Courseiva
Security Program Management and OversighthardMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Emergency change request CHG-8841
Service: Customer portal login API
Reason: critical authentication bug causing lockouts

Pipeline status:
- Code review: pending
- Automated unit tests: skipped to save time
- Integration tests: failed once and were not rerun
- Rollback plan: not documented
- Approval: verbal yes from operations supervisor
- Deployment window: 21:30-22:00 tonight

Based on the exhibit, what is the best next step before the hotfix is released?

⚠ Common exam trap

The trap here is that candidates may prioritize speed over security, assuming that a customer-facing issue justifies skipping change management, but the exam emphasizes that formal approval and testing are non-negotiable even for urgent fixes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Pause release until the change is formally approved, tested, and has a documented rollback path.

Releasing a hotfix without formal approval, testing, and a documented rollback path violates the change management policy required by security program management. Even for urgent customer-facing issues, skipping these steps risks introducing new vulnerabilities or breaking other systems, which could lead to a larger outage. The exhibit indicates a need for controlled change processes, so pausing until the change is properly vetted ensures stability and security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy immediately because the issue is customer-facing and urgent.

    Why it's wrong here

    Deploying immediately because the issue is customer-facing overlooks the fact that urgency does not bypass change management. The exhibit shows skipped tests, an unresolved integration failure, and no documented rollback path, so an immediate deployment could turn a partial sign-in problem into a complete authentication outage. An emergency change can be expedited, but it still requires documented authorization, at least minimal validation, and a clear rollback plan to avoid increasing impact.

  • Close the ticket after deployment and create a postmortem if users complain.

    Why it's wrong here

    Closing the ticket after deployment assumes the change succeeded without any post-deployment verification and disregards the missing pre-release approvals, testing, and rollback planning visible in the exhibit. A postmortem is a reactive learning tool; it cannot retroactively authorize an uncontrolled change or reduce the risk that was already taken. The ticket should remain open until the change is formally approved, tested, and has a rollback path, followed by verification of the deployment.

  • Ask support to warn users that sign-in may fail during the next hour.

    Why it's wrong here

    Asking support to warn users about sign-in failures treats the symptom of a known-quality-risk deployment but does nothing to address the exhibit’s process gaps, such as skipped tests and no rollback plan. This option effectively accepts an avoidable degradation instead of preventing it through proper change controls. The safest next step is to pause the release until the change is approved, validated, and reversible, rather than informing users of an impending failure that could be avoided.

  • Pause release until the change is formally approved, tested, and has a documented rollback path.

    Why this is correct

    The exhibit shows multiple process gaps: skipped tests, unresolved integration test failure, no documented rollback plan, and only verbal approval. Even an emergency fix should follow an emergency change process with documented authorization and enough validation to reduce the chance of making the outage worse. The safest next step is to complete the required change controls before production deployment.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.