SY0-701 exam dumps

SY0-701 practice question 454 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 454

Single answer5.4 Summarize elements of effective security compliance.

A healthcare company is preparing for an external audit after expanding into online patient scheduling and payment processing. The security manager discovers that teams are using different control baselines, system owners are not consistently documenting exceptions, and evidence for required safeguards is stored in individual spreadsheets. Leadership wants a sustainable compliance approach that will reduce audit findings across HIPAA and PCI DSS requirements. Which action should the security manager take FIRST to improve the organization's overall compliance posture?

  1. A

    Create a unified compliance program that maps regulatory requirements to internal controls, assigns control owners, and standardizes evidence collection

  2. B

    Purchase a penetration testing service to identify exploitable vulnerabilities before the audit begins

  3. C

    Require all employees to retake annual security awareness training focused on handling protected health information

  4. D

    Encrypt all databases containing patient and cardholder data, then mark the related audit items as complete

Show answer and explanation

Correct answer: A

Explanation

The best first step is to establish a formal, unified compliance program. Effective security compliance includes identifying applicable laws, regulations, standards, and contractual obligations; translating them into internal policies and controls; assigning responsibility; documenting exceptions and compensating controls; and maintaining evidence for audits and assessments. In practice, organizations often use control mapping or a common control framework so one control can satisfy multiple requirements across frameworks. This is especially useful when dealing with overlapping obligations such as HIPAA Security Rule safeguards and PCI DSS control requirements. HIPAA expects administrative, technical, and physical safeguards with documentation and ongoing risk management, while PCI DSS emphasizes defined controls, scoping, validation, and evidence. Best practices from governance frameworks such as NIST's risk management guidance and common audit approaches support centralized ownership, repeatable processes, and evidence retention. Technical measures like encryption, training, and penetration testing are valuable, but they are most effective when integrated into a documented compliance management process.

  • A. Correct.

    Correct. Effective security compliance begins with governance and structure: identifying applicable requirements, mapping them to internal controls, assigning ownership, documenting exceptions, and collecting evidence in a consistent way. For organizations subject to multiple frameworks such as HIPAA and PCI DSS, a unified compliance program reduces duplication, improves accountability, and supports audit readiness. This addresses the root causes in the scenario: inconsistent baselines, poor exception tracking, and scattered evidence.

  • B. Incorrect.

    Incorrect. Penetration testing can support compliance and security validation, and PCI DSS may require testing activities, but it does not solve the broader compliance management problems described. The main issue is the absence of a coordinated compliance structure, not simply a lack of technical testing.

  • C. Incorrect.

    Incorrect. Security awareness training is an important administrative control and is relevant to HIPAA workforce training requirements, but retraining employees would not fix inconsistent control baselines, undocumented exceptions, or fragmented audit evidence. This option addresses only one small part of the compliance program.

  • D. Incorrect.

    Incorrect. Encryption is an important safeguard for sensitive data and may help satisfy certain HIPAA and PCI DSS requirements, but implementing a single technical control does not establish effective compliance management. Marking audit items complete based only on encryption would be inappropriate because compliance requires documented evidence, scope validation, control ownership, and ongoing assessment.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam