SY0-701 exam dumps

SY0-701 practice question 468 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 468

Single answerInternal: Compliance , Audit committee , Self-assessments

A company's audit committee has asked the security manager to improve oversight of internal compliance with access control and data handling policies before the next external audit. The company has limited budget and wants to identify control gaps early without waiting for the annual independent assessment. Which action would BEST help the organization meet the audit committee's request?

  1. A

    Perform periodic internal self-assessments against established policies and control requirements, then report findings and remediation status to the audit committee

  2. B

    Delay any review activities until the external auditors arrive so the organization receives an unbiased assessment of its compliance posture

  3. C

    Allow each department to define its own compliance criteria so reviews can be tailored to local business needs

  4. D

    Have the audit committee directly administer technical security controls so it can verify compliance firsthand

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement periodic internal self-assessments and report results to the audit committee. In practice, self-assessments help organizations measure adherence to internal policies, regulatory obligations, and security control requirements on a recurring basis. This supports continuous improvement, early gap identification, and better preparation for external audits. The audit committee's role is governance and oversight, not day-to-day control operation. A sound model is for management and control owners to perform self-assessments, internal audit or compliance teams to validate as appropriate, and the audit committee to review trends, exceptions, and remediation progress. This aligns with common governance and control practices reflected in widely used guidance such as NIST's risk management and assessment principles, as well as standard internal control concepts found in frameworks like COSO, where management performs assessments and governance bodies oversee the effectiveness of controls.

  • A. Correct.

    Correct. Periodic internal self-assessments are an effective way to identify compliance gaps before a formal audit. They provide ongoing visibility into whether controls are operating as intended and allow management to track remediation. Reporting results and corrective actions to the audit committee supports governance and oversight, which is one of the committee's key responsibilities.

  • B. Incorrect.

    Incorrect. External audits are valuable for independent validation, but waiting for them does not provide proactive compliance monitoring. This approach increases the risk that known or preventable issues remain unresolved until the formal audit, which is the opposite of what the audit committee requested.

  • C. Incorrect.

    Incorrect. Departments may have different operational requirements, but compliance criteria should be based on organization-wide policies, legal requirements, and approved control frameworks. Allowing each department to create its own standards creates inconsistency and weakens internal control assurance.

  • D. Incorrect.

    Incorrect. The audit committee provides governance, oversight, and review of risk, compliance, and audit results. It should not directly administer technical controls, because that would blur separation of duties and undermine independent oversight.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam