SY0-701 Security Program Management and Oversight Practice Question
A security analyst discovers that a critical internal payroll application has no vendor-supported patch for a recently announced remote code execution vulnerability. The application must remain available for at least six months until a replacement is deployed. Management asks the security team to recommend the most appropriate risk response. Which risk response should the analyst recommend?
⚠ Common exam trap
The trap here is assuming that any vulnerability must be mitigated immediately, overlooking that acceptance is a legitimate risk response when business constraints prevent other actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk acceptance
The correct response is risk acceptance because the organization cannot patch the application, must keep it running, and has a planned replacement. Formally accepting the risk with management approval and monitoring is the pragmatic choice. Mitigation, transference, and avoidance are either infeasible or would cause unacceptable business disruption. The key is to recognize that acceptance is a valid strategy when other options are exhausted or impractical.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk transference
Why it's wrong here
Risk transference shifts the financial impact of a risk to a third party, often through insurance or contracts. However, the vulnerability affects an internal payroll application that must remain operational; transferring the risk does not eliminate the need to manage the vulnerability itself. Moreover, transference typically applies to financial losses, not to operational continuity, making it less suitable than acceptance in this context.
- ✓
Risk acceptance
Why this is correct
Risk acceptance is appropriate because the organization acknowledges the vulnerability but continues operating the application due to business necessity and a planned future replacement. The risk is formally documented, approved by management, and monitored, which aligns with the definition of acceptance. Other responses like mitigation or transfer are not feasible without a patch or compensating control, and avoidance would disrupt critical payroll operations.
- ✗
Risk mitigation
Why it's wrong here
Risk mitigation involves applying controls to reduce the likelihood or impact of a vulnerability. Here, no patch exists, and the application must stay online, so typical mitigation like patching or isolating the system may not be possible without disrupting payroll. While compensating controls could be considered, the scenario asks for the most appropriate response given the constraints, and the analyst should not assume mitigation is feasible without evidence.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance means discontinuing the activity that introduces the risk. In this case, shutting down the payroll application would halt critical business operations, which is not acceptable given the six-month timeline. Avoidance is impractical because the organization must continue paying employees. Thus, it is not the most appropriate response when the application is essential and a replacement is already planned.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.