SY0-701 Security Program Management and Oversight Practice Question
A security manager at a healthcare organization is responsible for maintaining the information security policy. A project manager requests a policy exception to use a cloud-based analytics platform that stores patient data. The platform currently encrypts data at rest with AES-128 instead of the required AES-256. The security manager assesses the risk and determines that the likelihood of data exposure is low due to other compensating controls already in place, but the impact would be high. The residual risk is within the organization's risk appetite. Which of the following is the most appropriate action for the security manager to take?
⚠ Common exam trap
Test-takers frequently assume any deviation from policy must be denied (Option A) or escalated (Option D), failing to recognize that a formal exception process with compensating controls and a review date is the correct risk-based action when residual risk is within appetite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approve the exception and document the compensating controls and a review date.
The security manager has assessed the risk, determined that compensating controls reduce the likelihood of data exposure, and confirmed that the residual risk is within the organization's risk appetite. Formally approving the exception with documented compensating controls and a review date ensures governance, accountability, and a timeline for reassessment, which aligns with the policy exception process in security program management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deny the exception and require the project to use an approved platform that meets the AES-256 requirement.
Why it's wrong here
This is incorrect because if the risk is within the organization's risk appetite and compensating controls are effective, a blanket denial may be overly restrictive and could hinder legitimate business operations. Policy exceptions exist to allow flexibility when risk is acceptable.
When this WOULD be correct
This option would be correct if the risk assessment showed high likelihood or residual risk exceeding the organization's risk appetite, or if no compensating controls existed to mitigate the encryption deficiency.
- ✓
Approve the exception and document the compensating controls and a review date.
Why this is correct
This is correct because a formal exception process with documented compensating controls and a scheduled review ensures that the risk is managed, tracked, and reassessed over time. This aligns with security program management best practices.
- ✗
Accept the risk and allow the project to proceed without a formal exception.
Why it's wrong here
Accepting the risk and proceeding without a formal exception is incorrect because it bypasses the governance and audit trails required for risk acceptance. Even when risk is within the organizational risk appetite, the decision must be documented through a formal exception process that records the rationale, compensating controls, and a re-review date. Undocumented risk acceptance creates unmonitored residual risk, undermines accountability, and can lead to compliance failures during audits or regulatory inspections. Security program management best practices require that every accepted risk be formally tracked and periodically reassessed to ensure the compensating controls remain effective.
When this WOULD be correct
This option would be correct if the security manager had determined that the risk is within the organization's risk appetite and the policy allows for risk acceptance without formal exceptions, and no compensating controls or review dates are needed.
- ✗
Escalate the request to the chief information officer for a final decision.
Why it's wrong here
This is incorrect because the security manager typically has the authority to approve policy exceptions within the defined risk appetite. Escalation without a clear reason adds unnecessary delay and does not leverage the manager's risk assessment.
When this WOULD be correct
This option would be correct if the organization's policy mandates that all exceptions involving patient data must be approved by the CIO, or if the risk exceeds the security manager's authority level and requires executive sign-off.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Approve the exception and document the compensating controls and a review date.Correct answer▾
Why this is correct
This is correct because a formal exception process with documented compensating controls and a scheduled review ensures that the risk is managed, tracked, and reassessed over time. This aligns with security program management best practices.
✗Deny the exception and require the project to use an approved platform that meets the AES-256 requirement.Wrong answer — click to see why▾
Why this is wrong here
Denying the exception outright ignores the risk assessment showing low likelihood and residual risk within appetite, and fails to leverage compensating controls that reduce risk.
★ When this WOULD be the correct answer
This option would be correct if the risk assessment showed high likelihood or residual risk exceeding the organization's risk appetite, or if no compensating controls existed to mitigate the encryption deficiency.
Why candidates choose this
Candidates may default to strict compliance with the policy requirement (AES-256) without considering that policy exceptions are a valid risk management tool when compensating controls reduce risk to an acceptable level.
✗Accept the risk and allow the project to proceed without a formal exception.Wrong answer — click to see why▾
Why this is wrong here
Accepting risk without a formal exception bypasses the required documentation and review process, which is critical for compliance and auditability in a healthcare organization handling patient data.
★ When this WOULD be the correct answer
This option would be correct if the security manager had determined that the risk is within the organization's risk appetite and the policy allows for risk acceptance without formal exceptions, and no compensating controls or review dates are needed.
Why candidates choose this
Candidates may confuse 'accepting risk' with 'approving an exception,' not realizing that formal exceptions require documentation and review to maintain policy integrity and compliance.
✗Escalate the request to the chief information officer for a final decision.Wrong answer — click to see why▾
Why this is wrong here
The security manager has the authority to approve exceptions within the organization's risk appetite, and the scenario does not indicate that escalation is required. Escalating to the CIO would be unnecessary and inefficient when the manager can make the decision themselves.
★ When this WOULD be the correct answer
This option would be correct if the organization's policy mandates that all exceptions involving patient data must be approved by the CIO, or if the risk exceeds the security manager's authority level and requires executive sign-off.
Why candidates choose this
Candidates may think that any exception involving sensitive data like patient health information must be escalated to higher management, especially when the impact is high, but the scenario explicitly states the residual risk is within the risk appetite, so the manager can decide.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
Key term
Residual risk
Residual risk is the level of risk that remains after all security controls and countermeasures have been applied.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A project team needs to use a temporary file-sharing service for two weeks because the approved platform is under maintenance. The security manager wants the exception to be reviewed, time-limited, and documented with the business reason. Which governance document should be created?
easy- A.A guideline, because it provides optional best practices for users to follow.
- ✓ B.An exception request, because it records a deviation from the normal security requirement.
- C.A standard, because it defines the mandatory company-wide rule for file sharing.
- D.A procedure, because it gives step-by-step instructions for employees to follow.
Why B: An exception request is the formal governance document used to record, review, and time-limit a deviation from the organization's security baseline. In this scenario, the temporary use of an unapproved file-sharing service for two weeks requires documented authorization, including the business reason, to ensure the risk is accepted and tracked until the approved platform returns.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.