SY0-701 exam dumps

SY0-701 practice question 416 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 416

Single answerTypes of governance structures: Boards , Committees , Government entities , Centralized/decentralized

A multinational company recently acquired three regional businesses. Each region currently manages its own security tools, incident response procedures, and vendor risk reviews. After a ransomware incident exposed inconsistent controls between regions, the CEO asks for a governance change that will provide enterprise-wide direction, consistent policy enforcement, and clear executive accountability for cybersecurity risk, while still allowing technical teams in each region to operate day to day. Which governance approach BEST meets this requirement?

  1. A

    Create a centralized governance model led by the board and an executive security steering committee, with regional teams handling local operations

  2. B

    Allow each region to keep a fully decentralized governance model so security decisions remain closest to the business units

  3. C

    Transfer all cybersecurity decision-making to a government regulatory agency to ensure compliance consistency

  4. D

    Eliminate board oversight and let the incident response team define enterprise security strategy after major events

Show answer and explanation

Correct answer: A

Explanation

The best answer is the centralized governance model with board oversight and an executive committee. In Security+ governance topics, boards are responsible for strategic oversight, risk accountability, and ensuring leadership addresses cybersecurity as a business risk. Committees, such as steering committees or risk committees, translate strategic direction into coordinated priorities and cross-functional decisions. Centralized governance is especially useful after mergers, acquisitions, or major incidents because it reduces control gaps and creates consistent policy enforcement across business units. At the same time, operations can remain distributed so regional teams can implement controls and respond to local business needs.

Government entities are external to the organization and may impose legal, regulatory, or reporting requirements, but they do not replace internal governance. This distinction is important in real environments subject to frameworks and guidance such as NIST Cybersecurity Framework (CSF), NIST SP 800-53 governance-related controls, and common corporate governance practices where the board and executive management retain responsibility for risk oversight. A practical best practice is centralized governance with decentralized execution when an organization needs consistency, accountability, and scalable local operations.

  • A. Correct.

    This is correct because it separates governance from operations in a practical way. The board provides oversight and risk accountability, while an executive committee such as a security steering committee can coordinate enterprise priorities, standards, and resource decisions. A centralized governance model is appropriate when the organization needs consistent policies and control objectives across multiple business units. Regional teams can still perform localized implementation and daily operations, which preserves agility without sacrificing enterprise direction.

  • B. Incorrect.

    This is incorrect because a fully decentralized model is exactly what contributed to the inconsistency described in the scenario. Decentralized structures can work when business units have very different needs, but they often result in uneven policy enforcement, fragmented tooling, and inconsistent risk treatment if not balanced by central governance. Someone might choose this option because local autonomy can improve responsiveness, but it does not best address the stated need for enterprise-wide direction and accountability.

  • C. Incorrect.

    This is incorrect because government entities regulate and enforce legal or sector-specific requirements, but they do not serve as the internal governance body for a private company. Regulatory agencies may publish rules, frameworks, or guidance that the company must follow, but responsibility for governance remains with the organization's own leadership, especially the board and executive management. This option reflects a misconception that compliance can be outsourced to the regulator.

  • D. Incorrect.

    This is incorrect because incident response teams are operational groups, not top-level governance bodies. They help detect, contain, and recover from security events, but they should operate under policies and risk tolerances established by leadership. Removing board oversight would weaken accountability and strategic risk management. A candidate might pick this if they confuse operational authority during an incident with governance authority for the enterprise.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam