SY0-701 Security Program Management and Oversight Practice Question
A vendor-supported legacy application can run only with a deprecated browser plug-in on two engineering workstations for 30 days while a replacement is tested. Management wants to allow the exception without weakening the security program. What is the best action?
⚠ Common exam trap
Many candidates choose Option A (informal approval) because it seems quick and pragmatic, but the SY0-701 exam emphasizes that any exception must be formally documented, risk-assessed, and time-bound to maintain a defensible security program.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document a time-bound exception, record the risk, apply compensating controls, and schedule review before expiration.
It follows the formal exception process required by a mature security program: documenting the exception with a specific time bound (30 days), recording the associated risk, applying compensating controls (such as network segmentation or host-based firewall rules to isolate the deprecated plug-in), and scheduling a review before expiration ensures the risk is managed and the exception does not become permanent. This aligns with the SY0-701 objective of implementing risk management processes, where time-bound exceptions with compensating controls are the standard way to handle legacy dependencies without weakening the overall security posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Approve the exception informally by email and revisit it if problems appear.
Why it's wrong here
Informal email approval does not create an auditable record, assign a risk owner, or define the compensating controls that make the exception acceptable. It also lacks a defined expiration or renewal trigger, so the risk becomes open-ended and may be forgotten once the email thread ends. Security governance requires formal, time-limited risk acceptance with management sign-off, not ad-hoc correspondence that provides no accountability if the vendor application is compromised.
- ✓
Document a time-bound exception, record the risk, apply compensating controls, and schedule review before expiration.
Why this is correct
A formal, time-bound exception is the correct governance approach because it explicitly documents the accepted risk, names the system owner, and specifies why the legacy application must operate outside baselines. Compensating controls — such as host-based firewalls, application allowlisting, or network segmentation — are implemented to reduce exposure while the exception is active. Scheduling a review before expiration forces a reassessment of whether the vulnerability still exists, whether the controls remain effective, and whether the application can now be upgraded or retired.
- ✗
Disable all monitoring on the workstations so the application will function normally.
Why it's wrong here
Disabling monitoring removes the organization's ability to detect malicious activity, anomalous behavior, or policy violations on those workstations. This is the opposite of a compensating control; it actually increases the risk profile by eliminating the visibility that would allow incident response teams to identify and contain a compromise. Monitoring controls like EDR, syslog forwarding, and perimeter inspection should remain active even when an exception is granted, and any performance conflicts with legacy software should be resolved through configuration tuning or exclusions rather than wholesale deactivation.
- ✗
Publish the exception as a permanent guideline so other teams can follow it.
Why it's wrong here
Publishing the exception as a permanent guideline would convert a narrowly scoped, time-limited risk acceptance into a broad standing policy for all teams, without management approval for each instance or a defined sunset date. It also bypasses the requirement to evaluate compensating controls per unique environment, since different teams may have different network postures, threat models, or compliance obligations. Permanent guidelines are for approved security baselines, not for exceptions — which by definition deviate from the baseline and must be reviewed, renewed, and eventually retired.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.