SY0-701 exam dumps

SY0-701 practice question 467 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 467

Single answerInternal: Compliance , Audit committee , Self-assessments

A financial services company is preparing for its annual governance review after several minor policy exceptions were found during the year. The CIO wants to improve internal compliance oversight without waiting for the next external audit. The company already has an audit committee that reports to the board. Which action would BEST help the organization identify control gaps early and provide the audit committee with meaningful information for oversight?

  1. A

    Require each business unit to perform periodic self-assessments against internal security policies and control requirements, then report the results and remediation status to the audit committee

  2. B

    Delay any internal review activities until the external auditors arrive so the assessment remains fully independent

  3. C

    Have the audit committee directly implement technical controls so it can verify compliance firsthand

  4. D

    Replace policy reviews with monthly vulnerability scans because technical findings are sufficient to demonstrate overall compliance

Show answer and explanation

Correct answer: A

Explanation

The best answer is the use of periodic self-assessments by business units, with results reported to the audit committee. In practice, internal compliance programs rely on ongoing monitoring to identify issues before they become audit findings or regulatory problems. Self-assessments are not a replacement for independent audit, but they are an effective first-line activity that helps management evaluate whether policies and controls are being followed. The audit committee's role is to provide oversight, review risk and compliance information, and ensure management addresses deficiencies; it should not perform day-to-day operational control implementation. This aligns with common governance practices reflected in frameworks such as COSO's internal control model and widely used audit and governance approaches where management performs assessments, internal audit provides independent assurance, and the audit committee oversees reporting, remediation, and accountability.

  • A. Correct.

    Correct. Periodic self-assessments are a common internal compliance practice used to identify control weaknesses before formal audits. Having business units assess themselves against documented policies, standards, and required controls helps detect issues early, promotes accountability, and creates a structured way to track remediation. Providing those results to the audit committee supports its oversight role by giving leadership visibility into risk, exceptions, and corrective actions.

  • B. Incorrect.

    Incorrect. External audits provide independent assurance, but delaying internal review until that point weakens governance and increases the likelihood that known issues remain unresolved. Internal compliance programs are expected to operate continuously, and self-assessments are specifically useful for ongoing monitoring between formal audits.

  • C. Incorrect.

    Incorrect. The audit committee provides governance and oversight, not operational implementation. If the committee directly deploys or manages technical controls, it compromises separation of duties and undermines its ability to independently review management's performance and compliance status.

  • D. Incorrect.

    Incorrect. Vulnerability scans are useful for identifying certain technical weaknesses, but compliance extends beyond technical exposure. Internal compliance also includes policy adherence, procedural controls, documentation, access reviews, training, and exception handling. Relying only on vulnerability scans creates a narrow view and would not provide the audit committee with a complete picture of control effectiveness.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam