SY0-701 Question 274
Single answer4.2 Explain the security implications of proper hardware, software, and data asset management.A healthcare company is preparing for an external audit after discovering that several retired laptops containing patient records were placed in storage without being wiped. During the investigation, the security team also finds that multiple business units are running unapproved file-sharing applications and several servers are missing from the asset inventory. The CISO wants to reduce the likelihood of data exposure and improve accountability for hardware, software, and data assets. Which action would BEST address these issues?
- A
Implement a formal asset management program that maintains inventories of hardware, software, and data assets, assigns ownership, and enforces secure media sanitization and approved software controls throughout the asset lifecycle
- B
Require all employees to change their passwords immediately and increase password length requirements for privileged accounts
- C
Deploy a next-generation firewall at the network perimeter to block unauthorized outbound traffic from user devices
- D
Enable full-disk encryption on all new laptops purchased after the audit and defer retirement procedures until the next hardware refresh cycle
Show answer and explanation
Correct answer: A
Explanation
The scenario is centered on asset management failures across hardware, software, and data. Security+ expects candidates to understand that proper asset management is not just inventory tracking; it includes lifecycle management, ownership, classification, approved use, change control, and disposal. The best response is to implement a formal asset management program that covers hardware inventories, software inventories and authorization, data ownership/classification, and secure media sanitization at end of life. For healthcare data, this is especially important because regulated information such as patient records must be protected throughout its lifecycle. Best practices align with guidance such as NIST SP 800-88 for media sanitization, which outlines how storage media should be cleared, purged, or destroyed before reuse or disposal. Inventory and control of hardware and software assets are also foundational concepts in common security frameworks and audit programs because organizations cannot protect assets they do not know they have. Accurate asset records, assigned owners, and secure retirement procedures significantly reduce the risk of data exposure, shadow IT, and unmanaged systems.
- A. Correct.
This is the best answer because it directly addresses the root causes identified in the scenario: missing hardware inventory, unauthorized software, unclear accountability, and improper handling of retired systems containing sensitive data. A formal asset management program should track assets from procurement through disposal, identify asset owners and custodians, classify data, maintain accurate hardware and software inventories, and define approved disposal and media sanitization procedures. It also supports software allowlisting or other approval processes to reduce the risk from unapproved applications. This is the most comprehensive and audit-aligned response.
- B. Incorrect.
This is incorrect because password changes do not address the primary control failures described. The scenario focuses on asset lifecycle management, missing inventories, unauthorized software, and improper disposal of devices with regulated data. Strong authentication is important, but it would not solve the lack of visibility into assets or ensure secure handling of retired laptops.
- C. Incorrect.
This is incorrect because a firewall may help detect or block some unauthorized file-sharing traffic, but it does not solve the broader asset management problem. It would not create accurate hardware and software inventories, assign ownership, or ensure laptops are sanitized before storage or disposal. This option treats one symptom rather than the full set of asset management deficiencies.
- D. Incorrect.
This is incorrect because full-disk encryption on future laptops is helpful, but it is too narrow and incomplete. It does not fix the existing issue of retired laptops already placed in storage, does not address unauthorized software or missing servers in the inventory, and delaying retirement procedures increases risk. Encryption is one protective control, but proper asset management requires secure disposal, inventory accuracy, and governance across the lifecycle.