Home › Certifications › CompTIA Security+ › Security Program Management and Oversight
68 multiple-choice questions and 44 flashcards on Security Program Management and Oversight, about 23% of the CompTIA Security+ bank. Every one carries a written rationale.
Security Program Management and Oversight is one of 6 chapters in CoStudy's CompTIA Security+ bank, and it holds 68 of the bank's 300 multiple-choice questions — roughly 23% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
Step 5 of the CompTIA troubleshooting methodology is to:
Answer: A — Verify full system functionality and implement preventive measures
(A) Step 5 confirms the fix worked end to end and adds measures such as patching or monitoring to prevent recurrence. (B) is step 6. (C) is step 3. (D) is step 1.
Separation of duties requires that:
Answer: A — Splitting a sensitive task so no one person completes it alone
A) Separation of duties divides a sensitive action across people, so fraud requires collusion. B) Concentrating a workflow in one person is the risk being removed. C) Randomization is not a control on authority. D) Skipping approvals weakens the process.
Security frameworks include:
Answer: E — NIST CSF, ISO 27001/27002, CIS Critical Security Controls, and COBIT
Organizations choose among frameworks by industry, regulation, and maturity: NIST CSF organizes identify, protect, detect, respond, and recover; ISO 27001 certifies a management system; the CIS Controls prioritize actions; COBIT governs IT. A denies that choice, and B, C, and D each erase the others that plainly exist.
A SOC 2 report attests to controls in which categories?
Answer: B — Security, availability, processing integrity, confidentiality, privacy
SOC 2 reports against the AICPA Trust Services Criteria, where Security is mandatory and the remaining four are scoped to customer commitments; Type I covers design at a point in time and Type II covers operating effectiveness over a period. A and D each name a single criterion or unrelated regime. C describes SOC 1 financial-reporting scope.
What is the FIRST step in the CompTIA troubleshooting methodology?
Answer: C — Identify the problem
Step 1 is identify the problem (gather info, question users, reproduce). (A) is step 2; (B) is step 3; (D) is the final step — a common direction-reversal trap.
Which regulation governs payment-card data handling?
Answer: B — PCI DSS, covering stored cardholder account data
B) PCI DSS is the card brands' standard for protecting cardholder data. A) HIPAA governs US health information. C) SOX addresses financial reporting controls for public companies. D) GLBA governs privacy at financial institutions.
Gap analysis in a security program is best described as:
Answer: C — Comparing current posture to a target framework's controls
C) Gap analysis measures current state against a desired target such as NIST CSF or ISO 27001 and names the missing or weak controls. A) Pen testing proves exploitability, not framework coverage. B) Patch counts are one input. D) Rule audits are far narrower in scope.
You are working on a user's machine and find personal/confidential files. You should:
Answer: C — Leave unrelated content alone; report illegal material per policy
(C) Professional conduct means accessing only what the ticket requires, with a defined escalation path for illegal content. (A), (B), and (D) all access or distribute private data without any business justification.
An SLA (Service Level Agreement) defines:
Answer: A — Agreed service targets and breach remedies
(A) An SLA sets measurable response, resolution, and availability commitments with remedies for breach. (B), (C), and (D) are different documents entirely.
The NIST Cybersecurity Framework (CSF) functions are:
Answer: A — Identify, Protect, Detect, Respond, Recover, plus Govern in CSF 2.0
(A) These are the CSF core functions, with Govern added in version 2.0. (B) is the PDCA quality cycle. (C) is file permissions. (D) is a governance model, not the CSF structure.
4 cards from the 44 in this chapter.
What is a bug bounty program?
An organization offers rewards to security researchers who responsibly disclose vulnerabilities. Crowdsources security testing. Examples: HackerOne, Bugcrowd.
What is a privacy impact assessment (PIA)?
An analysis of how personal information is collected, used, shared, and protected. Required by many privacy regulations.
What is residual risk?
The risk remaining after security controls are applied. Acceptable residual risk is determined by the organization's risk appetite.
What is a data processor vs. data controller (GDPR)?
Controller: determines the purposes and means of processing personal data. Processor: processes data on behalf of the controller. Both have legal obligations.
These are a sample. The full Security Program Management and Oversight chapter runs 112 items with per-chapter progress tracking, on the web and in the iOS app.
Open CompTIA Security+ in CoStudy →