SY0-701 Security Program Management and Oversight Practice Question
A small company has two security issues and can fix only one this week. Which should be prioritized first? One issue is an internal lab server with a medium-severity flaw. The other is an internet-facing login portal using default administrator credentials.
⚠ Common exam trap
The SY0-701 exam often tests the principle of prioritizing vulnerabilities based on risk (likelihood and impact) rather than treating all vulnerabilities equally, and the trap here is assuming that severity alone (medium vs. high) determines priority without considering exposure and exploitability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Fix the internet-facing login portal first because default administrator credentials create a much higher risk.
The internet-facing login portal using default administrator credentials represents an immediate, high-impact risk because it allows unauthorized remote access with administrative privileges. Default credentials are well-known and actively targeted by automated scanners and attackers, making exploitation trivial. In contrast, the internal lab server with a medium-severity flaw is behind network segmentation and requires additional access, so its risk is lower and can be deferred.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fix the internal lab server first because every vulnerability should be treated equally.
Why it's wrong here
Treating every vulnerability as equally important ignores the fundamental risk equation of likelihood and impact. An internal lab server is typically segmented from external access, meaning the default credentials are not remotely reachable by internet attackers, and a compromise would affect only non-critical lab operations. Meanwhile, the internet-facing login portal is permanently exposed and its default admin credentials are a trivial, easily automated attack vector. A risk-based approach weighs asset value, exposure, and exploitability, not just CVSS severity labels.
- ✓
Fix the internet-facing login portal first because default administrator credentials create a much higher risk.
Why this is correct
This is the best choice because a public-facing system with default credentials is far more likely to be attacked and can lead to immediate compromise. Risk prioritization considers both likelihood and impact, not just severity labels. Exposed administrative access can quickly become a business-wide incident, so it should be addressed first.
- ✗
Wait until the monthly maintenance window so both issues can be fixed at the same time.
Why it's wrong here
Delaying both fixes to a monthly maintenance window exposes your most critical asset to internet-facing attackers for the entire interval. Default administrator credentials on a portal are immediately discoverable and exploitable, often within minutes of being scanned by automated botnets. Emergency change procedures exist precisely for such high-risk issues, allowing you to remediate the portal now and still patch the lab server at the next maintenance window. Waiting multiplies the probability of a successful attack and turns a single vulnerable system into a likely breach.
- ✗
Ignore both issues until users report symptoms, then respond if something happens.
Why it's wrong here
This approach is purely reactive and ignores the reality that many security incidents are silent until long after exploitation. An attacker logging into a portal with default admin credentials may remain undetected while harvesting data or installing backdoors, with no user-visible symptoms. Relying on user reports means the organization has already suffered operational or reputational harm, and the response will be incident recovery rather than prevention. Proactive vulnerability management instead identifies and prioritizes exposures before they are exploited.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.