TechNuggets Academy

Security Program Management and Oversight

Free CompTIA Security+ (SY0-701) practice — 6 questions on Security Program Management and Oversight, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Security Program Management and Oversight
A risk register entry for a legacy web server lists an asset value of $500,000. A recent risk assessment determined the exposure factor for a successful compromise is 20%, and historical incident data shows this type of event occurs on average once every two years (ARO = 0.5). Based on quantitative risk analysis, what is the annualized loss expectancy (ALE) for this asset?
SLE = Asset Value x Exposure Factor = $500,000 x 0.20 = $100,000. ALE = SLE x ARO = $100,000 x 0.5 = $50,000. The 0.5 ARO reflects that the event happens less than once per year, which the exam frequently tests.
Question 2 of 6 · Security Program Management and Oversight
Two companies want to document their shared intent to jointly explore a future product partnership. Neither party is committing to specific deliverables, pricing, or legally binding obligations at this stage — they simply want a formal record of mutual understanding. Which agreement type is BEST suited for this purpose?
An MOU documents a general, good-faith understanding between parties without creating enforceable legal obligations or specifying deliverables — exactly matching the scenario's non-binding, exploratory intent.
Question 3 of 6 · Security Program Management and Oversight
During a business impact analysis following a simulated ransomware outbreak, the incident response team concludes that the organization can tolerate losing, at most, 4 hours of transaction data, while the application itself must be restored within 8 hours to satisfy a customer SLA. Which metric represents the 4-hour data loss tolerance?
RPO defines the maximum acceptable amount of data loss, measured as a point in time (e.g., last 4 hours of transactions) that determines backup frequency requirements.
Question 4 of 6 · Security Program Management and Oversight
A financial institution's board of directors has approved a formal statement describing, in general terms, the overall amount and types of risk the organization is willing to pursue in order to achieve its strategic objectives. The statement does not specify numeric thresholds or acceptable deviation ranges. Which governance element does this BEST describe?
Risk appetite is the broad, qualitative statement of how much risk an organization is willing to accept overall in pursuit of its objectives — set at the governance/board level as strategic philosophy.
Question 5 of 6 · Security Program Management and Oversight
An organization contracts a cloud provider to store and process customer records strictly according to the organization's written instructions. The cloud provider has no authority to determine why or how the data is ultimately used and only acts on the organization's directives. Under data privacy regulatory frameworks, which role does the cloud provider hold?
A data processor handles data strictly on behalf of and under the instructions of another party, without determining the purposes or means of processing — precisely matching the described relationship.
Question 6 of 6 · Security Program Management and Oversight
A security firm hired to evaluate a data center's overall security posture sends a team on-site. The team uses lock-picking tools to bypass a locked door and tailgates behind an employee to enter the server room without triggering any alarms. Which type of penetration test is being performed?
A physical penetration test evaluates real-world physical security controls — locks, badge access, tailgating resistance — by attempting to physically breach a facility, exactly as described.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

$109.99 $34.99 with code FREETEST33 — valid through September 2.

Get my $34.99 deal →