SY0-701 Question 459
Select 2Compliance monitoring: Due diligence/care , Attestation and acknowledgement , Internal and external , AutomationA healthcare company is preparing for an external HIPAA assessment after a recent internal review found inconsistent evidence that employees read updated security policies and that several cloud systems were drifting away from required logging settings. The security manager wants to strengthen compliance monitoring while demonstrating both due care and due diligence. Which TWO actions best address these goals?
- A
Require employees to electronically acknowledge updated policies and retain signed attestations for audit evidence
- B
Rely on the annual external assessment only, because external auditors are responsible for identifying compliance gaps
- C
Implement automated configuration monitoring to continuously detect and alert on logging-control deviations in cloud systems
- D
Replace internal reviews with manager verbal confirmations that teams are following policy
- E
Post the revised policies on the intranet without tracking who reviewed them, since publication alone shows reasonable care
Show answer and explanation
Correct answers: A, C
Explanation
The best answers are the actions that create verifiable evidence and improve ongoing oversight. In Security+ terms, due care means taking reasonable steps to protect the organization, while due diligence means maintaining and validating those efforts over time. Requiring employee acknowledgement with retained attestation records addresses the people and policy side of compliance monitoring. Implementing automated monitoring addresses the technical side by continuously checking for deviations instead of waiting for manual review.
Internal monitoring should occur continuously or on a defined cadence, while external assessments provide independent validation. They are complementary, not interchangeable. Common audit and compliance practices emphasize documented evidence, such as signed acknowledgements, training records, and system-generated compliance reports. Automation is especially valuable in cloud environments because configuration drift can occur quickly, and frameworks and best practices commonly recommend continuous monitoring to maintain required security baselines.
- A. Correct.
Correct. Electronic acknowledgement and retained attestation records provide documented evidence that personnel were notified of and acknowledged policy changes. This supports compliance monitoring and helps demonstrate due care by showing the organization took reasonable steps to communicate requirements. It also supports due diligence because the organization can prove it followed through with recordkeeping for later audit or investigation.
- B. Incorrect.
Incorrect. External assessments are important, but they do not replace ongoing internal compliance monitoring. Due diligence requires an organization to actively identify and remediate issues, not wait for an outside assessor to discover them once per year. This option reflects a common misconception that compliance responsibility can be outsourced.
- C. Correct.
Correct. Automated configuration monitoring is a practical way to detect control drift and continuously verify that required settings, such as logging, remain enabled. This is directly aligned with compliance monitoring through automation and supports both due care and due diligence by showing the organization implemented ongoing oversight rather than relying only on periodic manual checks.
- D. Incorrect.
Incorrect. Verbal confirmations are weak evidence and are difficult to validate during internal or external audits. They do not provide reliable attestation or acknowledgement records and are not a strong control for compliance monitoring. This option may seem convenient, but it fails to produce defensible evidence.
- E. Incorrect.
Incorrect. Simply publishing policies does not demonstrate that employees reviewed, understood, or acknowledged them. For audit and compliance purposes, organizations typically need evidence of acknowledgement or attestation. Posting policies without tracking is better than no communication, but it is insufficient when the goal is to prove compliance.