SY0-701 exam dumps

SY0-701 practice question 275 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 275

Single answer4.2 Explain the security implications of proper hardware, software, and data asset management.

A healthcare company is preparing for an external audit after discovering that several laptops issued to departing employees were never returned, and one of those devices was later found for sale online. The security team also learns that some business units have been installing unapproved file-sharing applications to move patient records between locations. Management asks which action would MOST directly reduce the organization's risk from both issues while improving compliance reporting.

  1. A

    Implement a formal asset management program with hardware inventory tracking, software allowlisting, and data classification tied to device assignment and disposal procedures

  2. B

    Increase internet bandwidth so employees can use approved cloud applications without performance delays

  3. C

    Require all employees to change their passwords every 30 days and prohibit password reuse

  4. D

    Deploy a newer perimeter firewall with geolocation blocking for outbound traffic

Show answer and explanation

Correct answer: A

Explanation

This question focuses on the security implications of proper hardware, software, and data asset management. In the scenario, the organization has weaknesses in all three areas: hardware assets are not being tracked through employee offboarding, software assets are not controlled because users can install unapproved applications, and sensitive data assets are being moved without proper governance. The best response is to implement a formal asset management program that covers the full lifecycle of devices, approved software, and data handling requirements. In practice, this aligns with widely accepted security guidance such as the NIST Cybersecurity Framework's Asset Management category (ID.AM), NIST SP 800-53 controls related to inventory, media protection, and configuration management, and CIS Controls covering enterprise asset inventory and software inventory. In regulated environments such as healthcare, these controls also support compliance efforts by improving chain of custody, reducing data exposure, and producing reliable audit evidence.

  • A. Correct.

    Correct. A formal asset management program addresses both missing laptops and unauthorized software in a coordinated way. Hardware inventory and lifecycle tracking help the organization know who has each device, whether it has been returned, and when it should be securely wiped or disposed of. Software allowlisting reduces the risk of users installing unauthorized file-sharing tools that could expose regulated data. Data classification ensures patient records are handled according to sensitivity and regulatory requirements, and tying this information to device assignment improves accountability and audit readiness.

  • B. Incorrect.

    Incorrect. Bandwidth improvements may reduce the temptation to use unauthorized tools, but this does not solve the core security problem. It does not create accountability for missing hardware, does not establish software control, and does not ensure regulated data is tracked through its lifecycle. This is an operational improvement, not a direct asset management control.

  • C. Incorrect.

    Incorrect. Strong password policies can help reduce account compromise, but they do not address the main issues in this scenario: missing endpoint hardware, unapproved software installation, and poor control over patient data. Someone might choose this because credential security is important, but it is not the most direct control for asset management failures.

  • D. Incorrect.

    Incorrect. A perimeter firewall can help monitor and restrict some traffic, but it does not provide full visibility into hardware ownership, device return status, software authorization, or data handling requirements. It may detect or block some file-sharing traffic, but it is not the most direct solution to the asset management and compliance gaps described.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam