SY0-701 Security Program Management and Oversight Practice Question
A business-critical internal reporting portal is exposed to all employees. A scan finds a high-severity vulnerability, but the vendor says a fix will not be available for 30 days. The application is only used by finance once a month, and the business can tolerate a brief outage if needed. Which risk treatment is the BEST immediate action?
⚠ Common exam trap
Test-takers frequently choose 'Accept the risk' (Option A) because the app is used infrequently, but they overlook that a high-severity vulnerability in an internal portal still poses a significant risk of lateral movement or data exposure, making acceptance inappropriate without compensating controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply compensating controls, such as restricting access and adding a temporary control, until the vendor patch is available.
Applying compensating controls—such as restricting access to only the finance team and implementing a temporary web application firewall (WAF) rule—immediately reduces the attack surface while the vendor develops a patch. This aligns with the risk treatment of mitigation, as it lowers the likelihood of exploitation without requiring a full fix. The business can tolerate a brief outage, so a temporary access control list (ACL) or IP whitelist is a practical, immediate measure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the application is used infrequently and the impact is limited.
Why it's wrong here
Risk acceptance is possible, but it is not the best immediate action when a known high-severity flaw is exposed to a broad user population. The organization still has time to reduce exposure before the patch arrives.
- ✓
Apply compensating controls, such as restricting access and adding a temporary control, until the vendor patch is available.
Why this is correct
This is the best choice because it reduces the likelihood of exploitation while the patch is unavailable. Restricting access to only the users who truly need the system, adding temporary network or application-layer controls, and documenting the residual risk are practical mitigation steps. The scenario shows the business can tolerate a short interruption, so a short-term reduction in exposure is more appropriate than doing nothing or permanently shutting the system down.
- ✗
Transfer the risk by purchasing cyber insurance for the application.
Why it's wrong here
Cyber insurance is a financial risk transfer mechanism that reimburses losses after an incident, but it does not reduce the likelihood of exploitation or the attack surface. It cannot block an attacker from abusing the vulnerability in the portal during the 30-day window before the vendor patch is released. Insurance also does not protect sensitive data, maintain business continuity, or prevent downtime, so it is not a compensating control. Additionally, policy exclusions for known unpatched vulnerabilities could render the coverage ineffective, leaving the organization exposed to both security and financial damage.
- ✗
Avoid the risk by permanently decommissioning the reporting portal.
Why it's wrong here
Permanently decommissioning the reporting portal would eliminate the vulnerability entirely, but it would also terminate a finance-critical business function with no immediate replacement, causing significant operational disruption. This option conflates short-term risk mitigation with long-term architectural decisions; the portal is needed for reporting, so avoidance is disproportionate and impractical. Unlike restricting access or adding a temporary WAF rule, decommissioning cannot be reversed quickly once the vendor patch is available, and it would require costly re-engineering to restore service. A more appropriate approach is to apply temporary compensating controls to reduce exposure while preserving the system's availability.
Visual reference
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.