SY0-701 exam dumps

SY0-701 practice question 415 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 415

Single answerTypes of governance structures: Boards , Committees , Government entities , Centralized/decentralized

A multinational company has grown through acquisitions and now operates several autonomous business units. Each unit currently selects its own security tools, writes its own incident response procedures, and negotiates separately with cloud providers. During a recent audit, leadership found inconsistent control implementation, duplicated spending, and delayed enterprise-wide response to a ransomware event. The board has directed executive management to improve oversight, standardization, and risk reporting across the company while still allowing business units to manage day-to-day local operations. Which governance approach would BEST address these concerns?

  1. A

    Adopt a centralized security governance model led by an enterprise security function that sets policies, standards, and reporting requirements for all business units

  2. B

    Create a fully decentralized governance model so each business unit can tailor security decisions without enterprise approval

  3. C

    Transfer all security decision-making authority directly to a government regulator to ensure compliance and consistent enforcement

  4. D

    Eliminate board involvement and let the incident response team define company-wide governance based on operational needs

Show answer and explanation

Correct answer: A

Explanation

This question tests the candidate's ability to distinguish among governance structures and apply them to a realistic enterprise scenario. In Security+ terms, boards provide strategic oversight and risk direction, while management implements governance through policies, standards, and procedures. Committees may support coordination and decision-making, but the core issue here is whether governance should be centralized or decentralized. Because the company is experiencing inconsistent controls, fragmented vendor management, and weak enterprise incident coordination, a centralized governance structure is the best choice. It allows the organization to define enterprise security policy, establish standard control baselines, consolidate reporting, and improve response coordination while still permitting decentralized operational execution where appropriate. This aligns with common governance and risk management practices described in security frameworks such as NIST Cybersecurity Framework governance outcomes and NIST SP 800-53's emphasis on organization-wide control governance and oversight. Government entities influence compliance requirements, but they do not replace internal governance bodies such as boards and management-led security functions.

  • A. Correct.

    Correct. A centralized governance model is the best fit when an organization needs consistent policies, enterprise-wide visibility, standardized controls, and consolidated risk reporting. In this scenario, the board wants stronger oversight and standardization after audit findings and a poorly coordinated ransomware response. Centralized governance does not mean every local action must be centrally executed; rather, the enterprise security function can establish common policy, control baselines, and reporting while business units continue handling local operations within that framework.

  • B. Incorrect.

    Incorrect. A decentralized model gives business units significant autonomy, which can be appropriate in some organizations with highly distinct operational needs. However, the scenario already describes problems caused by excessive autonomy: inconsistent controls, duplicated spending, and slow cross-company response. Choosing a fully decentralized approach would likely worsen these issues rather than solve them.

  • C. Incorrect.

    Incorrect. Government entities may impose legal and regulatory requirements, but they do not assume internal governance responsibility for a private company. Regulators set compliance obligations and may enforce them, but they do not function as the organization's governance structure for security decision-making. This option reflects a misconception between external oversight and internal governance.

  • D. Incorrect.

    Incorrect. The board has a legitimate governance role because boards provide strategic oversight, risk direction, and accountability at the highest level. An incident response team is an operational body focused on managing security events, not establishing enterprise governance. Removing board involvement would undermine risk oversight and would not address the audit's concerns about organization-wide governance.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam