nerdexam
CompTIA

SY0-301 · Question #550

The system administrator has deployed updated security controls for the network to limit risk of attack. The security manager is concerned that controls continue to function as intended to maintain…

The correct answer is C. Routine audits. Routine audits verify that deployed security controls are functioning correctly and maintaining the intended security posture over time, which is the core concern of the security manager.

Security program management and oversight

Question

The system administrator has deployed updated security controls for the network to limit risk of attack. The security manager is concerned that controls continue to function as intended to maintain appropriate security posture. Which of the following risk mitigation strategies is MOST important to the security manager?

Options

  • AUser permissions
  • BPolicy enforcement
  • CRoutine audits
  • DChange management

How the community answered

(25 responses)
  • A
    4% (1)
  • C
    88% (22)
  • D
    8% (2)

Why each option

Routine audits verify that deployed security controls are functioning correctly and maintaining the intended security posture over time, which is the core concern of the security manager.

AUser permissions

User permissions manage access rights for individuals but do not verify that the broader set of deployed security controls continues to function correctly.

BPolicy enforcement

Policy enforcement ensures rules are applied but does not assess whether the underlying technical controls that enforce those policies remain effective.

CRoutine auditsCorrect

Routine audits systematically evaluate whether security controls are operating as designed, identify gaps or degradation in control effectiveness, and confirm that the security posture matches organizational policy. This ongoing verification process is the primary strategy for ensuring that previously deployed controls continue to function as intended.

DChange management

Change management controls how modifications to systems are introduced but does not verify the ongoing effectiveness of existing security controls.

Concept tested: Routine audits for ongoing security control validation

Source: https://learn.microsoft.com/en-us/compliance/assurance/assurance-security-monitoring

Topics

#routine audits#risk mitigation#security controls#compliance

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice