ExamOpsPractice free

CompTIA Security+ SY0-701 · Free study guide

Objective 4.2 — Manage technology and data assets securely across their lifecycle

Unknown assets cannot be patched, monitored, retained, or retired reliably. Asset management begins during procurement and continues until every account, credential, data copy, and trust relationship is removed.

Acquisition should define a business owner, security requirements, supported lifetime, update process, logging capability, data handling, vendor access, and disposal terms. Low purchase price can hide future risk when a product cannot be updated or exported from safely.

Assignment and accounting connect an asset to a custodian, location, purpose, and classification. Ownership means accountability for use and risk; it is not always physical possession. Data classification should drive storage, access, monitoring, retention, and disposal requirements.

Inventory and tracking

An inventory should use durable identifiers and reconcile multiple sources: procurement, management platforms, network discovery, cloud accounts, software catalogs, and physical checks. Enumeration discovers what is present; classification and ownership explain what it is and why it matters. Track hardware, software, virtual resources, certificates, service accounts, data stores, and licenses.

Monitor lifecycle signals such as missing agents, unsupported versions, owner changes, inactive resources, and unexpected network appearance. Reconciliation is important because any one source can be incomplete. A cloud instance can disappear from a network scan while still storing snapshots or credentials.

Disposal and decommissioning

Choose sanitization or destruction based on data sensitivity, media type, reuse plan, and approved policy. Deleting a filename does not necessarily remove recoverable data. Cryptographic erasure can be effective when encryption and key management were implemented correctly. Physical destruction should be appropriate for the medium and evidenced.

Decommissioning also removes logical remnants: accounts, keys, certificates, DNS, firewall rules, monitoring exceptions, backups, replicas, vendor portals, and inventory relationships. Retention rules may require preserving selected records even as the service is dismantled. A completion certificate records what was handled, by whom, when, and under which procedure.

Decision rule: follow the asset and its data from approved acquisition through accountable use to verified removal; powering something off is not proof that its risk is gone.

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free