Skip to content

Security Program Management and Oversight Questions

Practice questions for Security Program Management and Oversight topic in CompTIA Security+. 20 questions covering this domain.

20 questions2 easy10 medium8 hard
Q1
hard

An organization experiences a significant data breach. During the incident response review, it is discovered that a key third-party vendor had access ...

Q2
medium

During a security audit, an auditor requests evidence that an organization's security controls are operating effectively. The organization provides sy...

Q3
medium

Which security governance document defines the high-level expectations for how employees must handle sensitive data, including rules around data class...

Q4
hard

A healthcare organization is implementing a new patient records system that will store protected health information (PHI). Which regulation MOST direc...

Q5
medium

A company has identified that a critical server has a known vulnerability that would be extremely costly to patch. Management decides to purchase cybe...

Q6
medium

A security awareness program sends simulated phishing emails to employees and tracks who clicks the links. Employees who click are automatically enrol...

Q7
hard

An organization outsources its cloud hosting to a third-party provider. The provider experiences a data breach affecting the organization's customer d...

Q8
easy

Which term describes the process of identifying, analyzing, and responding to potential risks to an organization's information assets?

Q9
medium

An organization is subject to the Payment Card Industry Data Security Standard (PCI DSS). Which action is required when they discover that a business ...

Q10
medium

An organization wants to establish a formal process for managing security-related changes to production systems, requiring documentation, testing, and...

Q11
hard

An organization operating in the European Union collects personal data from customers. A customer requests that all their personal data be deleted. Un...

Q12
hard

An organization must comply with multiple regulatory frameworks simultaneously, including PCI DSS, HIPAA, and state privacy laws. Which approach MOST ...

Q13
medium

An organization uses the NIST Cybersecurity Framework (CSF) to structure its security program. Which core function focuses on understanding the organi...

Q14
medium

A company performs a security risk assessment and determines that the likelihood of a specific threat exploiting a vulnerability is low, but the poten...

Q15
hard

An organization is developing a security metrics program to report to executive leadership. Which metric MOST effectively demonstrates the operational...

Q16
hard

An organization is developing a supply chain risk management program for its software vendors. Which control MOST effectively verifies that the softwa...

Q17
hard

An organization is contracting a cloud provider to process sensitive customer data. Which legal document defines the specific security and privacy obl...

Q18
medium

An employee is terminated and their access to all corporate systems should be immediately removed. Which security process governs this activity?

Q19
easy

Which document provides a high-level framework for an organization's overall approach to information security, defining the principles and goals that ...

Q20
medium

An organization conducts a business impact analysis (BIA) as part of its business continuity planning. What is the PRIMARY output of a BIA?

Sign in to see all 20 questions

Create a free account to browse all questions — completely free during our launch phase.