Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A business owner asks whether to proceed with a medium-risk issue on an internal reporting system. The vulnerability is unlikely to be exploited because the system is reachable only from a segmented admin network, and no sensitive data is stored there. The owner wants to postpone remediation until the next planned upgrade window. Which risk treatment is being chosen?

⚠ Common exam trap

The SY0-701 exam often tests the distinction between risk acceptance and risk avoidance, where candidates mistakenly think postponing remediation equals avoidance rather than a conscious decision to live with the risk temporarily.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Risk acceptance, because the business is choosing to live with the remaining risk for now.

Risk acceptance is the deliberate decision to acknowledge and tolerate a risk without immediate remediation. In this scenario, the business owner understands the vulnerability is low-likelihood (segmented admin network, no sensitive data) and chooses to postpone fixing it until the next planned upgrade, thereby accepting the residual risk for that period.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Risk avoidance, because the system will be upgraded later.

    Why it's wrong here

    Risk avoidance means eliminating the exposure entirely, such as decommissioning the vulnerable system or not implementing the feature at all. Merely planning a future upgrade does not remove the risk from the present environment; the business is still operating with the vulnerability in the meantime. Delaying remediation while continuing to use the system constitutes acceptance of the current residual risk, not avoidance.

  • Risk acceptance, because the business is choosing to live with the remaining risk for now.

    Why this is correct

    Risk acceptance is a formal treatment decision in which leadership acknowledges the residual risk and chooses to tolerate it without implementing additional controls at this time. When a business knowingly proceeds with a medium risk because a planned upgrade will later address the vulnerability, it is actively accepting the current level of risk. This decision should be documented in the risk register, assigned to a risk owner, and revisited when the upgrade is delivered.

  • Risk transfer, because the upgrade window shifts responsibility to the vendor.

    Why it's wrong here

    Risk transfer shifts the financial consequence of a risk to another party through mechanisms like insurance policies, indemnification clauses, or outsourced security services. Deferring remediation until an upgrade window does not transfer the current vulnerability's liability to the vendor; the business remains responsible for any exploit that occurs before the upgrade. Unless a contract explicitly makes the vendor liable for pre-upgrade incidents, the risk is still owned and accepted by the organization.

  • Risk escalation, because the issue is being sent to the help desk for tracking.

    Why it's wrong here

    In security risk management, escalation is a reporting and communication process used to notify higher management or a response team about a significant issue, not one of the four primary risk treatment strategies. Assigning a tracking ticket to the help desk is an operational action that does not resolve, transfer, or formally accept the underlying risk. Escalation is often driven by policy, but it neither constitutes a treatment decision nor changes the residual risk level.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.