Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Policy excerpt:
- All privileged remote access must use MFA.

Standard excerpt:
- Approved MFA methods are authenticator app or FIDO2 security key.

Procedure excerpt:
- Service desk validates identity, enrolls the device, and closes the ticket.

Exception request:
- The legacy partner portal supports only password authentication for 60 days until migration completes.
- The business owner asked for a quick email approval so the team can proceed today.

Based on the exhibit, what is the best governance action before the sales team uses the legacy portal without MFA?

⚠ Common exam trap

CompTIA often tests the distinction between an informal workaround and a formal governance process, trapping candidates who think a quick approval or policy change is sufficient without understanding the need for documented risk acceptance and compensating controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a formal time-bound exception with compensating controls, approval, and an expiration date.

Governance requires that any exception to a security policy (such as bypassing MFA) must be formally documented, approved by management, time-bound, and include compensating controls to mitigate risk. In this scenario, the legacy portal lacks MFA support, so a formal exception with an expiration date ensures the risk is tracked and re-evaluated, rather than permanently weakening security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Update the policy immediately to allow password-only access for all legacy systems.

    Why it's wrong here

    Rewriting the entire policy to permit password-only access across all legacy systems is a permanent, blanket control downgrade that affects systems not involved in the current request. It bypasses change management and risk review, destroying the MFA control baseline organization-wide rather than addressing a single documented business need. Policy updates should reflect deliberate decisions with broad stakeholder input—not be used as a quick fix for one exception, and doing so creates a lasting compliance gap.

  • Create a formal time-bound exception with compensating controls, approval, and an expiration date.

    Why this is correct

    A formal exception preserves the existing policy while allowing a documented, limited deviation for business need. It should include a risk owner approval, compensating controls such as stricter monitoring or network restrictions, and a review or expiration date so the exception does not become permanent.

  • Have the help desk approve the request informally in the ticket and proceed without further documentation.

    Why it's wrong here

    An informal ticket note lacks the accountable sign-off of a risk owner, fails to define compensating controls, and provides no expiration or review date. Without formal documentation, auditors and security teams lose the ability to verify that the deviation was risk-assessed, time-limited, and tracked to closure—turning a legitimate temporary need into an uncontrolled security exception. It also leaves the organization vulnerable if a later incident occurs because there is no evidence of governance approval.

  • Ignore the MFA requirement because the portal is owned by a trusted partner.

    Why it's wrong here

    Trusting a partner's portal does not transfer the organization's compliance responsibility—the organization remains accountable for protecting its data, regardless of who hosts the application. Ignoring the MFA requirement without a documented risk treatment violates governance principles and potentially contractual obligations, leaving no audit trail of the decision. A justified deviation must still be handled as a formal exception with compensating controls, not dismissed based on trust.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.