SY0-701 Security Program Management and Oversight Practice Question
A project team identifies a new risk with a high likelihood of minor data exposure during a pilot rollout. The impact is low, but the issue would become harder to address after production launch. The business owner wants the project to proceed. What should the risk owner do NEXT?
⚠ Common exam trap
Test-takers frequently assume low impact means the risk can be ignored or deferred, but the high likelihood and the worsening condition post-launch force a formal risk response before proceeding, not after.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the risk, assign an owner, and escalate for acceptance or treatment before launch.
The risk owner must follow the formal risk management process: document the risk, assign an owner, and escalate it to the business owner for a decision on acceptance or treatment before the pilot launch. Even though the impact is low, the high likelihood and the fact that the issue becomes harder to address post-production mean the risk cannot be ignored or deferred; it requires a documented acceptance or a mitigation plan before proceeding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the issue because the impact is low.
Why it's wrong here
A low impact does not make the risk acceptable; the high likelihood creates a meaningful expected loss (likelihood × impact) that must be formally assessed. Ignoring the issue violates risk register discipline and leaves management uninformed, especially since likelihood can also change as the system expands. Even if the impact is modest, recording and evaluating the risk is mandatory for defensible security decisions.
- ✓
Document the risk, assign an owner, and escalate for acceptance or treatment before launch.
Why this is correct
This is the best next step because the risk is both identified and still manageable during the pilot. Recording it in the risk register, assigning accountability, and escalating it for acceptance or treatment ensures management makes an informed decision. Since the issue will be harder to fix after production launch, early action is important. This is classic risk governance: identify, document, assign, and decide before exposure expands.
- ✗
Wait until after production launch to see whether the issue actually occurs.
Why it's wrong here
Waiting until after production launch deliberately extends the exposure window and enlarges the blast radius: more users, more data, and dependency chains that make fixes costlier and subject to stricter change control. If the issue triggers during production, the organization faces incident response, potential downtime, and regulatory consequences rather than a controlled pilot adjustment. The pilot exists to uncover and address such risks before launch, so postponing treatment is a reactive, non-governance approach.
- ✗
Transfer the risk by moving the pilot to a different business unit.
Why it's wrong here
Moving the pilot to another business unit does not transfer risk in the professional sense—it merely changes the organizational owner while the same threat and vulnerability persist. True risk transfer requires an external party to assume financial liability, typically through insurance, contractual indemnification, or outsourcing with enforceable service-level agreements. Without that, the enterprise risk profile is unchanged, and the receiving unit is exposed to precisely the same technical and operational impact.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.