SY0-701 Security Program Management and Oversight Practice Question
A business unit is worried about the financial impact of a rare but severe data center outage. After reviewing the risk register, leadership decides to purchase cyber insurance and document the remaining exposure rather than redesign the entire platform. Which risk treatment is this?
⚠ Common exam trap
Test-takers frequently confuse risk transfer (shifting financial liability) with risk mitigation (reducing probability/impact via technical controls), especially when the scenario mentions 'documenting the remaining exposure'—which is a hallmark of risk acceptance, not mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk transfer
(Risk transfer) because purchasing cyber insurance transfers the financial risk of a data center outage to an insurance provider. The business unit is not avoiding the risk by redesigning the platform, nor are they mitigating it through technical controls; they are simply documenting the residual exposure after transferring the monetary impact. This aligns with the risk treatment strategy of shifting the burden of loss to a third party.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk transfer
Why this is correct
Risk transfer is the correct classification because purchasing an insurance policy shifts the financial consequences of a rare, disruptive event to an external insurer in exchange for a fixed premium. This does not eliminate the operational risk or reduce the probability of the event; it only ensures that the monetary loss is compensated by a third party. This strategy is ideal for low-probability, high-impact risks where the financial loss could otherwise threaten the business unit's viability.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance is incorrect because it would require the business unit to eliminate the risky activity or system altogether, such as discontinuing the product, withdrawing from the market, or abandoning the asset that creates the exposure. In the scenario, the business unit is continuing its operations unchanged and is simply purchasing insurance, which does not remove the underlying risk. Avoidance is the only strategy that guarantees zero risk, but it also forgoes the benefits of the activity, so it does not match the described decision.
- ✗
Risk mitigation
Why it's wrong here
Risk mitigation is not the right label because it involves implementing controls—like technical safeguards, procedural changes, or physical barriers—to reduce the likelihood or impact of an adverse event. Purchasing insurance does not alter the probability of the event occurring nor does it lessen the severity of the damage; it only provides post-event financial reimbursement. In contrast, true mitigation would be something like installing fire suppression systems or redundant power supplies; therefore, insurance is not a mitigation measure.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is not the strategy being used, since the business unit is actively taking steps to transfer financial exposure to a third party rather than bearing it internally. Acceptance would mean consciously acknowledging the risk, making a deliberate decision to absorb any potential loss, and possibly setting aside contingency reserves. By paying a premium to an insurer, the business unit is clearly moving the financial risk off its balance sheet, which is the opposite of acceptance.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Risk transfer
Risk transfer is the practice of shifting the financial burden of a potential loss to another party, typically through insurance or contracts.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.