SY0-701 exam dumps

SY0-701 practice question 280 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 280

Single answerOwnership

A company is updating its information security program after a failed audit found that several critical business applications had no clearly assigned data owner. As a result, sensitive records were retained longer than necessary, access reviews were inconsistent, and no one could approve changes to data classification. The CISO wants to assign the role that should be accountable for determining how the data is classified, who should have access based on business need, and how long the data must be retained. Which role should be assigned?

  1. A

    Data owner

  2. B

    System administrator

  3. C

    Data custodian

  4. D

    Privacy officer

Show answer and explanation

Correct answer: A

Explanation

In Security+ terms, ownership refers to the person or role with business accountability for an asset or data set. For information assets, the data owner is responsible for classifying data, approving access based on need-to-know and least privilege principles, and defining handling and retention requirements. The data custodian implements those requirements operationally, and system administrators manage the supporting systems. This separation of duties is consistent with common governance frameworks and industry guidance, including concepts reflected in NIST SP 800-53 control families such as Access Control (AC) and Media Protection (MP), as well as general data governance best practices. When an audit finds unclear accountability for classification, access review, and retention, assigning a data owner is the most appropriate corrective action.

  • A. Correct.

    Correct. The data owner is the business role accountable for the data itself. This role determines the data's classification, establishes access requirements based on business and regulatory needs, and defines retention and handling requirements. In Security+ governance and data management concepts, ownership means accountability for business decisions about the data, even if day-to-day administration is delegated to others.

  • B. Incorrect.

    Incorrect. A system administrator typically manages the technical platform, such as servers, applications, accounts, and permissions implementation. While the administrator may enforce access controls and retention settings, the administrator should not be the person who decides the business classification of the data or who is authorized to access it. Choosing this option reflects the common misconception that technical control equals ownership.

  • C. Incorrect.

    Incorrect. A data custodian is responsible for implementing and maintaining the protections defined by the owner, such as backups, storage, access control mechanisms, and operational handling. Custodians safeguard and manage data on behalf of the owner, but they do not usually set classification or retention policy. This option is plausible because custodians work closely with the data, but they are not ultimately accountable for business decisions about it.

  • D. Incorrect.

    Incorrect. A privacy officer may oversee compliance with privacy laws and advise on requirements related to personal data, but this role does not generally become the owner of all business data. The privacy officer may influence retention and handling requirements where regulated data is involved, but ownership remains with the business function responsible for the data. Selecting this option confuses compliance oversight with business accountability.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam