SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Emergency change request CHG-8841 Service: Customer portal login API Reason: critical authentication bug causing lockouts Pipeline status: - Code review: pending - Automated unit tests: skipped to save time - Integration tests: failed once and were not rerun - Rollback plan: not documented - Approval: verbal yes from operations supervisor - Deployment window: 21:30-22:00 tonight
Based on the exhibit, what is the best next step before the hotfix is released?
⚠ Common exam trap
The trap here is that candidates may prioritize speed over security, assuming that a customer-facing issue justifies skipping change management, but the exam emphasizes that formal approval and testing are non-negotiable even for urgent fixes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pause release until the change is formally approved, tested, and has a documented rollback path.
Releasing a hotfix without formal approval, testing, and a documented rollback path violates the change management policy required by security program management. Even for urgent customer-facing issues, skipping these steps risks introducing new vulnerabilities or breaking other systems, which could lead to a larger outage. The exhibit indicates a need for controlled change processes, so pausing until the change is properly vetted ensures stability and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy immediately because the issue is customer-facing and urgent.
Why it's wrong here
Deploying immediately because the issue is customer-facing overlooks the fact that urgency does not bypass change management. The exhibit shows skipped tests, an unresolved integration failure, and no documented rollback path, so an immediate deployment could turn a partial sign-in problem into a complete authentication outage. An emergency change can be expedited, but it still requires documented authorization, at least minimal validation, and a clear rollback plan to avoid increasing impact.
- ✗
Close the ticket after deployment and create a postmortem if users complain.
Why it's wrong here
Closing the ticket after deployment assumes the change succeeded without any post-deployment verification and disregards the missing pre-release approvals, testing, and rollback planning visible in the exhibit. A postmortem is a reactive learning tool; it cannot retroactively authorize an uncontrolled change or reduce the risk that was already taken. The ticket should remain open until the change is formally approved, tested, and has a rollback path, followed by verification of the deployment.
- ✗
Ask support to warn users that sign-in may fail during the next hour.
Why it's wrong here
Asking support to warn users about sign-in failures treats the symptom of a known-quality-risk deployment but does nothing to address the exhibit’s process gaps, such as skipped tests and no rollback plan. This option effectively accepts an avoidable degradation instead of preventing it through proper change controls. The safest next step is to pause the release until the change is approved, validated, and reversible, rather than informing users of an impending failure that could be avoided.
- ✓
Pause release until the change is formally approved, tested, and has a documented rollback path.
Why this is correct
The exhibit shows multiple process gaps: skipped tests, unresolved integration test failure, no documented rollback plan, and only verbal approval. Even an emergency fix should follow an emergency change process with documented authorization and enough validation to reduce the chance of making the outage worse. The safest next step is to complete the required change controls before production deployment.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Change management
Change management is the structured process of planning, approving, implementing, and reviewing changes to IT systems to minimize risk and disruption.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.