What Sensitive Information Should Be Scrubbed from Job Postings?
An analyst is reviewing job postings to ensure sensitive company information is not being shared with the general public. Which of the following is the analyst most likely looking for?
Community Votes
64% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests operational security (OpSec) and open-source intelligence (OSINT) awareness, trapping candidates who prioritize personal identification data over technical reconnaissance vectors.
This Security+ question evaluates how organizations protect against unintentional data leaks through public-facing documents like job postings. The community consensus emphasizes that disclosing software versions poses a greater operational security risk than other listed items, as it reveals exploitable system vulnerabilities.
Candidates frequently select Government Identification Numbers due to their association with identity theft and high sensitivity, failing to recognize that such data rarely appears in job advertisements and does not directly expose corporate infrastructure vulnerabilities.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Operational Security & OSINT
This question focuses on Operational Security (OpSec) and mitigating Open Source Intelligence (OSINT) threats. Organizations must regularly audit public materials to prevent attackers from gathering actionable intelligence.Why Option B is Correct
Revealing software versions in job postings or internal documentation provides threat actors with critical reconnaissance data. Attackers routinely cross-reference disclosed versions with public Common Vulnerabilities and Exposures (CVE) databases to identify unpatched systems. As noted in community discussions, posting these details effectively hands attackers a roadmap to exploit known weaknesses, making it a primary target for security reviews.Why Other Options Are Incorrect
- Government Identification Numbers: While highly sensitive personally identifiable information (PII), these numbers are almost never included in corporate job postings. Their absence makes them irrelevant to this specific scenario.
- Office Addresses & Board Member Lists: These are standard public business disclosures required for regulatory compliance and corporate transparency. They do not constitute sensitive security information that would compromise the organization's defensive posture.
Community Insights
The voting split between B and D reflects a common test-taking dilemma. Supporters of D correctly identify the sensitivity of government IDs but overlook the contextual clue that job postings focus on corporate roles, not individual employee credentials. CompTIA consistently prioritizes answers that address systemic infrastructure risks over isolated PII concerns in this objective domain.Official Reference
Exam Strategy
When analyzing scenarios involving public information exposure, always weigh the likelihood of the data appearing in the given context against its potential to enable attacker reconnaissance. Favor answers that highlight systemic vulnerabilities or attack surface expansion over isolated personal data, as CompTIA heavily tests proactive threat modeling and operational security principles.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →