IT provider. What third-party risk step should occur promptly?
- AWait until the next annual audit
- BGrant permanent admin rights for support
- CKeep vendor VPN access active as a courtesy
- DRevoke accounts and recover company data
Show answer and explanation
Correct answer: D. Revoke accounts and recover company data
Offboarding a provider means promptly removing every access path it had and getting company data returned or destroyed. Leaving VPN access, granting standing admin rights, or waiting months leaves an open door nobody is watching.
- Question 27
Which agreement typically sets overarching legal terms for an ongoing commercial relationship that many work orders will reference?
- AService level agreement
- BMaster service agreement
- CStatement of work
- DNon-disclosure agreement
Show answer and explanation
Correct answer: B. Master service agreement
A master service agreement sets the overarching legal terms that individual statements of work then reference. An SLA defines measurable service targets, an SOW scopes one specific engagement, and an NDA covers confidentiality only.
- Question 28
A retailer must protect cardholder data environments and complete regular assessments under industry rules. Which standard is most directly in scope?
- APCI DSS
- BSOX
- CFERPA
- DHIPAA
Show answer and explanation
Correct answer: A. PCI DSS
PCI DSS is the industry standard governing cardholder data environments and their regular assessments. HIPAA covers health information, FERPA covers student records, and SOX covers financial reporting controls at public companies.
- Question 29
Under a privacy law, an individual asks an organization to delete personal data it holds about them, when allowed. What right is being exercised?
- ARight to rectification
- BRight to erasure
- CRight of access
- DRight to data portability
Show answer and explanation
Correct answer: B. Right to erasure
Asking an organization to delete personal data exercises the right to erasure, often called the right to be forgotten. Access lets you see the data, rectification corrects it, and portability lets you take a copy elsewhere.
- Question 30
A company publishes how long different record types are kept before secure disposal. Which compliance program element is this?
- AData retention policy
- BJitter configuration
- CHoneynet design
- DBanner grabbing guide
Show answer and explanation
Correct answer: A. Data retention policy
Retention policies define keep and dispose timelines for records. Honeynets, jitter, and banner grabbing relate to deception, timing, or reconnaissance, not retention compliance.
- Question 31
Which U.S. law requires public companies to maintain accurate financial reporting controls that often affect IT and access management?
- AFISMA
- BGLBA
- CHIPAA
- DSarbanes-Oxley Act (SOX)
Show answer and explanation
Correct answer: D. Sarbanes-Oxley Act (SOX)
SOX requires public companies to maintain accurate financial reporting controls, which pulls IT access management and change control into audit scope. HIPAA covers health data, GLBA covers financial institutions' customer privacy, and FISMA covers federal agencies.
- Question 32
An independent firm reviews whether controls operated effectively throughout the past year and issues an opinion. What engagement is this?
- AUser acceptance testing
- BRed team debrief only
- CExternal audit
- DTabletop exercise
Show answer and explanation
Correct answer: C. External audit
An external audit is an independent examination of controls over a period or at a point in time. Tabletop and red team work test readiness, and UAT validates software features.
- Question 33
Internal staff evaluate control design against a framework but do not attempt exploitation. Which assessment best matches this?
- AControl self-assessment
- BExternal compliance audit
- CBug bounty program
- DPenetration test
Show answer and explanation
Correct answer: A. Control self-assessment
When internal staff evaluate control design against a framework without attempting exploitation, that is a control self-assessment. An external audit is independent, a penetration test exploits, and a bug bounty invites outside researchers.
- Question 34
A SOC 2 Type I report differs from a Type II report mainly because Type I focuses on what?
- AControl design at a point in time
- BOnly privacy controls
- COnly physical security controls
- DOperating effectiveness over a period
Show answer and explanation
Correct answer: A. Control design at a point in time
A Type I report evaluates whether controls are suitably designed at a moment in time. Operating effectiveness over a period is exactly what distinguishes a Type II, and neither report is limited to physical or privacy controls.
- Question 35
Auditors request system configurations, access reviews, and ticket histories as support for their conclusions. What are these materials called?
- AC2 implants
- BAudit evidence
- CExploit payloads
- DBeacon intervals
Show answer and explanation
Correct answer: B. Audit evidence
Audit evidence is documentation used to support findings and opinions. Payloads, beacons, and implants are malware or attacker concepts, not assurance documentation.
- Question 36
Which assessment is performed by staff employed by the organization rather than by an outside firm?
- AThird-party attestation
- BInternal audit
- CExternal audit
- DRegulatory examination
Show answer and explanation
Correct answer: B. Internal audit
An internal audit is performed by the organization's own audit function. External audits, regulatory exams, and third-party attestations are all conducted by people outside the organization.
- Question 37
Security sends realistic fake phishing emails and tracks who clicks or reports them. Which awareness practice is this?
- ADisk degaussing
- BCertificate revocation
- CPhishing simulation
- DVLAN hopping drill
Show answer and explanation
Correct answer: C. Phishing simulation
Phishing simulations train and measure user response to deceptive mail. Revocation, degaussing, and VLAN hopping address crypto status, media sanitization, or network attacks.
- Question 38
Developers receive extra training on secure coding, while reception staff practice visitor escort rules. What training approach is this?
- AShared password workshops
- BRole-based awareness training
- CDisable-MFA coaching
- DUniversal root access training
Show answer and explanation
Correct answer: B. Role-based awareness training
Role-based training matches content to job duties. Teaching root access, shared passwords, or disabling MFA would weaken security rather than support awareness goals.
- Question 39
An employee receives an unexpected USB drive in the mail labeled as a free gift and is unsure whether to plug it in. What should awareness training emphasize?
- ADisable endpoint protection to test it
- BReport it and do not connect unknown media
- CImmediately run the executable as admin
- DShare the drive with coworkers first
Show answer and explanation
Correct answer: B. Report it and do not connect unknown media
Unknown removable media is a common delivery vector, so users should report and avoid connecting it. Running as admin, sharing, or disabling protection increases infection risk.
- Question 40
After quarterly awareness campaigns, leadership wants a metric that shows whether fewer users fail simulated phishing. Which measure is most useful?
- ANumber of open firewall ports
- BDisk rotational speed
- CCable color standards
- DClick rate trend over time
Show answer and explanation
Correct answer: D. Click rate trend over time
Click rate trends indicate whether phishing awareness is improving. Firewall ports, disk speed, and cable colors do not measure human security behavior.
Master every domain
A free account opens all of Domain 1: a lesson, a hands-on lab and a graded question bank on every objective, plus a placement check and a dated plan. No card.
FAQ
Are these Security+ Domain 5 practice questions free?
Yes. Every question on this page is free, with the correct answer and an explanation. No account, payment, or download is required.How much of the Security+ exam is Domain 5?
Domain 5, Security Program Management and Oversight, accounts for about 20% of the CompTIA Security+ SY0-701 exam.
Practice another domain
Original practice questions aligned to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.