SY0-701 Risk Mitigation Practice Question
A business unit keeps a low-priority legacy tool but adds extra monitoring and patching. The company also buys cyber insurance to reduce the financial effect of a loss. Which two risk treatment strategies are being used? Select two.
⚠ Common exam trap
Candidates often confuse risk acceptance (keeping the asset without additional controls) with risk mitigation (adding controls), or they may fail to recognize that cyber insurance is a transference strategy, not mitigation or acceptance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigation
Mitigation (B) is correct because the business unit keeps the legacy tool but reduces its risk exposure by adding extra monitoring and patching, which are compensating controls that lower the likelihood or impact of a loss. Transfer (D) is correct because purchasing cyber insurance shifts the financial consequences of a potential loss to the insurer, which is the defining characteristic of risk transfer. Acceptance (A) does not apply because the organization is actively applying controls rather than simply acknowledging and retaining the risk without action. Avoidance (C) does not apply because the legacy tool is still kept in use rather than being eliminated or discontinued. Deterrent (E) is not a distinct risk treatment strategy here; monitoring and patching are preventive/detective controls supporting mitigation, not a separate deterrent strategy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Acceptance
Why it's wrong here
Acceptance means taking no action to reduce likelihood or impact, yet the unit adds monitoring and patching, which are mitigation activities. Insurance transfers residual financial loss. Acceptance would be correct only if the tool were left unmodified and unmonitored.
- ✓
Mitigation
Why this is correct
Mitigation reduces risk likelihood or impact through added controls, so extra monitoring and patching lower the legacy tool's exposure while the business unit retains it. This matches the stem's first treatment, distinct from the insurance-based transfer applied to financial loss.
- ✗
Avoidance
Why it's wrong here
Avoidance eliminates the risk by discontinuing the activity or system entirely. This business unit retains the low-priority legacy tool, so the risk is accepted and reduced through monitoring, patching and insurance rather than avoided. Avoidance would be correct only if the tool were decommissioned and its function dropped.
- ✓
Transfer
Why this is correct
Transfer shifts the financial consequence of a risk to a third party, which cyber insurance accomplishes by covering losses in exchange for premiums. This addresses the stem's second treatment, complementing the mitigation applied to the retained legacy tool.
- ✗
Deterrent
Why it's wrong here
Deterrent measures discourage an attacker from acting at all, such as warning banners or visible cameras. Here the business accepts the legacy tool and reduces impact through monitoring, patching and insurance, which are mitigation and transference, not deterrence. Deterrence would be correct if the goal were to stop intrusion attempts before they begin.
Go deeper
Related to this question
Learn chapter
Business Impact Analysis (BIA)
Key term
Risk transfer
Risk transfer is the practice of shifting the financial burden of a potential loss to another party, typically through insurance or contracts.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.