SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Policy excerpt: - All privileged remote access must use MFA. Standard excerpt: - Approved MFA methods are authenticator app or FIDO2 security key. Procedure excerpt: - Service desk validates identity, enrolls the device, and closes the ticket. Exception request: - The legacy partner portal supports only password authentication for 60 days until migration completes. - The business owner asked for a quick email approval so the team can proceed today.
Based on the exhibit, what is the best governance action before the sales team uses the legacy portal without MFA?
⚠ Common exam trap
CompTIA often tests the distinction between an informal workaround and a formal governance process, trapping candidates who think a quick approval or policy change is sufficient without understanding the need for documented risk acceptance and compensating controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a formal time-bound exception with compensating controls, approval, and an expiration date.
Governance requires that any exception to a security policy (such as bypassing MFA) must be formally documented, approved by management, time-bound, and include compensating controls to mitigate risk. In this scenario, the legacy portal lacks MFA support, so a formal exception with an expiration date ensures the risk is tracked and re-evaluated, rather than permanently weakening security posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the policy immediately to allow password-only access for all legacy systems.
Why it's wrong here
Rewriting the entire policy to permit password-only access across all legacy systems is a permanent, blanket control downgrade that affects systems not involved in the current request. It bypasses change management and risk review, destroying the MFA control baseline organization-wide rather than addressing a single documented business need. Policy updates should reflect deliberate decisions with broad stakeholder input—not be used as a quick fix for one exception, and doing so creates a lasting compliance gap.
- ✓
Create a formal time-bound exception with compensating controls, approval, and an expiration date.
Why this is correct
A formal exception preserves the existing policy while allowing a documented, limited deviation for business need. It should include a risk owner approval, compensating controls such as stricter monitoring or network restrictions, and a review or expiration date so the exception does not become permanent.
- ✗
Have the help desk approve the request informally in the ticket and proceed without further documentation.
Why it's wrong here
An informal ticket note lacks the accountable sign-off of a risk owner, fails to define compensating controls, and provides no expiration or review date. Without formal documentation, auditors and security teams lose the ability to verify that the deviation was risk-assessed, time-limited, and tracked to closure—turning a legitimate temporary need into an uncontrolled security exception. It also leaves the organization vulnerable if a later incident occurs because there is no evidence of governance approval.
- ✗
Ignore the MFA requirement because the portal is owned by a trusted partner.
Why it's wrong here
Trusting a partner's portal does not transfer the organization's compliance responsibility—the organization remains accountable for protecting its data, regardless of who hosts the application. Ignoring the MFA requirement without a documented risk treatment violates governance principles and potentially contractual obligations, leaving no audit trail of the decision. A justified deviation must still be handled as a formal exception with compensating controls, not dismissed based on trust.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.