SY0-701 exam dumps

SY0-701 practice question 453 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 453

Single answer5.4 Summarize elements of effective security compliance.

A healthcare provider is preparing for an external compliance assessment after expanding its telemedicine platform. The security manager discovers that several development teams store meeting recordings containing patient information in a cloud repository indefinitely because no formal retention schedule exists. The legal team confirms that some recordings must be retained for a defined period for business purposes, while others should be deleted sooner to reduce risk. Which action should the security manager take FIRST to best improve security compliance?

  1. A

    Implement a data retention and data disposal policy based on legal, regulatory, and business requirements, then enforce it with technical controls

  2. B

    Enable full-disk encryption on the cloud storage repository so recordings can remain stored indefinitely without increasing compliance risk

  3. C

    Move all recordings to an on-premises file server to simplify ownership and avoid cloud-specific compliance obligations

  4. D

    Require developers to manually review and delete old recordings when storage usage becomes too high

Show answer and explanation

Correct answer: A

Explanation

The best first step is to establish a formal data retention and disposal policy that reflects legal, regulatory, and business requirements, then implement technical enforcement. This is a core element of effective security compliance because organizations must know what data they have, how long they are required to keep it, and when it should be securely disposed of. In healthcare scenarios, retained recordings may contain protected health information (PHI), so uncontrolled retention can create unnecessary risk and potential noncompliance. Best practices include maintaining data inventories, classifying sensitive information, documenting retention schedules, applying secure disposal methods, and using automated lifecycle management to demonstrate consistent enforcement. This aligns with common compliance expectations found in records-management programs, privacy frameworks, and security control guidance such as NIST recommendations for data governance and media sanitization.

  • A. Correct.

    Correct. Effective security compliance requires organizations to define and document retention and disposal requirements based on applicable laws, regulations, contracts, and business needs. In a healthcare environment, data handling decisions must align with formal governance rather than convenience. After defining the retention schedule, the organization should apply technical controls such as lifecycle policies, automated archival, and secure deletion to enforce it consistently and produce evidence during audits.

  • B. Incorrect.

    Incorrect. Encryption is an important security control for protecting confidentiality, but it does not address whether data is being retained longer than permitted or necessary. Compliance is not satisfied simply by encrypting regulated data. Over-retention can still increase legal exposure, privacy risk, e-discovery burden, and audit findings even if the data is encrypted.

  • C. Incorrect.

    Incorrect. Changing the storage location does not resolve the underlying compliance issue, which is the absence of a documented retention and disposal policy. On-premises storage is not inherently more compliant than cloud storage. Compliance depends on proper governance, classification, retention, access control, and disposal processes regardless of where the data resides.

  • D. Incorrect.

    Incorrect. Manual, ad hoc deletion based on storage capacity is not a compliant or defensible records-management process. It creates inconsistency, increases the chance of premature deletion or over-retention, and makes audit evidence difficult to produce. Compliance programs rely on documented policies and repeatable procedures, preferably with automation where possible.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam