Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Risk Register Excerpt

Asset: Customer portal API
Threat: Web application vulnerability in search endpoint
Inherent likelihood: High (4/5)
Inherent impact: High (5/5)
Current control: WAF rule added after recent scan
Business note: Patch is available and estimated at 3 developer days
Policy note: Internet-facing systems with a known critical vulnerability may not be accepted if a fix is available before release
Target go-live: 14 days
Residual risk owner: Application manager

Based on the exhibit, what is the best risk response for the security team to recommend before the customer portal goes live?

⚠ Common exam trap

Candidates often assume a WAF provides complete protection and thus choose 'accept the risk,' but the SY0-701 exam emphasizes that compensating controls like WAFs are not a substitute for fixing the underlying vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mitigate the risk by remediating the vulnerability before production release.

The exhibit shows a critical SQL injection vulnerability in the customer portal that has been partially mitigated by a WAF rule. However, WAF rules can be bypassed (e.g., through encoding tricks or HTTP parameter pollution), so the residual risk remains high. The best response is to remediate the vulnerability in the application code before launch, which directly removes the root cause and aligns with the principle of defense in depth.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the risk now, because the WAF rule lowers exposure enough for launch.

    Why it's wrong here

    Accepting the risk on the basis of a WAF rule treats a compensating control as a permanent fix, leaving the underlying application vulnerability exploitable if the rule is bypassed or misconfigured. The policy excerpt explicitly restricts risk acceptance for critical internet-facing vulnerabilities when remediation is feasible before release, and the exhibit shows a patch is available in time for launch. Therefore, this option violates the organization's stated risk appetite and leaves residual exposure that cannot be justified as 'acceptable.'

  • Mitigate the risk by remediating the vulnerability before production release.

    Why this is correct

    This is the best choice because the exhibit shows a high-likelihood, high-impact issue with a fix available in time for launch. The policy also says critical internet-facing vulnerabilities should not be accepted when remediation is available. A real fix reduces the underlying exposure more effectively than a temporary control.

  • Transfer the risk to the hosting provider through a service-level agreement.

    Why it's wrong here

    Signing an SLA with the hosting provider shifts contractual liability and incident-response responsibilities, but it does nothing to eliminate the vulnerable code that resides in the organization's own application layer. SaaS and IaaS providers typically do not patch custom business logic, and the security flaw remains open to exploitation regardless of the agreement's terms. Since the exhibit indicates the vulnerability is remediable before go-live, transfer is a misapplied control that leaves the actual exploit path intact.

  • Avoid the risk by permanently canceling the customer portal project.

    Why it's wrong here

    Avoidance permanently cancels a business initiative to eliminate exposure, but it is a drastic measure meant for situations where no workable control or remediation exists. The exhibit shows a feasible fix that can be completed before release, so avoidance squanders the launch investment and user value without providing any incremental security benefit. It is disproportionate; the risk can be reduced to an acceptable level through a concrete patch rather than by destroying the project's purpose.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.