Security+ Security Program Management and Oversight: 384 practice questions
12 of the 384 Security Program Management and Oversight questions in the Certsqill Security+ bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for Security+? Take the free 5-min readiness check →
1. Publish a security policy stating management’s required: Which control best meets this objective?
- Create a firewall rule restricting administrative traffic.A firewall rule enforces a specific technical restriction, but it does not communicate management direction across the organization.
- Deploy endpoint software that blocks unauthorized configuration changes.Endpoint enforcement can support security objectives, but it does not establish management’s formal direction or accountability.
- Write a procedure describing how administrators review access logs.A procedure provides step-by-step execution details, rather than setting organization-wide management direction or intent.
- Publish a security policy stating management’s required protection objectives. ✓A policy expresses management direction and establishes broad organizational expectations for protecting customer network data.
A policy communicates management direction and broad security expectations; procedures and technologies implement or enforce those expectations.
2. Define a security standard specifying approved storage: Which document should make those details mandatory?
- Create a recovery procedure for restoring encrypted laboratory files.A recovery procedure explains restoration actions, but it does not define organization-wide minimum encryption and storage requirements.
- Publish an awareness newsletter describing secure storage preferences.An awareness newsletter informs personnel, but preferences do not create mandatory, measurable requirements for project teams.
- Define a security standard specifying approved storage and encryption requirements. ✓A standard specifies mandatory, consistent details that teams must follow when implementing the laboratory’s security policy.
- Ask each project lead to document locally preferred encryption settings.Locally selected preferences permit inconsistency and do not establish one mandatory baseline across the laboratory.
Standards define mandatory details, such as minimum encryption and approved storage, under an organization’s broader policy.
3. Publish a guideline recommending safer device and account: Which control is most appropriate?
- Require a formally approved standard for all student devices.A standard imposes mandatory requirements, conflicting with the office’s stated intention to preserve user discretion.
- Deploy endpoint controls that enforce every recommended setting.Enforcement mechanisms remove discretion and therefore do not match the requested advisory nature of the control.
- Issue a procedure requiring students to complete each security step.A procedure gives required execution steps, which would make the practices obligatory rather than advisory.
- Publish a guideline recommending safer device and account practices. ✓A guideline offers recommended practices while allowing users discretion, matching the university’s nonmandatory objective.
Guidelines recommend practices without imposing the mandatory requirements associated with standards or procedures.
4. Assign accountable policy owners and an oversight body: What should happen first?
- Assign accountable policy owners and an oversight body. ✓Defined ownership and oversight establish accountability for review, escalation, and organization-wide security governance.
- Replace all policies with one technical configuration baseline.A configuration baseline addresses technical settings, but it cannot replace governance ownership, oversight, or risk decisions.
- Schedule vulnerability scans for every publishing platform.Scanning identifies technical weaknesses, but it does not resolve unclear policy accountability or executive risk oversight.
- Require administrators to document every routine maintenance task.Maintenance documentation may improve operational records, but it does not establish policy ownership or leadership oversight.
Governance begins by assigning accountability and oversight so policies, risks, and escalations have responsible decision makers.
5. Approve or reject the organization’s significant risk: Which responsibility belongs primarily to the board?
- Test application performance after the upgrade is installed.Performance testing supports implementation assurance, but it is not the board’s primary risk oversight function.
- Write the maintenance procedure for regional technicians.Procedure writing is an operational documentation task and does not represent board-level risk accountability.
- Apply the upgrade to each warehouse server.Server implementation belongs to operational or technical staff, not the board’s governance responsibility.
- Approve or reject the organization’s significant risk decision. ✓Senior governance bodies provide oversight and make or approve major organizational risk decisions.
Boards provide governance oversight and approve significant risk decisions; technical teams implement and test controls.
6. The data owner: Which role should determine the classification and access requirements?
- The external auditorAuditors evaluate controls and evidence, but they do not own the nonprofit’s information or set its access requirements.
- The data owner ✓The data owner determines classification and establishes access requirements for information under organizational governance.
- The help desk technicianHelp desk personnel may support access requests, but they do not normally determine organizational data classification.
- The system custodianA custodian implements handling and protection requirements but generally does not decide the information’s classification.
The data owner decides classification and access requirements; custodians implement the resulting handling controls.
7. The custodian: Which role should configure systems and carry out those handling requirements?
- Privacy counsel, who interprets obligations and advises the organization on privacy riskPrivacy counsel may advise on obligations but normally does not administer systems or perform routine data handling.
- The board risk committee, which provides oversight and approves major risk decisionsThe board risk committee provides oversight and risk decisions, not daily system configuration or data handling.
- The custodian ✓The custodian implements the owner’s approved requirements through system configuration and operational handling.
- The data owner, who establishes classification, access, retention, and protection requirementsThe data owner establishes requirements but normally delegates their technical and operational implementation.
The custodian implements the data owner’s approved requirements.
8. The retailer is the controller and the cloud service is: Which role relationship is described?
- The retailer is the data custodian and the cloud service is the data owner.Owner and custodian describe information governance roles, not the controller-processor relationship described by processing decisions and instructions.
- The retailer is the processor and the cloud service is the controller.The retailer determines purposes and means, while the service acts on instructions, so these role assignments are reversed.
- Both organizations are independent controllers for the same processing.The scenario describes instructed processing rather than two organizations independently determining purposes and means.
- The retailer is the controller and the cloud service is the processor. ✓The retailer determines purposes and means, while the cloud service processes data under the retailer’s documented instructions.
The controller determines purposes and means; the processor handles data on the controller’s documented instructions.
9. Assign an owner and schedule periodic policy reviews: Which control best ensures the policy remains current?
- Enable multifactor authentication for administrators.Multifactor authentication improves access security, but it does not establish a policy review or update process.
- Record the policy in a version-controlled repository.Version control preserves change history, but by itself it does not require periodic review or accountable reassessment.
- Publish the existing policy on the staff portal.Publication improves availability, but it does not ensure the policy is reviewed or updated when conditions change.
- Assign an owner and schedule periodic policy reviews. ✓Ownership and scheduled reviews create accountability for reassessing policy relevance as services and risks change.
An owner and recurring review schedule ensure policies are reassessed as technology, services, and risks change.
10. Establish one security policy framework with assigned: Which control most directly supports that objective?
- Create a shared security contact list for regional offices.A contact list improves coordination but does not establish authority, accountability, or centralized decision rights.
- Establish one security policy framework with assigned owners and review authority. ✓A centralized policy framework defines management direction, accountability, oversight, and consistent security decision authority.
- Require each office to submit monthly security metrics to headquarters.Metrics support oversight, but reporting alone does not create centralized authority or define who makes decisions.
- Deploy identical endpoint configurations across all regional offices.Uniform configurations provide technical consistency but do not assign governance responsibility or resolve policy ownership.
A centralized policy framework with accountable owners directly establishes consistent authority and oversight across regional offices.
11. Require security requirements and approval checkpoints: Which control best meets the objective?
- Schedule an annual application security audit.An annual audit may find weaknesses later but does not place security requirements into early development decisions.
- Provide developers with optional secure-coding guidance before design reviews.Guidance can help developers, but optional advice does not create mandatory security checkpoints or approval authority.
- Scan production applications after each release for security defects.Post-release scanning can identify defects but does not govern security requirements before design and implementation.
- Require security requirements and approval checkpoints throughout the SDLC. ✓SDLC checkpoints make security requirements part of planning, design, and approval before implementation proceeds.
Mandatory security requirements and approval checkpoints embedded in the SDLC govern security before implementation.
12. Use an approved change record with testing: Which control is most appropriate next?
- Apply the configuration during normal operations without additional planning.Immediate implementation bypasses planned testing, maintenance timing, and restoration controls.
- Record the change in version control for traceability.Version control records history but does not establish approval, testing, maintenance timing, or rollback planning.
- Use an approved change record with testing, scheduling, and rollback details. ✓An approved change record documents authorization, testing, timing, recovery, and accountability for implementation.
- Notify the payment support team before implementation begins.Notification supports communication but does not authorize or fully control the change.
Use an approved change record containing testing, scheduling, and rollback details.
372 more Security Program Management and Oversight questions
The remaining 372 questions in this domain are part of the full Security+ bank — 1918 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your Security+ readiness — freeOther Security+ domains
- Security Operations — 528 questions →
- Threats, Vulnerabilities, and Mitigations — 425 questions →
- Security Architecture — 349 questions →
- General Security Concepts — 232 questions →
- All 1918 Security+ questions →