nerdexam
CompTIA

SY0-501 · Question #533

An external auditor visits the human resources department and performs a physical security assessment. The auditor observed documents on printers that are unclaimed. A closer look at these documents…

The correct answer is D. Report to the human resources manager that their personnel are violating a privacy policy. An external auditor found unattended documents containing sensitive PII on printers in the human resources department, indicating a clear violation of data privacy policies.

Submitted by jordan8· Mar 4, 2026Security program management and oversight

Question

An external auditor visits the human resources department and performs a physical security assessment. The auditor observed documents on printers that are unclaimed. A closer look at these documents reveals employee names, addresses, ages, and types of medical and dental coverage options each employee has selected. Which of the following is the MOST appropriate actions to take?

Options

  • AFlip the documents face down so no one knows these documents are PII sensitive
  • BShred the documents and let the owner print the new set
  • CRetrieve the documents, label them with a PII cover sheet, and return them to the printer
  • DReport to the human resources manager that their personnel are violating a privacy policy

How the community answered

(54 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    9% (5)
  • D
    85% (46)

Why each option

An external auditor found unattended documents containing sensitive PII on printers in the human resources department, indicating a clear violation of data privacy policies.

AFlip the documents face down so no one knows these documents are PII sensitive

Flipping documents face down only conceals the immediate exposure without resolving the underlying policy violation or preventing future occurrences of sensitive PII being left unattended.

BShred the documents and let the owner print the new set

Shredding the documents removes the immediate risk but does not address the fundamental issue of HR personnel violating privacy policies by leaving sensitive PII unattended on printers.

CRetrieve the documents, label them with a PII cover sheet, and return them to the printer

Retrieving and labeling the documents, then returning them to an unattended printer, still poses a risk of PII exposure and does not resolve the systemic non-compliance with data privacy policies.

DReport to the human resources manager that their personnel are violating a privacy policyCorrect

Reporting the policy violation to the human resources manager is the most appropriate action because it addresses the systemic issue of personnel failing to adhere to data privacy policies, rather than just the immediate incident. This escalation ensures that management can investigate the root cause, reinforce training, and implement corrective measures to prevent future PII exposure.

Concept tested: Data privacy policy enforcement and incident reporting

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-data-privacy

Topics

#PII#privacy policy#data handling#clean desk policy

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice