Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Risk register excerpt
--------------------------------------------------
Risk ID: R-19
Asset: Partner self-service portal on legacy VM
Likelihood: 4/5
Impact: 5/5
Current controls: firewall ACL, nightly backups
Business note: Portal must remain online for 90 more days until migration completes
Available budget: Compensating controls approved for this quarter

Based on the exhibit, what is the best risk treatment recommendation for the security manager?

⚠ Common exam trap

Many candidates confuse risk acceptance (A) with simply having a backup, failing to recognize that backups address only one aspect of risk (availability) and do not mitigate the active vulnerabilities that could lead to data exposure or system compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mitigate the risk with compensating controls until the migration is complete.

The exhibit shows a legacy portal with known vulnerabilities that is scheduled for migration to a modern platform. Since backups alone do not address the active security weaknesses, the best recommendation is to mitigate the risk with compensating controls (e.g., web application firewall rules, network segmentation, or strict access controls) to reduce the likelihood or impact of exploitation until the migration is complete. This aligns with the risk treatment strategy of mitigation, as it actively reduces the risk without prematurely retiring the service or relying solely on insurance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the risk because backups are already enabled.

    Why it's wrong here

    Accepting the risk solely because backups are enabled is inappropriate. Backups provide recovery after an incident but do nothing to reduce the likelihood of a compromise or prevent data exfiltration, service disruption, or lateral movement while the portal remains live. With an approved budget and an imminent migration, accepting a known unmitigated exposure violates the fundamental risk management principle that risk should be reduced to an acceptable level when feasible.

  • Mitigate the risk with compensating controls until the migration is complete.

    Why this is correct

    Mitigation via compensating controls is the best treatment because the service must remain operational and a permanent fix (migration) is already scheduled. Deploying a web application firewall, enforcing multifactor authentication, segmenting the network, and enabling enhanced monitoring reduce the immediate exposure to a level the organization can tolerate. This approach uses the approved budget effectively and preserves business continuity until the migration removes the underlying vulnerability.

  • Avoid the risk by immediately retiring the portal.

    Why it's wrong here

    Immediate retirement is a classic avoidance strategy, but it would eliminate the portal's business value before the migration is ready. The portal supports required business operations, so taking it down would cause significant disruption and violate service continuity. Since mitigation is feasible and budgeted, outright avoidance is an unnecessarily extreme response that fails to balance security with business needs.

  • Transfer the risk by purchasing cyber insurance only.

    Why it's wrong here

    Purchasing cyber insurance only transfers the financial consequences of a breach; it does not reduce the likelihood or operational impact of a compromise. The portal remains exposed to attackers, and insurance will not prevent downtime, data theft, or reputational damage. Risk transfer should be reserved for residual risk after mitigation, not as a substitute for implementing feasible security controls.

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.