CoStudy

HomeCertificationsCompTIA Security+ › Security Program Management and Oversight

Security Program Management and Oversight — CompTIA Security+ practice questions

68 multiple-choice questions and 44 flashcards on Security Program Management and Oversight, about 23% of the CompTIA Security+ bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Security Program Management and Oversight is one of 6 chapters in CoStudy's CompTIA Security+ bank, and it holds 68 of the bank's 300 multiple-choice questions — roughly 23% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Security Program Management and Oversight practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

Step 5 of the CompTIA troubleshooting methodology is to:

  1. Verify full system functionality and implement preventive measures
  2. Document the findings and outcomes in the ticket, then close it
  3. Test the theory to determine whether it truly explains the symptoms
  4. Identify the problem by questioning the user about the symptoms

Answer: A — Verify full system functionality and implement preventive measures

(A) Step 5 confirms the fix worked end to end and adds measures such as patching or monitoring to prevent recurrence. (B) is step 6. (C) is step 3. (D) is step 1.

Separation of duties requires that:

  1. Splitting a sensitive task so no one person completes it alone
  2. Assigning every step of a critical workflow to one trusted admin
  3. Assigning tasks at random among whichever staff are available
  4. Skipping approval steps when workload exceeds staffing levels

Answer: A — Splitting a sensitive task so no one person completes it alone

A) Separation of duties divides a sensitive action across people, so fraud requires collusion. B) Concentrating a workflow in one person is the risk being removed. C) Randomization is not a control on authority. D) Skipping approvals weakens the process.

Security frameworks include:

  1. One single universal framework mandated for every organization worldwide
  2. The CIS Controls alone, with no other recognized framework existing
  3. NIST publications alone, with no international equivalent standards
  4. ISO standards alone, with no US or industry-specific alternatives
  5. NIST CSF, ISO 27001/27002, CIS Critical Security Controls, and COBIT

Answer: E — NIST CSF, ISO 27001/27002, CIS Critical Security Controls, and COBIT

Organizations choose among frameworks by industry, regulation, and maturity: NIST CSF organizes identify, protect, detect, respond, and recover; ISO 27001 certifies a management system; the CIS Controls prioritize actions; COBIT governs IT. A denies that choice, and B, C, and D each erase the others that plainly exist.

A SOC 2 report attests to controls in which categories?

  1. Only the privacy of personal data the service organization holds
  2. Security, availability, processing integrity, confidentiality, privacy
  3. Only the accuracy of the service organization's financial reporting
  4. Only compliance with the HIPAA Security Rule safeguards for PHI

Answer: B — Security, availability, processing integrity, confidentiality, privacy

SOC 2 reports against the AICPA Trust Services Criteria, where Security is mandatory and the remaining four are scoped to customer commitments; Type I covers design at a point in time and Type II covers operating effectiveness over a period. A and D each name a single criterion or unrelated regime. C describes SOC 1 financial-reporting scope.

What is the FIRST step in the CompTIA troubleshooting methodology?

  1. Establish a theory of probable cause
  2. Test the theory to determine cause
  3. Identify the problem
  4. Document findings and outcomes

Answer: C — Identify the problem

Step 1 is identify the problem (gather info, question users, reproduce). (A) is step 2; (B) is step 3; (D) is the final step — a common direction-reversal trap.

Which regulation governs payment-card data handling?

  1. HIPAA, covering protected health information records
  2. PCI DSS, covering stored cardholder account data
  3. SOX, covering financial reporting accuracy controls
  4. GLBA, covering consumer financial privacy rules

Answer: B — PCI DSS, covering stored cardholder account data

B) PCI DSS is the card brands' standard for protecting cardholder data. A) HIPAA governs US health information. C) SOX addresses financial reporting controls for public companies. D) GLBA governs privacy at financial institutions.

Gap analysis in a security program is best described as:

  1. Penetration testing to find exploitable holes in the network
  2. Counting unpatched systems reported by the vulnerability scanner
  3. Comparing current posture to a target framework's controls
  4. Auditing firewall rule sets for overlapping or shadowed rules

Answer: C — Comparing current posture to a target framework's controls

C) Gap analysis measures current state against a desired target such as NIST CSF or ISO 27001 and names the missing or weak controls. A) Pen testing proves exploitability, not framework coverage. B) Patch counts are one input. D) Rule audits are far narrower in scope.

You are working on a user's machine and find personal/confidential files. You should:

  1. Read the files to better understand the user's daily workflow
  2. Forward copies to your manager so that a record exists on file
  3. Leave unrelated content alone; report illegal material per policy
  4. Share what you found with coworkers on the same support team

Answer: C — Leave unrelated content alone; report illegal material per policy

(C) Professional conduct means accessing only what the ticket requires, with a defined escalation path for illegal content. (A), (B), and (D) all access or distribute private data without any business justification.

An SLA (Service Level Agreement) defines:

  1. Agreed service targets and breach remedies
  2. The license terms for delivered source code
  3. The wage scale for the support technicians
  4. The organization's information security policy

Answer: A — Agreed service targets and breach remedies

(A) An SLA sets measurable response, resolution, and availability commitments with remedies for breach. (B), (C), and (D) are different documents entirely.

The NIST Cybersecurity Framework (CSF) functions are:

  1. Identify, Protect, Detect, Respond, Recover, plus Govern in CSF 2.0
  2. Plan, Do, Check, Act, the improvement cycle drawn from ISO 9001
  3. Read, Write, Execute, the permission bits used on file systems
  4. The three lines of defense model used in enterprise risk governance

Answer: A — Identify, Protect, Detect, Respond, Recover, plus Govern in CSF 2.0

(A) These are the CSF core functions, with Govern added in version 2.0. (B) is the PDCA quality cycle. (C) is file permissions. (D) is a governance model, not the CSF structure.

Security Program Management and Oversight flashcards

4 cards from the 44 in this chapter.

What is a bug bounty program?

An organization offers rewards to security researchers who responsibly disclose vulnerabilities. Crowdsources security testing. Examples: HackerOne, Bugcrowd.

What is a privacy impact assessment (PIA)?

An analysis of how personal information is collected, used, shared, and protected. Required by many privacy regulations.

What is residual risk?

The risk remaining after security controls are applied. Acceptable residual risk is determined by the organization's risk appetite.

What is a data processor vs. data controller (GDPR)?

Controller: determines the purposes and means of processing personal data. Processor: processes data on behalf of the controller. Both have legal obligations.

Practise the full chapter

These are a sample. The full Security Program Management and Oversight chapter runs 112 items with per-chapter progress tracking, on the web and in the iOS app.

Open CompTIA Security+ in CoStudy →

Other CompTIA Security+ chapters

All CompTIA Security+ practice questions →