SY0-701 Security Program Management and Oversight Practice Question
A business unit asks for a 30-day exception to use an unsupported browser plug-in on two engineering workstations while a replacement is tested. Which three conditions should be required before approval? Select three.
⚠ Common exam trap
The trap here is that candidates might think only one or two conditions are sufficient, but CompTIA expects all three—justification, expiration, and compensating controls—to be required for a valid exception approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A documented business justification for why the plug-in is still needed.
A documented business justification ensures that the exception is necessary and aligns with organizational risk appetite. Without a clear reason, the exception could be granted for convenience rather than critical need, undermining security governance. This justification also provides an audit trail for why an unsupported, potentially vulnerable plug-in is still in use.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A documented business justification for why the plug-in is still needed.
Why this is correct
It demonstrates that the exception is not merely for convenience but addresses a genuine operational need, tying the risk acceptance to a specific business outcome. Without this, the exception lacks context for risk owners to evaluate whether the temporary risk is worth taking, and it fails the requirement for risk acceptance to be an informed decision. This documentation also provides the basis for the review at expiration, showing whether the need still exists.
- ✓
A defined expiration date and review point before the exception can be extended.
Why this is correct
Time-boxing the exception ensures it is treated as a temporary deviation from the security baseline rather than a permanent weakening of controls. A defined review point forces the team to re-evaluate the risk posture and the availability of alternatives, preventing the exception from silently persisting. This aligns with the principle that exceptions must be periodically revalidated and cannot be allowed to become de facto policy.
- ✓
A compensating control such as isolating the workstations from the general user network.
Why this is correct
Isolation of the workstations containing the unsupported plug-in from the general user network limits the exposure of other systems if the plug-in is exploited. This control reduces the attack surface and blast radius, making the operational risk more acceptable during the 30-day period. It also demonstrates that the business is actively mitigating the risk, not just accepting it blindly, which is a key requirement for a valid exception.
- ✗
An open-ended waiver so the team can continue if testing slips.
Why it's wrong here
An indefinite waiver defeats the purpose of a time-limited exception, as it removes the pressure to find a supported alternative and allows the risk to persist indefinitely. Without a forced end date, there is no accountability for the team to complete testing or migration, and the organization loses visibility into a prolonged exposure. This is a common pitfall that turns exceptions into permanent risk acceptance, which is not justifiable under standard risk management frameworks.
- ✗
Verbal approval only, with no written record.
Why it's wrong here
Verbal approval provides no evidence of the risk decision, making it impossible to audit the exception or hold anyone accountable if the risk materializes. Written approval creates a permanent record that can be reviewed by auditors, security teams, and future decision-makers, and it ensures the approver has formally acknowledged their responsibility. In practice, undocumented exceptions are often discovered after incidents, leading to confusion about who authorized the risk and why.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Audit trail
An audit trail is a chronological record of events, changes, or activities in a system that provides evidence of who did what, when, and from where.
Key term
Risk appetite
Risk appetite is the amount of risk an organization is willing to accept in pursuit of its objectives, defining the boundaries for decision-making.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.