What Sensitive Information Should Be Scrubbed from Job Postings?

An analyst is reviewing job postings to ensure sensitive company information is not being shared with the general public. Which of the following is the analyst most likely looking for?

  1. Office addresses
  2. Software versions Source Reference Answer
  3. List of board members
  4. Government identification numbers

Community Votes

B
64%
D
36%

64% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests operational security (OpSec) and open-source intelligence (OSINT) awareness, trapping candidates who prioritize personal identification data over technical reconnaissance vectors.

This Security+ question evaluates how organizations protect against unintentional data leaks through public-facing documents like job postings. The community consensus emphasizes that disclosing software versions poses a greater operational security risk than other listed items, as it reveals exploitable system vulnerabilities.

Candidates frequently select Government Identification Numbers due to their association with identity theft and high sensitivity, failing to recognize that such data rarely appears in job advertisements and does not directly expose corporate infrastructure vulnerabilities.

Community Discussion (5 comments)

1f2b013 👍 6 Selected: B
When reviewing job postings, an analyst is most likely looking for information that could inadvertently expose the company's vulnerabilities or security posture. Posting software versions could reveal outdated or vulnerable systems, which attackers might exploit.
MarysSon 👍 1 Selected: D
D is the better answer. Government identification numbers fall under sensitive data because some ID numbers can be misused as a launchpad for attacks. Software version numbers are typically public information. If a company is concerned about a vulnerability in a software version, it should be patched, upgraded, or replaced.
9149f41 👍 1 Selected: B
The Gov ID number usually never appears in the job ad. So this is not relevant with questions. However, the software version contains sensitive data.
Eracle 👍 1 Selected: D
Government Identification Numbers are more sensibile data than others.
ProudFather 👍 2 Selected: D
An analyst reviewing job postings for sensitive company information would be most concerned about the disclosure of Government Identification Numbers. These numbers are highly sensitive and can be misused for identity theft and fraud. Here's why other options are less critical: A. Office addresses: While generally not considered highly confidential, publicly disclosing office addresses could potentially aid in physical security assessments or social engineering attacks. B. Software versions: Software versions are often publicly available and not considered highly sensitive. C. List of board members: While information about board members is generally public, disclosing this information in job postings might not be the company's standard practice. Therefore, the disclosure of Government Identification Numbers in job postings poses the highest risk of sensitive data leakage.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Operational Security & OSINT

This question focuses on Operational Security (OpSec) and mitigating Open Source Intelligence (OSINT) threats. Organizations must regularly audit public materials to prevent attackers from gathering actionable intelligence.

Why Option B is Correct

Revealing software versions in job postings or internal documentation provides threat actors with critical reconnaissance data. Attackers routinely cross-reference disclosed versions with public Common Vulnerabilities and Exposures (CVE) databases to identify unpatched systems. As noted in community discussions, posting these details effectively hands attackers a roadmap to exploit known weaknesses, making it a primary target for security reviews.

Why Other Options Are Incorrect

  • Government Identification Numbers: While highly sensitive personally identifiable information (PII), these numbers are almost never included in corporate job postings. Their absence makes them irrelevant to this specific scenario.
  • Office Addresses & Board Member Lists: These are standard public business disclosures required for regulatory compliance and corporate transparency. They do not constitute sensitive security information that would compromise the organization's defensive posture.

Community Insights

The voting split between B and D reflects a common test-taking dilemma. Supporters of D correctly identify the sensitivity of government IDs but overlook the contextual clue that job postings focus on corporate roles, not individual employee credentials. CompTIA consistently prioritizes answers that address systemic infrastructure risks over isolated PII concerns in this objective domain.

Official Reference

Exam Strategy

When analyzing scenarios involving public information exposure, always weigh the likelihood of the data appearing in the given context against its potential to enable attacker reconnaissance. Favor answers that highlight systemic vulnerabilities or attack surface expansion over isolated personal data, as CompTIA heavily tests proactive threat modeling and operational security principles.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide