A business unit asks for a 30-day exception to use an unsupported browser plug-in on two engineering workstations while a replacement is tested. Which three conditions should be required before approval? Select three.
It demonstrates that the exception is not merely for convenience but addresses a genuine operational need, tying the risk acceptance to a specific business outcome. Without this, the exception lacks context for risk owners to evaluate whether the temporary risk is worth taking, and it fails the requirement for risk acceptance to be an informed decision. This documentation also provides the basis for the review at expiration, showing whether the need still exists.
Why this answer
A documented business justification ensures that the exception is necessary and aligns with organizational risk appetite. Without a clear reason, the exception could be granted for convenience rather than critical need, undermining security governance. This justification also provides an audit trail for why an unsupported, potentially vulnerable plug-in is still in use.
Exam trap
The trap here is that candidates might think only one or two conditions are sufficient, but CompTIA expects all three—justification, expiration, and compensating controls—to be required for a valid exception approval.