Security Program Management and Oversight
SY0-701 · 60 questions
- City IT discovers staff running personal cryptocurrency miners on servers. Which governance artifact most directly prohibits that use of organizational resources?
- A records manager asks how municipal governance documents differ. Which statement correctly contrasts them?
- A mayor’s office wants distinct written policies for information security, business continuity, disaster recovery, incident response, secure development, and change control. Why separate them?
- Public-works IT must enforce measurable password length, MFA for remote access, badge requirements for server rooms, and approved encryption algorithms. Which artifact type sets those mandatory specifics?
- HR and security need consistent steps when hiring and terminating staff who access citizen data systems, plus a ransomware response playbook. Which artifacts operationalize those steps?
- A border-city CISO must shape governance that reflects privacy statutes, court orders, industry baselines, and both local and national obligations. Which statement best describes these inputs?
- After a major incident and as the calendar year turns, which governance practice keeps municipal policies effective?
- A county needs clear oversight for IT security direction across departments. Which option best identifies governance structures that decide and oversee that direction?
- A public-health dataset of clinic encounters is stored by IT and processed by a contracted analytics firm under the health department’s instructions. Which role pairing is most accurate?
- Engineers want to push emergency firewall changes to a city data center with no ticket, approval, or backout plan because “it is faster.” Which governance response is correct?
- A county CIO must justify spending on a warm alternate site for tax and permitting systems. Which governance artifact most clearly sets the recovery expectations that the technical disaster-recovery design must meet?
- A city applications team wants to push a new citizen-portal build straight to production tonight. Which policy requirement should stop that deploy until security gates are complete?
- During a municipal risk identification workshop, finance and IT list ransomware that encrypts property-tax databases as a top concern. What is the workshop primarily accomplishing?
- A county must choose risk-assessment cadences for three systems: a rarely changed archival land-record vault, a permitting app that ships monthly features, and a 911 CAD platform that changes configuration daily. Which pairing best matches assessment type to change rate and criticality?
- A city council must decide whether to issue bonds that fund a multi-million-dollar SCADA upgrade and wants a dollar-based annual risk figure for outage exposure. Which analysis approach best fits that decision?
- A utility estimates that a payment-portal outage would cost $50,000 in lost fees and overtime (SLE) and expects such an outage twice per year (ARO = 2). What is the ALE?
- A flood model shows that if the riverside 911 radio shed floods, 40% of the $200,000 equipment value would be destroyed. In quantitative risk terms, what does that 40% figure represent?
- A county risk officer needs a living record that names each top risk, assigns an owner, records thresholds, and tracks key risk indicators for leadership reviews. Which artifact should they maintain?
- The city council states it is willing to take moderate cyber risk to keep online permitting fast for businesses, while IT must keep residual risk inside a defined band around that stance. How should appetite and tolerance be distinguished here?
- After MFA, immutable backups, and segmentation, a school district still faces residual ransomware financial exposure. Which risk strategy best describes buying a cyber insurance policy for that remainder?
- A library kiosk still runs a legacy catalog plugin that cannot support MFA. The risk is rated low, the catalog is air-gapped from payment systems, and leadership documents a time-boxed exemption. Which strategy is being used?
- A parks department plans public Wi-Fi kiosks that would expose unsegmented access into the utility SCADA VLAN. Redesign will take months and residual risk exceeds appetite. What strategy should leadership apply until a safe design exists?
- A transit agency faces ransomware risk against fare-collection servers. Leadership wants to reduce both likelihood of compromise and impact of encryption. Which action set best illustrates risk mitigation?
- Before a quarterly meeting, the CISO must brief the municipal audit committee on top cyber risks, treatment status, and trend indicators. Which activity is required?
- A city's BIA shows online building permits can be offline for 72 hours with limited harm, while 911 CAD must resume within 15 minutes and lose no more than 30 seconds of call data. What do those figures primarily represent?
- Facilities notes that aging courthouse badge controllers fail often and take many hours to restore. Which pair of metrics best frames that resilience discussion in a BIA or risk context?
- A county is selecting a cloud backup provider for court records and needs contractual ability to verify the vendor's security claims after signing. Which assessment requirement should be negotiated first?
- While evaluating a SaaS case-management vendor for public health, the procurement team reviews SOC reports and summaries of the vendor's recent internal audits. What is the team primarily doing?
- An elections office must understand not only the ballot-system integrator but also who builds firmware and hardware components upstream. Which third-party activity addresses that need?
- Before awarding a 24×7 security-monitoring contract, a city requires financial checks, reference calls, and a review of whether evaluation panelists have financial ties to bidders. Which vendor-selection practices are being applied?
- A township hires an MSP to run endpoint detection and shares network diagrams during onboarding. Which pair of agreements best matches uptime/response commitments versus protecting the diagrams?
- A city and a neighboring county want to document intent to share SOC analysts without creating a detailed commercial statement of work yet. Which agreement type best fits that early intergovernmental partnership?
- Six months after signing, a city's EHR hosting vendor changes subprocessors and suffers a regional outage. Why is ongoing vendor monitoring still required?
- HR wants a scalable way to collect control evidence from multiple SaaS benefits vendors before renewal. Which method best fits that need?
- A water utility will hire a third party to penetration-test the customer portal and selected OT jump hosts. What must be defined before testing begins?
- A SaaS vendor that hosts the city’s permit portal sends its own penetration-test report as proof of security. What is the most appropriate way for the city to treat that evidence?
- A grant-funded housing assistance system must show security status both to the city’s CIO and to the state grant office. Which distinction should the compliance lead apply first?
- After missing mandated cybersecurity reporting for a regulated utility billing system, which set of outcomes best illustrates realistic consequences of non-compliance?
- The county wants ongoing proof that privacy and security controls for resident services stay in place—not only a once-a-year binder review. Which approach best matches compliance monitoring?
- A regional tourism portal stores visitor contact data that may involve local ordinance, state privacy law, and cross-border guests. What should the privacy lead emphasize about legal implications?
- A resident submits a right-to-be-forgotten request through the city’s online services portal. What should the privacy process emphasize first?
- A vendor hosts the city’s constituent CRM and processes resident records only on the city’s documented instructions. How should controller versus processor roles be assigned?
- Before a compliance audit of records management, which pair of artifacts most directly helps the city prove it knows what data it holds and how long it keeps it?
- After mandatory compliance training on handling grant-funded case files, what evidence best shows staff understood and accepted their obligations?
- Automation flags permit archives kept past the city’s retention policy. How does this use of automation support compliance monitoring?
- The city auditor reviews security control evidence for a public-works system, while a state regulator later conducts a formal examination of the same environment. Which statement best distinguishes these activities?
- A federal grantor asks for a formal assurance statement on security controls for a homelessness-services platform. Which engagement type is designed to provide that kind of assurance reporting?
- Security findings from recent assessments need council-level visibility. Which body typically provides oversight of such findings in the municipal assurance ecosystem?
- Parking payment kiosks that handle cardholder data need unbiased assurance before peak festival season. Which assessment approach best fits?
- Facilities wants a test that walks locked doors and badge controls at city hall, while IT wants network exploitation testing, and leadership wants both views combined. Which pentest-type framing matches those goals?
- For a web application test of the library catalog, leadership can give testers full architecture notes, limited hints, or almost no insider detail. Which knowledge framing should guide the engagement design?
- Before a third-party assessment of the transit website, analysts gather public OSINT quietly, then propose port scans against production. What distinction matters most?
- A state cybersecurity bureau schedules a mandatory examination of the county’s emergency-alert systems, while the county also buys a voluntary security assessment from a consulting firm. How should leaders treat the regulatory examination?
- Human resources wants staff to get better at spotting and reporting fake 'payroll update' emails. Which awareness practice best addresses that goal?
- A supervisor notices a clerk emailing large case exports to a personal address at odd hours without a business need. Which awareness theme does this scenario highlight for training?
- Remote permitting clerks work from home with laptops and occasional USB drives. Which awareness content set best matches practical user guidance for that hybrid municipal workforce?
- After launching security awareness for new hires, leadership asks whether training stays effective over time. What should the program measure and schedule?
- A department head proposes 'sending one cautionary email' as the entire security awareness effort for the year. What should the CISO require instead?
- Employees use the report-phish button, but tickets often sit untouched for days. What awareness-related operational fix is most important?
- During awareness month, HR wants staff warned that outsiders might recruit or pressure employees for access—without encouraging casual accusations against coworkers. What should the module emphasize?