SY0-701 Security Program Management and Oversight Practice Question
A business owner asks whether to proceed with a medium-risk issue on an internal reporting system. The vulnerability is unlikely to be exploited because the system is reachable only from a segmented admin network, and no sensitive data is stored there. The owner wants to postpone remediation until the next planned upgrade window. Which risk treatment is being chosen?
⚠ Common exam trap
The SY0-701 exam often tests the distinction between risk acceptance and risk avoidance, where candidates mistakenly think postponing remediation equals avoidance rather than a conscious decision to live with the risk temporarily.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance, because the business is choosing to live with the remaining risk for now.
Risk acceptance is the deliberate decision to acknowledge and tolerate a risk without immediate remediation. In this scenario, the business owner understands the vulnerability is low-likelihood (segmented admin network, no sensitive data) and chooses to postpone fixing it until the next planned upgrade, thereby accepting the residual risk for that period.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk avoidance, because the system will be upgraded later.
Why it's wrong here
Risk avoidance means eliminating the exposure entirely, such as decommissioning the vulnerable system or not implementing the feature at all. Merely planning a future upgrade does not remove the risk from the present environment; the business is still operating with the vulnerability in the meantime. Delaying remediation while continuing to use the system constitutes acceptance of the current residual risk, not avoidance.
- ✓
Risk acceptance, because the business is choosing to live with the remaining risk for now.
Why this is correct
Risk acceptance is a formal treatment decision in which leadership acknowledges the residual risk and chooses to tolerate it without implementing additional controls at this time. When a business knowingly proceeds with a medium risk because a planned upgrade will later address the vulnerability, it is actively accepting the current level of risk. This decision should be documented in the risk register, assigned to a risk owner, and revisited when the upgrade is delivered.
- ✗
Risk transfer, because the upgrade window shifts responsibility to the vendor.
Why it's wrong here
Risk transfer shifts the financial consequence of a risk to another party through mechanisms like insurance policies, indemnification clauses, or outsourced security services. Deferring remediation until an upgrade window does not transfer the current vulnerability's liability to the vendor; the business remains responsible for any exploit that occurs before the upgrade. Unless a contract explicitly makes the vendor liable for pre-upgrade incidents, the risk is still owned and accepted by the organization.
- ✗
Risk escalation, because the issue is being sent to the help desk for tracking.
Why it's wrong here
In security risk management, escalation is a reporting and communication process used to notify higher management or a response team about a significant issue, not one of the four primary risk treatment strategies. Assigning a tracking ticket to the help desk is an operational action that does not resolve, transfer, or formally accept the underlying risk. Escalation is often driven by policy, but it neither constitutes a treatment decision nor changes the residual risk level.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Residual risk
Residual risk is the level of risk that remains after all security controls and countermeasures have been applied.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.