Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A business owner asks the security team to compare the cost of two controls for a legacy application in dollar terms. The team estimates the annual chance of a breach, the potential loss per event, and the expected yearly loss after each control is applied. Which risk analysis approach is being used?

⚠ Common exam trap

The SY0-701 exam often tests the distinction between quantitative and qualitative risk analysis by embedding monetary terms in the scenario, leading candidates to mistakenly choose qualitative analysis when they see subjective-sounding phrases like 'annual chance' without recognizing that dollar values are the key indicator of a quantitative approach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Quantitative risk analysis

The question describes a risk analysis that uses dollar values for the annual chance of a breach, potential loss per event, and expected yearly loss after controls are applied. This is the hallmark of quantitative risk analysis, which assigns monetary or numerical values to risk components (e.g., ALE = SLE × ARO) to compare control costs in objective financial terms. The scenario explicitly asks for a cost comparison in dollar terms, which only a quantitative approach can provide.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Qualitative risk analysis

    Why it's wrong here

    Qualitative risk analysis does not produce dollar-based values; it assigns subjective ratings such as low, medium, or high to likelihood and impact, often using a risk matrix. Because the results are categorical rather than numerical, they cannot be used to calculate the financial cost of a control or compare it against expected loss in monetary terms. It is useful for prioritization and quick triage, but it does not support a cost-based comparison.

  • Quantitative risk analysis

    Why this is correct

    Quantitative risk analysis assigns numeric values to risk components, enabling direct cost comparison. It calculates metrics such as asset value, exposure factor, single loss expectancy (SLE), annualized rate of occurrence (ARO), and annualized loss expectancy (ALE). With these figures, an organization can compare the ALE before and after implementing a control, subtract the control's annual cost, and determine if the safeguard provides a positive return on investment. This makes it the correct method for comparing the cost of security measures.

  • Business impact analysis

    Why it's wrong here

    A business impact analysis (BIA) is a process used for business continuity planning; it identifies critical business functions, dependencies, and recovery requirements such as recovery time objectives (RTOs) and recovery point objectives (RPOs). While it may quantify the impact of a disruption, it does not calculate the cost-effectiveness of specific security controls or compare alternative safeguard investments. The BIA informs recovery strategies, not the financial comparison of risk mitigation options.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance is one of the risk response strategies, alongside mitigation, transfer, and avoidance, where management explicitly acknowledges the risk and decides to tolerate it without implementing additional controls. It is a decision made after risk analysis has been performed, not an analytical method for estimating expected losses. Accepting risk involves documenting the rationale and potential impact, but it does not involve calculating control costs or comparing alternatives financially.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.