Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A business wants to keep operating even if a supplier-related loss occurs, so it purchases cyber insurance to offset possible costs. Which risk treatment is being used?

⚠ Common exam trap

Test-takers frequently confuse risk transfer (shifting financial impact) with risk mitigation (reducing likelihood or impact), leading candidates to incorrectly select mitigation when insurance is involved.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Transfer, because some financial impact is shifted to another party

Purchasing cyber insurance transfers the financial risk of a supplier-related loss to the insurance company. This is a classic risk transfer strategy, where the business does not eliminate or reduce the likelihood of the loss but shifts the financial impact to another party via a contractual agreement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Avoidance, because the company is eliminating the supplier relationship

    Why it's wrong here

    Avoidance would require the business to eliminate the exposure entirely, such as terminating the supplier relationship or discontinuing the dependent process. Here the supplier relationship may continue and operations proceed; the company simply purchases insurance to cover potential losses. Therefore, this is not avoidance, because the risky activity is still being performed.

  • Mitigation, because insurance removes the risk before it happens

    Why it's wrong here

    Mitigation reduces the likelihood or impact of an event through safeguards or controls, such as backup suppliers or quality inspections. Insurance does not remove or reduce the risk itself; it only provides financial compensation after a loss occurs. The incident can still happen, and the company still suffers operational disruption, so treating insurance as mitigation mischaracterizes the control.

  • Acceptance, because the company is doing nothing about the exposure

    Why it's wrong here

    Acceptance is a deliberate decision to retain the risk and absorb any losses with no active risk treatment or transfer, often because the potential impact is low. By purchasing insurance, the company is taking a defined action to shift a portion of the financial exposure to a third party, which is the opposite of passively accepting the risk. Thus, acceptance does not apply.

  • Transfer, because some financial impact is shifted to another party

    Why this is correct

    This is a textbook risk transfer: the business keeps the supplier and the process but shifts the financial consequences of certain losses to the insurance company via premium payments. The underlying risk (e.g., supplier failure) still exists, but the monetary impact is substantially borne by the insurer, subject to policy terms. Transfer best describes this balance of retaining operational activity while offloading financial risk.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.