SY0-701: Security Program Management & Oversight
Security Program Management & Oversight is one of the skill areas tested on the Security+ (SY0-701) exam. Below are free SY0-701 practice questions with worked answers and a concept diagram — each with a plain-language explanation. Practice the first 10 questions of SY0-701 free, no signup.
The concept, in one picture
2 free SY0-701 Security Program Management & Oversight questions
An accountant gets an unexpected message promising a tax rebate if they click an enclosed link. Before clicking, the accountant pauses, hovers the cursor over the link, and sees that it resolves to an unrelated, misspelled domain instead of the company's finance portal — so they delete the message and report it. Which security program element most directly enabled the accountant to catch this attempt?
- ✓ A recurring security awareness program that teaches staff to inspect link destinations before clicking
- An automated secure email gateway that rewrites and scans embedded URLs
- A written acceptable-use policy that prohibits clicking external links
- Configuring the mail client to render all incoming messages as plain text
The give-away is that a human paused and manually inspected the link's true destination before acting — the exact habit that ongoing security awareness training instills, making it a people/program control rather than a technical one. An automated email gateway would have scanned the URL on the server side without the user's involvement, so it does not describe what the accountant personally did. An acceptable-use policy sets expectations on paper but does not, by itself, give a user the skill to spot a spoofed domain in the moment. Rendering mail as plain text can reveal a mismatched link but is a client configuration, not the reason the accountant knew to check and recognize the deception.
During onboarding, a staff member browsed to a gambling site that the organization prohibits. A subsequent review concluded the individual breached a governing document that spells out how corporate devices and internet access may be used. Which document was breached?
- ✓ Acceptable use policy (AUP)
- Non-disclosure agreement (NDA)
- Memorandum of understanding (MOU)
- Memorandum of agreement (MOA)
An acceptable use policy (AUP) is the internal document that states what employees may and may not do with company systems, networks, and internet access, so visiting a banned site is a direct AUP violation. An NDA governs the protection of confidential information, not browsing behavior. An MOU and an MOA are agreements that describe intent or responsibilities between two separate parties or organizations, so neither dictates an individual employee's day-to-day system use.
Practice SY0-701 free
The first 10 questions of every exam are free. No signup, no email wall.
Start practicing →Get a free SY0-701 study plan by email
A short plan to work through SY0-701 by skill area, plus a note when we add new questions. Optional — the practice above stays free. No spam, unsubscribe anytime.