Courseiva
Security Program Management and OversighteasyMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A manager asks how to decide whether a new security issue is worth spending money on. Which two factors should be reviewed first? Select two.

⚠ Common exam trap

Test-takers frequently confuse severity indicators (like color-coded CVSS scores) with the primary decision factors, or they may incorrectly assume that administrative metrics (like user count or asset age) are relevant to risk-based spending decisions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Likelihood that the issue will be exploited

The likelihood of exploitation is a fundamental factor in risk assessment. Without understanding how probable it is that a threat actor will exploit a vulnerability, an organization cannot prioritize remediation efforts effectively. This is a core component of risk calculation (Risk = Likelihood × Impact).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Likelihood that the issue will be exploited

    Why this is correct

    Likelihood of exploitation is a core factor in risk calculation: it reflects the probability that an attacker will successfully leverage the vulnerability in the current threat environment. Analysts evaluate real-world exploit availability, ease of exploitation, and the exposure of the affected asset to potential threat actors. A high likelihood means the organization faces a realistic and imminent threat, which directly drives prioritization.

  • Business impact if the issue is successful

    Why this is correct

    Business impact quantifies the potential damage if the issue is successfully exploited, including loss of confidentiality, integrity, or availability, as well as financial, reputational, and regulatory consequences. It requires analyzing the criticality of the affected system and the sensitivity of data it processes. A vulnerability that could disrupt revenue-generating services or expose protected data has high impact, making it a priority even if the likelihood is moderate.

  • The color used on the vulnerability report

    Why it's wrong here

    The color assigned to a vulnerability on a report, such as red, orange, or yellow, is typically a visualization of a numeric severity score, not a direct measure of business risk. These colors often reflect the vendor's base severity rating, which ignores the organization's specific threat landscape and asset value. Relying on colors alone can lead to misprioritization, because they do not combine likelihood and actual business impact.

  • The number of users in the IT department

    Why it's wrong here

    The number of users in the IT department describes staffing capacity and is unrelated to the probability or consequence of a specific security issue. Whether a team has two or twenty members does not change the exploitability of a vulnerability or the potential damage to an asset. Staffing levels may affect how quickly a response can occur, but they should never be a factor in initial risk prioritization because they measure resources, not risk.

  • The age of the server name in inventory

    Why it's wrong here

    The age of a server name in inventory, such as when it was added to the asset management system, is metadata that does not indicate the vulnerability's exploitability or potential severity. While an older machine might predate security hardening, correlation does not provide a decision-quality measure of risk. Prioritization should rely on exposure, criticality, and known exploit likelihood, not arbitrary naming or inventory timestamps.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.