Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A vendor-supported application cannot be patched for 30 days, but the business must keep it online. What is the best short-term risk treatment?

⚠ Common exam trap

Many candidates confuse 'risk acceptance' (Option A) as a valid short-term treatment, but the question explicitly requires the best treatment when the business must keep the application online, making compensating controls the correct choice over passive acceptance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Apply a compensating control, such as restricting access and monitoring traffic

When a known vulnerability cannot be patched immediately, applying a compensating control—such as restricting network access via firewall rules (e.g., allowing only specific source IPs) and enabling deep packet inspection (DPI) or an intrusion prevention system (IPS) to monitor for exploit attempts—reduces the risk to an acceptable level without taking the application offline. This approach aligns with the principle of defense in depth, buying time until the vendor patch is available.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the risk without any additional controls

    Why it's wrong here

    Accepting the risk without any compensating control leaves the known vulnerability completely exposed for the entire 30-day window, with no additional security measures to reduce the likelihood or impact of an exploit. This approach is only acceptable if a formal risk acceptance has been signed by management and the system has been evaluated to determine that the potential impact is within organizational tolerance. In most cases, when a vendor-supported application must remain online and vulnerable, the absence of interim technical controls is a significant governance failure.

  • Apply a compensating control, such as restricting access and monitoring traffic

    Why this is correct

    Applying a compensating control is the correct approach because it provides interim mitigation while the permanent patch is unavailable. Restricting access, such as through network segmentation, IP allowlisting, or disabling internet-facing exposure, directly reduces the attack surface and makes it harder for an attacker to reach the vulnerable service. Concurrently, monitoring traffic with intrusion detection or continuous log review enables early detection of suspicious activity, giving the security team time to respond. This aligns with risk management best practices and is a recognized alternative when patches cannot be immediately deployed.

  • Delete the application so the vulnerability no longer exists

    Why it's wrong here

    Deleting the application eliminates the vulnerability entirely but also removes a business service that is supported by the vendor and presumably required for operations. This is a risk avoidance measure that carries severe operational and financial consequences, often making it impractical or impossible without a replacement system. It also ignores the fact that a temporary compensating control could preserve the service while safely managing the risk until the patch is ready.

  • Transfer the risk by telling users to work faster

    Why it's wrong here

    Telling users to work faster is not a valid risk transfer mechanism because risk transfer involves shifting the potential financial or liability impact to a third party, such as through insurance or outsourcing, not changing user behavior. Altering user speed does not reduce the technical vulnerability or the exposure of the application to network-based attacks, and it may increase human error or operational stress. This approach misunderstands both the nature of the vulnerability and the definition of risk transfer.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.