Courseiva

SY0-701 Risk Mitigation Practice Question

A business unit keeps a low-priority legacy tool but adds extra monitoring and patching. The company also buys cyber insurance to reduce the financial effect of a loss. Which two risk treatment strategies are being used? Select two.

⚠ Common exam trap

Candidates often confuse risk acceptance (keeping the asset without additional controls) with risk mitigation (adding controls), or they may fail to recognize that cyber insurance is a transference strategy, not mitigation or acceptance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mitigation

Mitigation (B) is correct because the business unit keeps the legacy tool but reduces its risk exposure by adding extra monitoring and patching, which are compensating controls that lower the likelihood or impact of a loss. Transfer (D) is correct because purchasing cyber insurance shifts the financial consequences of a potential loss to the insurer, which is the defining characteristic of risk transfer. Acceptance (A) does not apply because the organization is actively applying controls rather than simply acknowledging and retaining the risk without action. Avoidance (C) does not apply because the legacy tool is still kept in use rather than being eliminated or discontinued. Deterrent (E) is not a distinct risk treatment strategy here; monitoring and patching are preventive/detective controls supporting mitigation, not a separate deterrent strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Acceptance

    Why it's wrong here

    Acceptance means taking no action to reduce likelihood or impact, yet the unit adds monitoring and patching, which are mitigation activities. Insurance transfers residual financial loss. Acceptance would be correct only if the tool were left unmodified and unmonitored.

  • ✓

    Mitigation

    Why this is correct

    Mitigation reduces risk likelihood or impact through added controls, so extra monitoring and patching lower the legacy tool's exposure while the business unit retains it. This matches the stem's first treatment, distinct from the insurance-based transfer applied to financial loss.

  • ✗

    Avoidance

    Why it's wrong here

    Avoidance eliminates the risk by discontinuing the activity or system entirely. This business unit retains the low-priority legacy tool, so the risk is accepted and reduced through monitoring, patching and insurance rather than avoided. Avoidance would be correct only if the tool were decommissioned and its function dropped.

  • ✓

    Transfer

    Why this is correct

    Transfer shifts the financial consequence of a risk to a third party, which cyber insurance accomplishes by covering losses in exchange for premiums. This addresses the stem's second treatment, complementing the mitigation applied to the retained legacy tool.

  • ✗

    Deterrent

    Why it's wrong here

    Deterrent measures discourage an attacker from acting at all, such as warning banners or visible cameras. Here the business accepts the legacy tool and reduces impact through monitoring, patching and insurance, which are mitigation and transference, not deterrence. Deterrence would be correct if the goal were to stop intrusion attempts before they begin.

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.