What Best Describes Researching Security Laws and Regulations?
Which of the following best describes the practice of researching laws and regulations related to information security operations within a specific industry?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your ability to identify proactive legal research in GRC frameworks, commonly confused with documentation-heavy practices like attestation or compliance reporting.
Due diligence is the proactive investigation of applicable laws, regulations, and industry standards to ensure legal and operational compliance. The community unanimously agrees that researching these requirements defines due diligence rather than reactive reporting or specific regional mandates.
Candidates often select 'Compliance reporting' or 'Attestation' by mistakenly equating the research phase with post-implementation documentation or third-party certification processes.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Due diligence represents the proactive effort to investigate, research, and understand applicable laws, regulations, and industry standards before implementing security controls. In the context of SY0-701, this practice ensures that an organization identifies legal obligations early to effectively manage risk and avoid penalties. The question explicitly highlights the research phase, which is the foundational step of due diligence.Why the Other Options Are Wrong
Compliance reporting involves documenting and submitting evidence of adherence after controls are already in place, rather than the initial research stage. GDPR is a specific regional data privacy regulation, not a generalized practice or methodology for legal research. Attestation requires a formal third-party validation that controls meet predefined criteria, which occurs much later in the governance lifecycle.Community Comment Notes
Multiple contributors confirmed option C as correct, emphasizing that due diligence inherently covers the thorough investigation of legal and regulatory landscapes [1][2]. Commenters clarified that while GDPR is a well-known mandate, due diligence is the overarching process used to identify and comply with such requirements [3]. The unanimous voting pattern demonstrates strong candidate alignment with the official exam objectives regarding GRC terminology.Official Reference
Exam Strategy
Focus on distinguishing proactive governance activities like due diligence and due care from reactive documentation tasks such as compliance reporting or attestation. Create flashcards for GRC vocabulary pairs, as SY0-701 consistently tests nuanced differences between similar-sounding compliance terms.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →