Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A legacy production scanner cannot support MFA, but it must remain available for six months until replacement hardware arrives. What is the best security response?

⚠ Common exam trap

Many exam-takers choose Option C (immediate shutdown) thinking it is the only secure choice, but the question explicitly states the scanner must remain available, making a risk-accepted, time-bound exception with compensating controls the correct security program management response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Approve a time-bound exception with compensating controls and a review date.

It balances security with operational necessity by implementing a time-bound exception with compensating controls (e.g., network segmentation, strict access logging, or IP whitelisting) and a mandatory review date. This ensures the legacy scanner remains available for six months while mitigating the risk of unauthorized access, aligning with the principle of least privilege and security program oversight.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Permanently waive MFA for the scanner and leave the exception open-ended.

    Why it's wrong here

    A permanent MFA waiver turns a temporary risk acceptance into a standing vulnerability that persists indefinitely. Without an expiration or review date, there is no formal trigger to reassess the risk or require remediation, and any compromise of the scanner's credentials would bypass the intended identity verification layer indefinitely. Security governance best practice, as reflected in exception-management processes, requires that waivers are time-limited, documented, and paired with compensating controls so the risk is actively owned rather than silently accepted.

  • Approve a time-bound exception with compensating controls and a review date.

    Why this is correct

    A time-bound exception allows the business to keep operating while security reduces risk through other controls such as network restriction, monitoring, or limited access. Adding a review date keeps the exception temporary and accountable, which is the best governance practice.

  • Shut down the scanner immediately until MFA can be enabled.

    Why it's wrong here

    Immediately shutting down the scanner eliminates the MFA risk but at the cost of operational continuity, which may not be proportionate for a legacy production device the business depends on. A more balanced response is to isolate the scanner on a restricted network segment, apply host-based firewall rules, and enable logging/monitoring while a technical solution (such as an authentication proxy or token-based access) is implemented. Abruptly halting production without a transition plan also fails to consider the organization's risk appetite and the availability requirements of downstream processes.

  • Create a shared administrator account so operators can sign in more easily.

    Why it's wrong here

    Creating a shared administrator account does not solve the MFA limitation because the shared credential is still protected only by a password, and it actually undermines non-repudiation by making it impossible to attribute actions to a specific operator. If the shared password is exposed, the entire scanner's administrative access is compromised, and audit trails become meaningless because multiple people use the same identity. This approach violates separation of duties and least privilege, and it is explicitly discouraged by security frameworks that require individual accountability for privileged access.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.