Question 512 of 1,013
SY0-701 Security Program Management and Oversight Practice Question
A finance application has a known vulnerability in a third-party reporting component. The vendor says a patch will not be available for six months, but the business cannot stop using the application. What is the BEST risk treatment for the organization to pursue next?
⚠ Common exam trap
A common mix-up: candidates confuse 'accepting risk' with 'doing nothing,' but in CompTIA's framework, risk acceptance requires a formal decision by management after evaluating the risk level, not an automatic deferral due to a delayed patch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate the risk by adding compensating controls and tracking residual risk until the patch is available.
When a known vulnerability exists in a third-party component and patching is delayed, the best risk treatment is to implement compensating controls (such as network segmentation, WAF rules, or input validation) to reduce the likelihood or impact of exploitation. This approach allows the business to continue operations while actively tracking residual risk until the vendor releases the patch. It aligns with the NIST risk management framework, which prioritizes mitigation when avoidance is not feasible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid the risk by shutting down the finance application immediately.
Why it's wrong here
Avoidance would eliminate the vulnerability's exposure by taking the application offline, but that action would also halt a critical business service that the organization has determined must remain available for the next six months. In this scenario, the availability impact of a shutdown exceeds the security impact of the known vulnerability. Compensating controls are preferable because they preserve the service while actively reducing the likelihood or blast radius of an exploit.
- ✓
Mitigate the risk by adding compensating controls and tracking residual risk until the patch is available.
Why this is correct
This approach reduces the likelihood or impact of exploitation while keeping the business service running. Compensating controls such as increased monitoring, segmentation, additional access restrictions, and temporary workarounds are appropriate when a patch is unavailable. The organization can then document the remaining risk, assign an owner, and revisit the issue when the vendor releases the fix.
- ✗
Transfer the risk by asking the vendor to guarantee that no incident will occur.
Why it's wrong here
Risk transfer does not mean obtaining a promise of perfect security; it typically shifts the financial impact of a loss to an insurer or a vendor through a contract, yet the actual technical vulnerability remains exploitable. A vendor guarantee cannot prevent an attack or protect the finance application's data, and no vendor will accept unlimited liability. Furthermore, the organization retains responsibility for safeguarding its own assets, so this proposed 'transfer' is neither practical nor effective as a risk treatment.
- ✗
Accept the risk because any delay in patching is automatically low priority.
Why it's wrong here
Risk acceptance is a formal decision made only after a thorough assessment shows that the residual risk is within the organization's risk appetite, and it must be documented and approved by management. A known vulnerability in a finance application directly affects confidentiality and integrity, so classifying it as automatically low priority just because the patch is delayed is unsound. Without compensating controls or a risk-based justification, unwarranted acceptance leaves the organization exposed to potential financial fraud or data loss, violating security governance principles.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.