🇺🇸 CompTIA Security+ · flashcards

CompTIA Security+ Security Program Management and Oversight Flashcards

71 question-and-answer cards covering Security Program Management and Oversight as it is examined in CompTIA Security+. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

71Cards in deck
24Free preview
23Syllabus topics
~208Chars per answer
FreePrice

24 sample cards from the Security Program Management and Oversight deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is attestation in the context of compliance?

    A formal declaration or acknowledgment—often signed by management or a third party—affirming that controls are in place and the organization meets specific compliance requirements.

  2. What are common legal implications/scopes of compliance: local, national, and global?

    Compliance obligations vary by jurisdiction—local (city/state), national (country-wide laws), and global/international (cross-border regulations like GDPR)—and organizations must satisfy all applicable layers where they operate.

  3. What is the difference between data inventory and data retention in a privacy program?

    Data inventory catalogs what personal/sensitive data is held, where it lives, and how it flows. Data retention defines how long data is kept and when it must be securely disposed of, per policy and law.

  4. What is the 'right to be forgotten'?

    A privacy right (notably under GDPR) allowing individuals to request that an organization delete their personal data when there is no compelling reason to keep it.

  5. Differentiate the roles of data subject, data owner, and data controller in privacy.

    Data subject = the individual whom the personal data is about. Data owner = internal party accountable for the data's classification/protection. Data controller = the entity that decides the purposes and means of processing the data.

  6. What is the difference between an internal audit and an external audit?

    An internal audit is performed by the organization's own staff to evaluate controls and readiness. An external audit is conducted by an independent third party, providing impartial verification and credibility (e.g., regulatory or certification audits).

  7. What is the difference between an audit, an assessment, and a penetration test?

    An audit verifies compliance against a defined standard/control set. An assessment broadly evaluates security posture and gaps. A penetration test actively exploits vulnerabilities to demonstrate real-world impact.

  8. What is attestation versus examination in independent assessments?

    In an attestation engagement, an auditor reports on management's own assertion about controls. In an examination, the auditor independently tests and forms an opinion on the controls/subject matter directly.

  9. What is phishing, and how does it differ from spear phishing and whaling?

    Phishing = mass fraudulent messages to trick users into revealing data or clicking malicious links. Spear phishing = targeted at a specific individual/group. Whaling = spear phishing aimed at high-value executives (the 'big fish').

  10. Differentiate phishing, vishing, smishing, and pharming.

    Phishing = fraudulent email. Vishing = voice/phone-based. Smishing = SMS/text-based. Pharming = redirecting users to a fake site (e.g., via DNS poisoning) without requiring them to click a link.

  11. What are common indicators that help users recognize a phishing message?

    Urgent or threatening language, requests for credentials/payment, generic greetings, mismatched or spoofed sender addresses, suspicious links/attachments, spelling/grammar errors, and unexpected requests that bypass normal process.

  12. What is anomalous behavior recognition in user security awareness?

    Training users and systems to detect deviations from normal patterns—risky behavior, unexpected actions, or unintentional behavior—that may indicate compromise or insider threat.

  13. Classify the three types of anomalous behavior emphasized in Security+ user guidance.

    Risky behavior (knowingly dangerous actions), unexpected behavior (out-of-pattern activity), and unintentional behavior (accidental mistakes such as misdirected email or accidental data exposure).

  14. What topics should comprehensive user guidance and security awareness training cover?

    Policies/handbooks, situational awareness, insider threat, password management, removable media/cables, social engineering, operational security, and hybrid/remote work practices.

  15. What is operational security (OPSEC) guidance for users?

    Teaching users to protect sensitive information by limiting what details (about systems, projects, or routines) they disclose, since seemingly harmless data can be aggregated by adversaries for attacks.

  16. What is an insider threat, and what user guidance reduces it?

    A security risk originating from people inside the organization (employees, contractors). Guidance includes least-privilege access, monitoring, reporting suspicious behavior, and clear acceptable-use and data-handling policies.

  17. What are the key phases of developing and executing a security awareness program?

    Develop (design content and objectives), Execute (deliver training/campaigns), Review/measure (assess effectiveness via metrics like phishing click rates), and continuously improve based on results.

  18. Why is a security awareness program treated as a recurring cycle rather than a one-time event?

    Because threats evolve, staff change, and behavior reverts over time; continuous reinforcement, periodic phishing simulations, and metric-driven updates keep users effective against current attacks.

  19. What metrics measure the effectiveness of a phishing awareness/anti-phishing campaign?

    Phishing simulation click-through rates, reporting rates (how many users report the test), time-to-report, repeat-offender counts, and trends in these metrics over successive campaigns.

  20. What is the purpose of recognizing and reporting phishing attempts (the 'report' behavior)?

    Prompt reporting lets security teams contain threats, warn other users, block malicious senders/links, and improve defenses—turning each user into an active sensor in the human firewall.

  21. What is a gap analysis in the context of audits and assessments?

    A comparison of an organization's current security state against a desired standard or framework to identify the differences ('gaps') that must be remediated to reach compliance.

  22. What is the difference between compliance monitoring done internally versus by an external entity?

    Internal compliance monitoring uses the organization's own tools/staff for self-assessment and continuous oversight. External monitoring involves regulators or third-party auditors verifying adherence, often required for certifications or legal obligations.

  23. What is supply chain risk, and why is vendor monitoring critical to it?

    Supply chain risk is the threat that a compromised vendor, supplier, or service provider introduces vulnerabilities into your environment. Ongoing vendor monitoring is critical because a third party's security posture can degrade after onboarding.

  24. What is the difference between an SLA and an OLA?

    An SLA (Service Level Agreement) is between a service provider and an external customer. An OLA (Operational Level Agreement) defines responsibilities between internal teams/departments that support delivery of that SLA.

What this deck covers

The Security Program Management and Oversight deck follows the CompTIA Security+ Security Program Management and Oversight syllabus — 5 chapters and 23 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 14.2 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 208 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Security Program Management and Oversight flashcards FAQ

How many Security Program Management and Oversight flashcards are in this CompTIA Security+ deck?

71 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CompTIA Security+ flashcards free?

Yes. The preview here is free to read with no signup, and the full 71-card deck is free inside the Examius app.

What do the Security Program Management and Oversight cards cover?

They follow the CompTIA Security+ Security Program Management and Oversight syllabus — 5 chapters and 23 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.