SY0-701 Security Program Management and Oversight Practice Question
A vendor says a patch for a critical flaw in a public-facing application will not be available for 30 days, but the service must stay online. What is the best short-term risk treatment?
⚠ Common exam trap
CompTIA often tests the misconception that risk acceptance is a valid short-term treatment when a patch is delayed, but the key is that acceptance is only appropriate after evaluating and documenting the risk, not as a default action without controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement compensating controls, such as tighter filtering and temporary restrictions, until the patch is released.
When a critical patch is unavailable, the best short-term risk treatment is to implement compensating controls that reduce the likelihood or impact of exploitation. For a public-facing application, this could include deploying a web application firewall (WAF) with tighter rule sets, rate limiting, IP allowlisting, or temporarily disabling non-essential functionality. These controls provide a defense-in-depth layer until the vendor releases the patch, keeping the service online while reducing risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk without making any changes because the patch is not available yet.
Why it's wrong here
Accepting the risk without implementing any compensating security controls is inappropriate when the vulnerability is critical and the application is publicly reachable. In risk management, acceptance is a formal decision to tolerate potential loss, but that decision still requires justification and usually a residual risk that is deemed low; here, the residual risk is high because no safeguards reduce exploitability. The unavailability of a vendor patch does not remove the exploit path, so doing nothing leaves the organization with an unacceptable level of exposure until that patch arrives.
- ✗
Avoid the risk by permanently shutting down the application.
Why it's wrong here
Permanently shutting down the application is a risk avoidance response that eliminates the vulnerability by removing the asset, but it also eliminates the business function the application was built to provide. This is disproportionate because the organization can preserve availability while reducing risk through temporary technical and administrative measures, such as IP allow lists, web application firewall rules, or disabling nonessential features. Avoidance is more appropriate for non-critical systems or when no practical safeguards exist, not for an application the business depends on, so this choice sacrifices continuity instead of managing the risk.
- ✗
Transfer the risk to an insurance policy and wait for the patch.
Why it's wrong here
Transferring the risk to an insurance policy shifts potential financial liability, but it does not reduce the likelihood or technical impact of an attacker exploiting the vulnerability. Cyber insurance may compensate for losses, but it cannot prevent data exfiltration, credential theft, or system compromise, and it may have exclusions for unpatched known vulnerabilities. Waiting for the patch while relying on insurance leaves the public-facing attack surface fully exposed and is not a substitute for the compensating controls that can lower exploitability during the gap.
- ✓
Implement compensating controls, such as tighter filtering and temporary restrictions, until the patch is released.
Why this is correct
This is the best option because the business must keep the application online, but the known vulnerability still needs risk reduction. Compensating controls are temporary safeguards that lower exposure when a permanent fix is unavailable. Examples include stricter access filtering, disabling unnecessary features, or adding monitoring until the vendor patch can be applied safely.
Visual reference
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Web Application Firewall
A Web Application Firewall (WAF) is a security tool that monitors, filters, and blocks HTTP traffic to and from a web application to protect it from common attacks.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.