A project team needs to use an unapproved file-sharing application for two weeks because the approved platform cannot support an external client collaboration feature. What is the best security action?
A temporary exception is the best choice when a business need exists and the risk can be managed. Document the reason, identify compensating controls such as encryption or restricted access, assign an owner, and set an expiration date. That approach preserves governance, keeps the risk visible, and avoids turning a temporary deviation into an indefinite shadow process.
Why this answer
It follows the principle of risk acceptance through a formal exception process. By documenting a temporary exception with compensating controls (e.g., data encryption, access logging, and usage monitoring) and setting a review date, the organization maintains security oversight while addressing the legitimate business need. This approach aligns with the SY0-701 domain of Security Program Management, which emphasizes balancing security with operational requirements through managed risk.
Exam trap
The trap here is that candidates may choose Option D, thinking that a detailed procedure mitigates risk, but CompTIA tests the understanding that procedures without compensating controls do not reduce the inherent risk of using an unapproved application.
How to eliminate wrong answers
Option A is wrong because it ignores the business need entirely, which can lead to shadow IT or unauthorized workarounds that bypass security controls entirely. Option C is wrong because immediately rewriting policy for a temporary, isolated need creates unnecessary risk exposure for all users and violates change management principles. Option D is wrong because a detailed procedure does not address the underlying security risk of using an unapproved application; it only documents how to use it unsafely.