5.1 Summarize elements of effective security governance
Objective 5.1 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
Before enforcing a new business rule, a security manager first assigns it with an audit effect to observe its impact, then switches to a deny effect once satisfied. This staged rollout follows which governance element?
The concept
Procedures are the documented, repeatable sequence of steps followed to achieve a safe, consistent outcome.
Why this answer
Following a defined sequence, audit first then deny, to safely roll out enforcement is a documented procedure.
- Correct: a defined sequence of rollout steps is a procedure.
- BStandards fix the destination. They are silent on the order you get there in.
- CNo outside body required this sequencing; the manager chose it.
- DShows who reports to whom. Useful, and not a set of steps.
- ERight answer if the question had asked who reviews the audit findings before the switch to deny.
Now you: objective 5.1 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A cloud architect groups ten related business rules into a single policy initiative and assigns it once to a subscription, rather than creating ten separate assignments. This grouping mainly supports which governance element?
Sample question 2 of 3
An engineering team received an approved exception to skip a mandatory control six months ago, citing an urgent deadline. No one has revisited whether the exception is still justified. Which governance gap does this best describe?
Sample question 3 of 3
Which governance structure gives business units common risk management principles, methodologies, and tools so they can perform consistent, comparable risk assessments?
That’s 3 of the full Security+ bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practicingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Program Management and Oversight
- 5.2 5.2 Explain elements of the risk management process
- 5.3 5.3 Explain the processes associated with third-party risk assessment and management
- 5.4 5.4 Summarize elements of effective security compliance
- 5.5 5.5 Explain types and purposes of audits and assessments
- 5.6 5.6 Given a scenario, implement security awareness practices