Security Program Management and Oversight

Targeted SY0-701 practice for this exam objective, with an explanation for every answer option.

Practise this domain free

Certification
SY0-701
Domain
Security Program Management and Oversight
Questions
10

Practice SY0-701 Security Program Management and Oversight questions with exam-style scenarios, detailed explanations, and option-by-option rationale for this domain.

Example question from this objective

Each option is explained, so the reasoning behind the distractors is part of the answer.

A financial services company is migrating to the cloud and using Multi-Party Computation (MPC) for cold wallet security. Which KPI should be prioritized for the Board of Directors?

  • Mean Time To Detect (MTTD) for anomalous hot wallet transaction patterns after the cloud migration.
  • Percentage reduction in financial risk exposure from major cold wallet compromise scenarios after MPC implementation.
  • Total security engineering hours spent implementing and hardening MPC cold wallet controls.
  • Number of open critical findings from the latest PCI DSS audit for cloud payment processing infrastructure.

Mean Time To Detect (MTTD) for anomalous hot wallet transaction patterns after the cloud migration. — MTTD is a useful SOC metric, but it is too detailed for board reporting. The Board needs strategic risk and business impact, not detection performance data.

Percentage reduction in financial risk exposure from major cold wallet compromise scenarios after MPC implementation. — This KPI shows how MPC reduces potential financial loss from cold wallet compromise. It is board-level because it ties security controls to measurable business risk.

Total security engineering hours spent implementing and hardening MPC cold wallet controls. — Engineering hours show resource use, not control effectiveness or risk reduction. The Board is interested in outcomes and return on security investment.

Number of open critical findings from the latest PCI DSS audit for cloud payment processing infrastructure. — Open audit findings matter for remediation, but the raw count is tactical. The Board should see overall compliance risk and business impact, not individual findings.

Continue preparing