SY0-701 Question 281
Single answerOwnershipA company is preparing for a compliance audit after several incidents in which critical customer records were modified without clear authorization. During the review, the security manager finds that multiple departments can change the same records, but no one has been formally assigned responsibility for approving changes, validating data quality, or determining who should have access. Which action would BEST address the root cause of this issue?
- A
Assign a data owner for the customer records who is responsible for classification, approving access, and defining handling requirements
- B
Assign a data custodian for the customer records and allow the custodian to make all access-control and classification decisions
- C
Require all departments to use shared administrative accounts so changes can be made quickly during business hours
- D
Increase the frequency of backups for the customer records so unauthorized modifications can be rolled back more easily
Show answer and explanation
Correct answer: A
Explanation
This question tests understanding of ownership as a governance and accountability function. In common security governance models, the data owner is the business role responsible for classifying data, approving access, and defining how the data should be protected. The data custodian, by contrast, implements and operates the technical and administrative controls on the owner's behalf. In a scenario where records are being changed without clear authorization, the root cause is the lack of a clearly assigned owner, not simply weak backup practices or operational administration. This aligns with widely accepted security governance practices described in frameworks and guidance such as NIST security governance principles and standard role separation concepts used across industry.
- A. Correct.
Correct. In Security+ governance and data management concepts, the data owner is the role accountable for determining the sensitivity/classification of data, approving access, and defining protection and handling requirements. Assigning ownership addresses the underlying problem: no one is accountable for authorizing changes and access to the records.
- B. Incorrect.
Incorrect. A data custodian is responsible for implementing and maintaining the controls specified by the owner, such as backups, storage, and technical handling of data. Custodians typically do not decide classification or who should be granted access; those are owner responsibilities. This option reflects a common confusion between ownership and custodianship.
- C. Incorrect.
Incorrect. Shared administrative accounts reduce accountability and make it harder to attribute changes to specific users, which would worsen the current audit and authorization problem. Security best practices favor unique identities and individual accountability.
- D. Incorrect.
Incorrect. More frequent backups may improve recovery capability, but they do not solve the root issue of missing accountability for data access, approval, and handling. This is a compensating recovery measure, not a governance fix.