Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager at a healthcare organization is responsible for maintaining the information security policy. A project manager requests a policy exception to use a cloud-based analytics platform that stores patient data. The platform currently encrypts data at rest with AES-128 instead of the required AES-256. The security manager assesses the risk and determines that the likelihood of data exposure is low due to other compensating controls already in place, but the impact would be high. The residual risk is within the organization's risk appetite. Which of the following is the most appropriate action for the security manager to take?

⚠ Common exam trap

Test-takers frequently assume any deviation from policy must be denied (Option A) or escalated (Option D), failing to recognize that a formal exception process with compensating controls and a review date is the correct risk-based action when residual risk is within appetite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Approve the exception and document the compensating controls and a review date.

The security manager has assessed the risk, determined that compensating controls reduce the likelihood of data exposure, and confirmed that the residual risk is within the organization's risk appetite. Formally approving the exception with documented compensating controls and a review date ensures governance, accountability, and a timeline for reassessment, which aligns with the policy exception process in security program management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deny the exception and require the project to use an approved platform that meets the AES-256 requirement.

    Why it's wrong here

    This is incorrect because if the risk is within the organization's risk appetite and compensating controls are effective, a blanket denial may be overly restrictive and could hinder legitimate business operations. Policy exceptions exist to allow flexibility when risk is acceptable.

    When this WOULD be correct

    This option would be correct if the risk assessment showed high likelihood or residual risk exceeding the organization's risk appetite, or if no compensating controls existed to mitigate the encryption deficiency.

  • Approve the exception and document the compensating controls and a review date.

    Why this is correct

    This is correct because a formal exception process with documented compensating controls and a scheduled review ensures that the risk is managed, tracked, and reassessed over time. This aligns with security program management best practices.

  • Accept the risk and allow the project to proceed without a formal exception.

    Why it's wrong here

    Accepting the risk and proceeding without a formal exception is incorrect because it bypasses the governance and audit trails required for risk acceptance. Even when risk is within the organizational risk appetite, the decision must be documented through a formal exception process that records the rationale, compensating controls, and a re-review date. Undocumented risk acceptance creates unmonitored residual risk, undermines accountability, and can lead to compliance failures during audits or regulatory inspections. Security program management best practices require that every accepted risk be formally tracked and periodically reassessed to ensure the compensating controls remain effective.

    When this WOULD be correct

    This option would be correct if the security manager had determined that the risk is within the organization's risk appetite and the policy allows for risk acceptance without formal exceptions, and no compensating controls or review dates are needed.

  • Escalate the request to the chief information officer for a final decision.

    Why it's wrong here

    This is incorrect because the security manager typically has the authority to approve policy exceptions within the defined risk appetite. Escalation without a clear reason adds unnecessary delay and does not leverage the manager's risk assessment.

    When this WOULD be correct

    This option would be correct if the organization's policy mandates that all exceptions involving patient data must be approved by the CIO, or if the risk exceeds the security manager's authority level and requires executive sign-off.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Approve the exception and document the compensating controls and a review date.Correct answer

Why this is correct

This is correct because a formal exception process with documented compensating controls and a scheduled review ensures that the risk is managed, tracked, and reassessed over time. This aligns with security program management best practices.

Deny the exception and require the project to use an approved platform that meets the AES-256 requirement.Wrong answer — click to see why

Why this is wrong here

Denying the exception outright ignores the risk assessment showing low likelihood and residual risk within appetite, and fails to leverage compensating controls that reduce risk.

★ When this WOULD be the correct answer

This option would be correct if the risk assessment showed high likelihood or residual risk exceeding the organization's risk appetite, or if no compensating controls existed to mitigate the encryption deficiency.

Why candidates choose this

Candidates may default to strict compliance with the policy requirement (AES-256) without considering that policy exceptions are a valid risk management tool when compensating controls reduce risk to an acceptable level.

Accept the risk and allow the project to proceed without a formal exception.Wrong answer — click to see why

Why this is wrong here

Accepting risk without a formal exception bypasses the required documentation and review process, which is critical for compliance and auditability in a healthcare organization handling patient data.

★ When this WOULD be the correct answer

This option would be correct if the security manager had determined that the risk is within the organization's risk appetite and the policy allows for risk acceptance without formal exceptions, and no compensating controls or review dates are needed.

Why candidates choose this

Candidates may confuse 'accepting risk' with 'approving an exception,' not realizing that formal exceptions require documentation and review to maintain policy integrity and compliance.

Escalate the request to the chief information officer for a final decision.Wrong answer — click to see why

Why this is wrong here

The security manager has the authority to approve exceptions within the organization's risk appetite, and the scenario does not indicate that escalation is required. Escalating to the CIO would be unnecessary and inefficient when the manager can make the decision themselves.

★ When this WOULD be the correct answer

This option would be correct if the organization's policy mandates that all exceptions involving patient data must be approved by the CIO, or if the risk exceeds the security manager's authority level and requires executive sign-off.

Why candidates choose this

Candidates may think that any exception involving sensitive data like patient health information must be escalated to higher management, especially when the impact is high, but the scenario explicitly states the residual risk is within the risk appetite, so the manager can decide.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A project team needs to use a temporary file-sharing service for two weeks because the approved platform is under maintenance. The security manager wants the exception to be reviewed, time-limited, and documented with the business reason. Which governance document should be created?

easy
  • A.A guideline, because it provides optional best practices for users to follow.
  • B.An exception request, because it records a deviation from the normal security requirement.
  • C.A standard, because it defines the mandatory company-wide rule for file sharing.
  • D.A procedure, because it gives step-by-step instructions for employees to follow.

Why B: An exception request is the formal governance document used to record, review, and time-limit a deviation from the organization's security baseline. In this scenario, the temporary use of an unapproved file-sharing service for two weeks requires documented authorization, including the business reason, to ensure the risk is accepted and tracked until the approved platform returns.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.