SY0-701 Security Program Management and Oversight Practice Question
A department identifies a low-likelihood software risk that would be expensive to fix right now. Leadership decides the business can live with the exposure for now, but wants it documented and reviewed later. What risk treatment is this?
⚠ Common exam trap
It's easy for candidates to confuse risk acceptance with risk mitigation, thinking that documenting a risk means a control is applied, but acceptance explicitly means no control is implemented and the exposure is tolerated with formal sign-off.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept the risk with documented approval and periodic review
The scenario describes a low-likelihood, high-cost software risk that leadership chooses to tolerate rather than fix immediately. This is the definition of risk acceptance, which requires documented approval and periodic review to ensure the risk remains acceptable over time. The correct risk treatment is to formally accept the exposure with a record of the decision and a schedule for reassessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Mitigate the risk by applying a technical control immediately
Why it's wrong here
Mitigation seeks to reduce a risk's likelihood or impact by applying a technical control, which is designed for risks the organization has decided to actively remediate. In this scenario, the department has already judged the software risk to be low likelihood and has chosen not to fix it now, so an immediate technical control would be disproportionate, consume resources, and contradict the leadership's deliberate decision to defer action. The appropriate response under these conditions is not to deploy a control but to formally accept the situation while tracking it.
- ✓
Accept the risk with documented approval and periodic review
Why this is correct
Acceptance is a formal risk response in which the risk owner acknowledges the residual risk and documents the decision to tolerate it, often with a justification such as low likelihood and minimal impact. In this case, because the business has decided not to fix the issue now, the correct step is to record that approval and schedule periodic reviews to ensure the risk remains within the organization's risk appetite. This differs from ignoring the risk; it requires ongoing monitoring and reassessment to detect when the risk level changes and the cost of mitigation eventually becomes justified.
- ✗
Transfer the risk to an insurer or third party
Why it's wrong here
Transference shifts the financial burden of a risk to a third party, typically through insurance or contractual clauses, but it does not reduce the underlying software vulnerability or remove the organization's responsibility for the system's operation. The scenario explicitly says the business is keeping the risk internally and will review it later, so there is no indication that an insurer has been engaged or that transfer would address the root cause or the acceptance decision. Additionally, low-likelihood software risks are often excluded from standard policies or carry premiums that exceed the expected loss, making transfer economically unattractive.
- ✗
Avoid the risk by stopping the business activity entirely
Why it's wrong here
Avoidance is the most drastic risk response because it eliminates the risk entirely by discontinuing the business activity, process, or system that produces it, rather than managing the probability or impact afterward. Here, the scenario describes only a low likelihood software risk that the business has decided not to fix now, so ceasing operations would introduce far greater disruption, lost productivity, and cost than the risk itself. Avoidance should be reserved for high-impact, unacceptable risks that cannot be otherwise controlled, not for a residual risk that the organization is willing to tolerate and monitor.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Risk acceptance
Risk acceptance is a risk management strategy where an organization acknowledges a potential risk but decides to tolerate it without taking active measures to reduce or eliminate it.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.