Courseiva

SY0-701 Security Program Management and Oversight Practice Question

A security analyst discovers that a critical internal payroll application has no vendor-supported patch for a recently announced remote code execution vulnerability. The application must remain available for at least six months until a replacement is deployed. Management asks the security team to recommend the most appropriate risk response. Which risk response should the analyst recommend?

⚠ Common exam trap

The trap here is assuming that any vulnerability must be mitigated immediately, overlooking that acceptance is a legitimate risk response when business constraints prevent other actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk acceptance

The correct response is risk acceptance because the organization cannot patch the application, must keep it running, and has a planned replacement. Formally accepting the risk with management approval and monitoring is the pragmatic choice. Mitigation, transference, and avoidance are either infeasible or would cause unacceptable business disruption. The key is to recognize that acceptance is a valid strategy when other options are exhausted or impractical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk transference

    Why it's wrong here

    Risk transference shifts the financial impact of a risk to a third party, often through insurance or contracts. However, the vulnerability affects an internal payroll application that must remain operational; transferring the risk does not eliminate the need to manage the vulnerability itself. Moreover, transference typically applies to financial losses, not to operational continuity, making it less suitable than acceptance in this context.

  • ✓

    Risk acceptance

    Why this is correct

    Risk acceptance is appropriate because the organization acknowledges the vulnerability but continues operating the application due to business necessity and a planned future replacement. The risk is formally documented, approved by management, and monitored, which aligns with the definition of acceptance. Other responses like mitigation or transfer are not feasible without a patch or compensating control, and avoidance would disrupt critical payroll operations.

  • ✗

    Risk mitigation

    Why it's wrong here

    Risk mitigation involves applying controls to reduce the likelihood or impact of a vulnerability. Here, no patch exists, and the application must stay online, so typical mitigation like patching or isolating the system may not be possible without disrupting payroll. While compensating controls could be considered, the scenario asks for the most appropriate response given the constraints, and the analyst should not assume mitigation is feasible without evidence.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance means discontinuing the activity that introduces the risk. In this case, shutting down the payroll application would halt critical business operations, which is not acceptable given the six-month timeline. Avoidance is impractical because the organization must continue paying employees. Thus, it is not the most appropriate response when the application is essential and a replacement is already planned.

About these practice questions

This SY0-701 question is part of Courseiva's 1,030-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.