SY0-701 exam dumps

SY0-701 practice question 457 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 457

Single answerConsequences of non-compliance: Fines , Sanctions , Reputational damage , Loss of license , Contractual impacts

A payment-processing company that handles credit card transactions failed a PCI DSS assessment after auditors found that cardholder data was stored unencrypted and access reviews had not been performed for six months. Two major business customers have notified the company that they may terminate their agreements if the issues are not corrected immediately. Which consequence of non-compliance is MOST directly represented by the customers' response?

  1. A

    Fines imposed by a regulatory authority

  2. B

    Contractual impacts due to violation of customer agreement requirements

  3. C

    Loss of business license issued by the state

  4. D

    Criminal sanctions against the security administrator

Show answer and explanation

Correct answer: B

Explanation

The best answer is contractual impacts due to violation of customer agreement requirements. In real environments, security and compliance obligations are often embedded in contracts, service agreements, and third-party risk requirements. For organizations handling payment card data, PCI DSS non-compliance can lead not only to fines and increased transaction fees from payment brands or acquiring banks, but also to contract termination, loss of customers, and reputational damage. The question asks for the consequence MOST directly represented by the customers' response, which is the threat to terminate agreements. This aligns with common vendor-management and contractual enforcement practices. PCI DSS documentation and related merchant/acquirer agreements commonly require protection of cardholder data, including encryption and access-control governance, and failure to meet those terms can trigger contractual remedies even before any regulator or licensing body acts.

  • A. Incorrect.

    Incorrect. Fines are a common consequence of non-compliance, but this scenario specifically describes customers threatening to end their agreements. That points to contract-related consequences rather than a regulator issuing monetary penalties.

  • B. Correct.

    Correct. PCI DSS obligations are frequently incorporated into merchant agreements, processor agreements, or customer security addenda. If customers threaten to terminate agreements because the company failed to meet required security controls, that is a contractual impact of non-compliance. This is the most direct consequence described in the scenario.

  • C. Incorrect.

    Incorrect. Loss of license can occur in some regulated industries, such as healthcare, finance, or other licensed operations, but the scenario does not mention a licensing body or a state authority taking action. The immediate issue is potential termination of business agreements by customers.

  • D. Incorrect.

    Incorrect. Criminal sanctions generally require violations of law involving willful misconduct or other prosecutable behavior. The scenario describes an audit failure and business customers reacting to unmet security obligations, not a criminal proceeding against an individual administrator.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam