Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A project team identifies a new risk with a high likelihood of minor data exposure during a pilot rollout. The impact is low, but the issue would become harder to address after production launch. The business owner wants the project to proceed. What should the risk owner do NEXT?

⚠ Common exam trap

Test-takers frequently assume low impact means the risk can be ignored or deferred, but the high likelihood and the worsening condition post-launch force a formal risk response before proceeding, not after.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document the risk, assign an owner, and escalate for acceptance or treatment before launch.

The risk owner must follow the formal risk management process: document the risk, assign an owner, and escalate it to the business owner for a decision on acceptance or treatment before the pilot launch. Even though the impact is low, the high likelihood and the fact that the issue becomes harder to address post-production mean the risk cannot be ignored or deferred; it requires a documented acceptance or a mitigation plan before proceeding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ignore the issue because the impact is low.

    Why it's wrong here

    A low impact does not make the risk acceptable; the high likelihood creates a meaningful expected loss (likelihood × impact) that must be formally assessed. Ignoring the issue violates risk register discipline and leaves management uninformed, especially since likelihood can also change as the system expands. Even if the impact is modest, recording and evaluating the risk is mandatory for defensible security decisions.

  • Document the risk, assign an owner, and escalate for acceptance or treatment before launch.

    Why this is correct

    This is the best next step because the risk is both identified and still manageable during the pilot. Recording it in the risk register, assigning accountability, and escalating it for acceptance or treatment ensures management makes an informed decision. Since the issue will be harder to fix after production launch, early action is important. This is classic risk governance: identify, document, assign, and decide before exposure expands.

  • Wait until after production launch to see whether the issue actually occurs.

    Why it's wrong here

    Waiting until after production launch deliberately extends the exposure window and enlarges the blast radius: more users, more data, and dependency chains that make fixes costlier and subject to stricter change control. If the issue triggers during production, the organization faces incident response, potential downtime, and regulatory consequences rather than a controlled pilot adjustment. The pilot exists to uncover and address such risks before launch, so postponing treatment is a reactive, non-governance approach.

  • Transfer the risk by moving the pilot to a different business unit.

    Why it's wrong here

    Moving the pilot to another business unit does not transfer risk in the professional sense—it merely changes the organizational owner while the same threat and vulnerability persist. True risk transfer requires an external party to assume financial liability, typically through insurance, contractual indemnification, or outsourcing with enforceable service-level agreements. Without that, the enterprise risk profile is unchanged, and the receiving unit is exposed to precisely the same technical and operational impact.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.