Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A business unit is worried about the financial impact of a rare but severe data center outage. After reviewing the risk register, leadership decides to purchase cyber insurance and document the remaining exposure rather than redesign the entire platform. Which risk treatment is this?

⚠ Common exam trap

Test-takers frequently confuse risk transfer (shifting financial liability) with risk mitigation (reducing probability/impact via technical controls), especially when the scenario mentions 'documenting the remaining exposure'—which is a hallmark of risk acceptance, not mitigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Risk transfer

(Risk transfer) because purchasing cyber insurance transfers the financial risk of a data center outage to an insurance provider. The business unit is not avoiding the risk by redesigning the platform, nor are they mitigating it through technical controls; they are simply documenting the residual exposure after transferring the monetary impact. This aligns with the risk treatment strategy of shifting the burden of loss to a third party.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Risk transfer

    Why this is correct

    Risk transfer is the correct classification because purchasing an insurance policy shifts the financial consequences of a rare, disruptive event to an external insurer in exchange for a fixed premium. This does not eliminate the operational risk or reduce the probability of the event; it only ensures that the monetary loss is compensated by a third party. This strategy is ideal for low-probability, high-impact risks where the financial loss could otherwise threaten the business unit's viability.

  • Risk avoidance

    Why it's wrong here

    Risk avoidance is incorrect because it would require the business unit to eliminate the risky activity or system altogether, such as discontinuing the product, withdrawing from the market, or abandoning the asset that creates the exposure. In the scenario, the business unit is continuing its operations unchanged and is simply purchasing insurance, which does not remove the underlying risk. Avoidance is the only strategy that guarantees zero risk, but it also forgoes the benefits of the activity, so it does not match the described decision.

  • Risk mitigation

    Why it's wrong here

    Risk mitigation is not the right label because it involves implementing controls—like technical safeguards, procedural changes, or physical barriers—to reduce the likelihood or impact of an adverse event. Purchasing insurance does not alter the probability of the event occurring nor does it lessen the severity of the damage; it only provides post-event financial reimbursement. In contrast, true mitigation would be something like installing fire suppression systems or redundant power supplies; therefore, insurance is not a mitigation measure.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance is not the strategy being used, since the business unit is actively taking steps to transfer financial exposure to a third party rather than bearing it internally. Acceptance would mean consciously acknowledging the risk, making a deliberate decision to absorb any potential loss, and possibly setting aside contingency reserves. By paying a premium to an insurer, the business unit is clearly moving the financial risk off its balance sheet, which is the opposite of acceptance.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.