Free CompTIA Security+ SY0-701 Practice Question

Your organization has implemented strong internal controls to manage sensitive customer data. During a routine internal audit, you discover that a newly implemented software tool does not comply with the established encryption standards. What is the next step to maintain compliance?

  • Document the issue and wait for the next external audit to confirm the non-compliance before taking action.

  • Request a feature update from the software tool vendor to accommodate the required encryption standards without internal notification.

  • Immediately cease using the tool across the organization until it complies with encryption standards.

  • Report the non-compliance issue to the compliance department for review and correction.

This question's topic:
CompTIA Security+ SY0-701 / 
Security Program Management and Oversight
Your Score:

Check or uncheck an objective to set which questions you will receive.