SY0-701 exam dumps

SY0-701 practice question 460 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 460

Single answerCompliance monitoring: Due diligence/care , Attestation and acknowledgement , Internal and external , Automation

A healthcare company must demonstrate ongoing compliance with internal security policies and external regulatory requirements. The security manager wants a solution that reduces manual evidence collection, proves employees have reviewed required policies, and clearly distinguishes management's responsibility to implement controls from the independent validation of those controls. Which approach BEST meets these requirements?

  1. A

    Implement automated compliance monitoring and reporting, require employee policy attestation through signed acknowledgements, have management perform due care by enforcing controls, and use external auditors for independent assessment

  2. B

    Rely on annual employee security awareness training records as proof of compliance, and have the infrastructure team validate its own controls to avoid outside cost

  3. C

    Use a one-time internal audit to document baseline compliance, then accept verbal confirmation from department managers that policies were reviewed by staff

  4. D

    Deploy automated vulnerability scans only, and treat scan results as sufficient evidence that all administrative, technical, and regulatory compliance requirements are being met

Show answer and explanation

Correct answer: A

Explanation

The best answer is the one that addresses all parts of the scenario: automation, attestation/acknowledgement, internal versus external validation, and management responsibility. In practice, due care means management takes reasonable steps to implement and enforce safeguards, while due diligence involves ongoing investigation, monitoring, and validation that controls remain appropriate and effective. Automated compliance monitoring helps collect evidence consistently across systems and reduces human error. Policy attestation and acknowledgement provide documented proof that employees reviewed and accepted required responsibilities. Internal assessments are useful for routine monitoring, but external assessments provide independent assurance and are often required or strongly preferred for regulatory, contractual, or stakeholder confidence purposes. This aligns with common security governance and audit best practices seen in frameworks such as NIST guidance, ISO 27001 auditing concepts, and regulated-environment expectations for documented evidence and independent review.

  • A. Correct.

    Correct. This option combines the key elements of effective compliance monitoring. Automation supports continuous or recurring evidence collection and reporting, reducing manual effort and improving consistency. Employee attestation and acknowledgement provide documented proof that staff reviewed and accepted required policies. Due care refers to taking reasonable actions to protect assets and enforce controls, while due diligence is the ongoing effort to assess risks and verify compliance. Using an external auditor provides independent validation, which is often important for regulatory reviews, customer assurance, or formal attestations.

  • B. Incorrect.

    Incorrect. Training records alone do not prove broader compliance with policies, standards, or regulations. They show participation in training but not necessarily formal acknowledgement of specific policy requirements. In addition, having the infrastructure team validate its own controls weakens independence and can create conflicts of interest. Internal reviews are useful, but independent internal audit or external assessment is typically preferred for stronger assurance.

  • C. Incorrect.

    Incorrect. A one-time internal audit may establish a starting point, but it does not support ongoing compliance monitoring. Verbal confirmation is poor evidence because it is not durable, auditable, or easy to validate later. Formal attestation or acknowledgement should be documented, and compliance monitoring should be recurring rather than a single event.

  • D. Incorrect.

    Incorrect. Vulnerability scanning is only one automated technical control and does not address the full compliance picture. Compliance programs also include administrative requirements such as policy acknowledgement, user responsibilities, control reviews, exceptions management, and evidence retention. Scan results can support compliance monitoring, but they are not sufficient by themselves to demonstrate complete compliance.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam