SY0-701 Security Program Management and Oversight Practice Question
A legacy production scanner cannot support MFA, but it must remain available for six months until replacement hardware arrives. What is the best security response?
⚠ Common exam trap
Many exam-takers choose Option C (immediate shutdown) thinking it is the only secure choice, but the question explicitly states the scanner must remain available, making a risk-accepted, time-bound exception with compensating controls the correct security program management response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approve a time-bound exception with compensating controls and a review date.
It balances security with operational necessity by implementing a time-bound exception with compensating controls (e.g., network segmentation, strict access logging, or IP whitelisting) and a mandatory review date. This ensures the legacy scanner remains available for six months while mitigating the risk of unauthorized access, aligning with the principle of least privilege and security program oversight.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Permanently waive MFA for the scanner and leave the exception open-ended.
Why it's wrong here
A permanent MFA waiver turns a temporary risk acceptance into a standing vulnerability that persists indefinitely. Without an expiration or review date, there is no formal trigger to reassess the risk or require remediation, and any compromise of the scanner's credentials would bypass the intended identity verification layer indefinitely. Security governance best practice, as reflected in exception-management processes, requires that waivers are time-limited, documented, and paired with compensating controls so the risk is actively owned rather than silently accepted.
- ✓
Approve a time-bound exception with compensating controls and a review date.
Why this is correct
A time-bound exception allows the business to keep operating while security reduces risk through other controls such as network restriction, monitoring, or limited access. Adding a review date keeps the exception temporary and accountable, which is the best governance practice.
- ✗
Shut down the scanner immediately until MFA can be enabled.
Why it's wrong here
Immediately shutting down the scanner eliminates the MFA risk but at the cost of operational continuity, which may not be proportionate for a legacy production device the business depends on. A more balanced response is to isolate the scanner on a restricted network segment, apply host-based firewall rules, and enable logging/monitoring while a technical solution (such as an authentication proxy or token-based access) is implemented. Abruptly halting production without a transition plan also fails to consider the organization's risk appetite and the availability requirements of downstream processes.
- ✗
Create a shared administrator account so operators can sign in more easily.
Why it's wrong here
Creating a shared administrator account does not solve the MFA limitation because the shared credential is still protected only by a password, and it actually undermines non-repudiation by making it impossible to attribute actions to a specific operator. If the shared password is exposed, the entire scanner's administrative access is compromised, and audit trails become meaningless because multiple people use the same identity. This approach violates separation of duties and least privilege, and it is explicitly discouraged by security frameworks that require individual accountability for privileged access.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.