SY0-701 Security Program Management and Oversight Practice Question
A manufacturing company must keep a legacy scheduling application running for 60 days while replacement testing finishes. The application supports production orders, and the business cannot tolerate a shutdown. Which three conditions should be required before approving the temporary exception? Select three.
⚠ Common exam trap
The trap here is that candidates might think only one or two of these conditions are needed, but the SY0-701 exam expects all three—risk owner, expiration/review, and compensating controls—to be present for a valid risk exception.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign a named risk owner who is authorized to accept the residual risk.
Assigning a named risk owner who is authorized to accept residual risk is a fundamental requirement for any risk exception. This ensures accountability and that a specific individual with the authority to accept the potential consequences of running an unsupported system is identified. Without a designated owner, the exception lacks governance and could lead to unmanaged exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign a named risk owner who is authorized to accept the residual risk.
Why this is correct
Assigning a named risk owner who is authorized to accept the residual risk is essential because it formalizes accountability. Only a business owner with the proper authority can consciously accept the remaining exposure after implementing mitigations, ensuring the decision is documented, understood, and aligned with the organization's risk appetite. Without this explicit acceptance, the residual risk is left unowned, potentially leading to oversight or unintended assumptions of liability.
- ✓
Set a clear expiration date and mandatory review point before renewal.
Why this is correct
Setting a clear expiration date and mandatory review point ensures the temporary exception does not silently become a permanent state. Time-boxing the waiver forces the organization to re-evaluate the risk, the effectiveness of any safeguards, and the progress toward a permanent solution at a defined future date. This review discipline keeps the exception active only as long as necessary and prevents the organization from growing complacent about a known risk.
- ✓
Implement a compensating control such as network restriction or added monitoring.
Why this is correct
Implementing a compensating control, such as a network restriction or added monitoring, reduces the likelihood or impact of a threat while the legacy scheduling system is still in use. Compensating controls are a critical component of an exception request because they demonstrate that the residual risk is being actively managed and that the organization is not simply accepting an unmitigated vulnerability. This approach aligns with industry frameworks that require security measures to be comparable to the intended control.
- ✗
Rely on the vendor's promise that a better version will be available eventually.
Why it's wrong here
Relying on the vendor's promise that a better version will be available eventually is flawed because a promise is not a current, actionable control that reduces exposure. It does not lower the probability of exploitation, nor does it provide a formal, documented exception that can be tracked and reviewed. An unenforceable future commitment offers no assurance to the organization and fails to satisfy the requirement of a risk acceptance decision based on present facts.
- ✗
Approve an unlimited waiver so operations do not need to revisit the issue.
Why it's wrong here
Approving an unlimited waiver removes the review discipline needed to reassess the risk as the threat landscape evolves. Without a defined end date or a scheduled review, the organization becomes permanently exposed to a known vulnerability, and the waiver itself may be forgotten, leaving no mechanism to revisit the decision or implement a permanent fix. This practice contradicts risk management principles that require periodic validation of exceptions and ensures risks are only accepted for a limited, justified period.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Residual risk
Residual risk is the level of risk that remains after all security controls and countermeasures have been applied.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.