Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A department identifies a low-likelihood software risk that would be expensive to fix right now. Leadership decides the business can live with the exposure for now, but wants it documented and reviewed later. What risk treatment is this?

⚠ Common exam trap

It's easy for candidates to confuse risk acceptance with risk mitigation, thinking that documenting a risk means a control is applied, but acceptance explicitly means no control is implemented and the exposure is tolerated with formal sign-off.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Accept the risk with documented approval and periodic review

The scenario describes a low-likelihood, high-cost software risk that leadership chooses to tolerate rather than fix immediately. This is the definition of risk acceptance, which requires documented approval and periodic review to ensure the risk remains acceptable over time. The correct risk treatment is to formally accept the exposure with a record of the decision and a schedule for reassessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mitigate the risk by applying a technical control immediately

    Why it's wrong here

    Mitigation seeks to reduce a risk's likelihood or impact by applying a technical control, which is designed for risks the organization has decided to actively remediate. In this scenario, the department has already judged the software risk to be low likelihood and has chosen not to fix it now, so an immediate technical control would be disproportionate, consume resources, and contradict the leadership's deliberate decision to defer action. The appropriate response under these conditions is not to deploy a control but to formally accept the situation while tracking it.

  • Accept the risk with documented approval and periodic review

    Why this is correct

    Acceptance is a formal risk response in which the risk owner acknowledges the residual risk and documents the decision to tolerate it, often with a justification such as low likelihood and minimal impact. In this case, because the business has decided not to fix the issue now, the correct step is to record that approval and schedule periodic reviews to ensure the risk remains within the organization's risk appetite. This differs from ignoring the risk; it requires ongoing monitoring and reassessment to detect when the risk level changes and the cost of mitigation eventually becomes justified.

  • Transfer the risk to an insurer or third party

    Why it's wrong here

    Transference shifts the financial burden of a risk to a third party, typically through insurance or contractual clauses, but it does not reduce the underlying software vulnerability or remove the organization's responsibility for the system's operation. The scenario explicitly says the business is keeping the risk internally and will review it later, so there is no indication that an insurer has been engaged or that transfer would address the root cause or the acceptance decision. Additionally, low-likelihood software risks are often excluded from standard policies or carry premiums that exceed the expected loss, making transfer economically unattractive.

  • Avoid the risk by stopping the business activity entirely

    Why it's wrong here

    Avoidance is the most drastic risk response because it eliminates the risk entirely by discontinuing the business activity, process, or system that produces it, rather than managing the probability or impact afterward. Here, the scenario describes only a low likelihood software risk that the business has decided not to fix now, so ceasing operations would introduce far greater disruption, lost productivity, and cost than the risk itself. Avoidance should be reserved for high-impact, unacceptable risks that cannot be otherwise controlled, not for a residual risk that the organization is willing to tolerate and monitor.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.