Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

After reviewing a risk memo, the operations director signs off on continuing to use an older application because the cost of replacement is too high right now. Which risk management action did the director take?

⚠ Common exam trap

Many candidates confuse 'acceptance' with 'avoidance' — candidates often think that continuing to use the application means avoiding the risk, but avoidance requires stopping the risky activity entirely, not just living with it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Risk acceptance, because management chose to live with the remaining risk.

The operations director chose to continue using the older application despite the identified risk, explicitly because the cost of replacement was too high. This is the definition of risk acceptance: management acknowledges the risk and decides to tolerate the residual risk without implementing additional controls. The director did not transfer, avoid, or mitigate the risk; they accepted it as a cost of business.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Risk transfer, because the risk was moved to another company.

    Why it's wrong here

    Risk transfer shifts the financial consequences of a loss to a third party, typically through insurance policies, indemnification clauses, or outsourcing contracts. In this scenario, the operations director is not executing any such arrangement; the memo's sign-off is an internal governance decision to keep the system running as-is. Even when risk is genuinely transferred, the originating organization retains some residual risk and accountability, so saying the risk was "moved to another company" is inaccurate. Because there is no contractual or financial mechanism shifting the exposure, this is not risk transfer.

  • Risk acceptance, because management chose to live with the remaining risk.

    Why this is correct

    Risk acceptance is the correct term when management knowingly approves continued operation despite identified risk. The director is not eliminating the issue or moving it elsewhere; instead, they are choosing to tolerate the residual risk for business reasons such as cost or timing. This is a normal part of risk management when the risk is understood and documented.

  • Risk avoidance, because the application is still being used.

    Why it's wrong here

    Risk avoidance is a deliberate strategy to eliminate a risk entirely by discontinuing the activity that creates it, such as shutting down the application or removing the vulnerable process. The scenario clearly states the application remains in active use, so the risk is not avoided; the exposure is still present. The director's sign-off does not stop the risky behavior—it explicitly allows continued operation. Therefore, choosing this option misidentifies a tolerance decision as an elimination decision.

  • Risk mitigation, because the replacement cost was too high.

    Why it's wrong here

    Risk mitigation involves implementing safeguards—technical, administrative, or physical controls—to reduce the likelihood or impact of an identified risk, such as patching, segmentation, or monitoring. The operations director's sign-off is not adding any such controls; it is a management decision to proceed despite the risk because the cost of remediation or replacement is deemed too high. Accepting a risk because mitigation is too expensive is the essence of risk acceptance, not mitigation, since mitigation would require actively applying controls. Thus, this answer confuses a decision to tolerate with an action to reduce.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.