SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Risk register excerpt -------------------------------------------------- Risk ID: R-19 Asset: Partner self-service portal on legacy VM Likelihood: 4/5 Impact: 5/5 Current controls: firewall ACL, nightly backups Business note: Portal must remain online for 90 more days until migration completes Available budget: Compensating controls approved for this quarter
Based on the exhibit, what is the best risk treatment recommendation for the security manager?
⚠ Common exam trap
Many candidates confuse risk acceptance (A) with simply having a backup, failing to recognize that backups address only one aspect of risk (availability) and do not mitigate the active vulnerabilities that could lead to data exposure or system compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate the risk with compensating controls until the migration is complete.
The exhibit shows a legacy portal with known vulnerabilities that is scheduled for migration to a modern platform. Since backups alone do not address the active security weaknesses, the best recommendation is to mitigate the risk with compensating controls (e.g., web application firewall rules, network segmentation, or strict access controls) to reduce the likelihood or impact of exploitation until the migration is complete. This aligns with the risk treatment strategy of mitigation, as it actively reduces the risk without prematurely retiring the service or relying solely on insurance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because backups are already enabled.
Why it's wrong here
Accepting the risk solely because backups are enabled is inappropriate. Backups provide recovery after an incident but do nothing to reduce the likelihood of a compromise or prevent data exfiltration, service disruption, or lateral movement while the portal remains live. With an approved budget and an imminent migration, accepting a known unmitigated exposure violates the fundamental risk management principle that risk should be reduced to an acceptable level when feasible.
- ✓
Mitigate the risk with compensating controls until the migration is complete.
Why this is correct
Mitigation via compensating controls is the best treatment because the service must remain operational and a permanent fix (migration) is already scheduled. Deploying a web application firewall, enforcing multifactor authentication, segmenting the network, and enabling enhanced monitoring reduce the immediate exposure to a level the organization can tolerate. This approach uses the approved budget effectively and preserves business continuity until the migration removes the underlying vulnerability.
- ✗
Avoid the risk by immediately retiring the portal.
Why it's wrong here
Immediate retirement is a classic avoidance strategy, but it would eliminate the portal's business value before the migration is ready. The portal supports required business operations, so taking it down would cause significant disruption and violate service continuity. Since mitigation is feasible and budgeted, outright avoidance is an unnecessarily extreme response that fails to balance security with business needs.
- ✗
Transfer the risk by purchasing cyber insurance only.
Why it's wrong here
Purchasing cyber insurance only transfers the financial consequences of a breach; it does not reduce the likelihood or operational impact of a compromise. The portal remains exposed to attackers, and insurance will not prevent downtime, data theft, or reputational damage. Risk transfer should be reserved for residual risk after mitigation, not as a substitute for implementing feasible security controls.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Exploitation
Exploitation is the act of using a vulnerability or weakness in a system, network, or application to gain unauthorized access, cause damage, or extract data.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.