Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A vendor-supported legacy application can run only with a deprecated browser plug-in on two engineering workstations for 30 days while a replacement is tested. Management wants to allow the exception without weakening the security program. What is the best action?

⚠ Common exam trap

Many candidates choose Option A (informal approval) because it seems quick and pragmatic, but the SY0-701 exam emphasizes that any exception must be formally documented, risk-assessed, and time-bound to maintain a defensible security program.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Document a time-bound exception, record the risk, apply compensating controls, and schedule review before expiration.

It follows the formal exception process required by a mature security program: documenting the exception with a specific time bound (30 days), recording the associated risk, applying compensating controls (such as network segmentation or host-based firewall rules to isolate the deprecated plug-in), and scheduling a review before expiration ensures the risk is managed and the exception does not become permanent. This aligns with the SY0-701 objective of implementing risk management processes, where time-bound exceptions with compensating controls are the standard way to handle legacy dependencies without weakening the overall security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Approve the exception informally by email and revisit it if problems appear.

    Why it's wrong here

    Informal email approval does not create an auditable record, assign a risk owner, or define the compensating controls that make the exception acceptable. It also lacks a defined expiration or renewal trigger, so the risk becomes open-ended and may be forgotten once the email thread ends. Security governance requires formal, time-limited risk acceptance with management sign-off, not ad-hoc correspondence that provides no accountability if the vendor application is compromised.

  • Document a time-bound exception, record the risk, apply compensating controls, and schedule review before expiration.

    Why this is correct

    A formal, time-bound exception is the correct governance approach because it explicitly documents the accepted risk, names the system owner, and specifies why the legacy application must operate outside baselines. Compensating controls — such as host-based firewalls, application allowlisting, or network segmentation — are implemented to reduce exposure while the exception is active. Scheduling a review before expiration forces a reassessment of whether the vulnerability still exists, whether the controls remain effective, and whether the application can now be upgraded or retired.

  • Disable all monitoring on the workstations so the application will function normally.

    Why it's wrong here

    Disabling monitoring removes the organization's ability to detect malicious activity, anomalous behavior, or policy violations on those workstations. This is the opposite of a compensating control; it actually increases the risk profile by eliminating the visibility that would allow incident response teams to identify and contain a compromise. Monitoring controls like EDR, syslog forwarding, and perimeter inspection should remain active even when an exception is granted, and any performance conflicts with legacy software should be resolved through configuration tuning or exclusions rather than wholesale deactivation.

  • Publish the exception as a permanent guideline so other teams can follow it.

    Why it's wrong here

    Publishing the exception as a permanent guideline would convert a narrowly scoped, time-limited risk acceptance into a broad standing policy for all teams, without management approval for each instance or a defined sunset date. It also bypasses the requirement to evaluate compensating controls per unique environment, since different teams may have different network postures, threat models, or compliance obligations. Permanent guidelines are for approved security baselines, not for exceptions — which by definition deviate from the baseline and must be reviewed, renewed, and eventually retired.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.