Exception Request: Documenting Policy Deviations in Security
A project team needs to use a temporary file-sharing service for two weeks because the approved platform is under maintenance. The security manager wants the exception to be reviewed, time-limited, and documented with the business reason. Which governance document should be created?
Quick Answer
The correct answer is an exception request, because it formally documents a time-limited deviation from the organization’s security baseline. In this scenario, the project team’s temporary use of an unapproved file-sharing service for two weeks requires a documented, reviewed, and time-bound authorization that captures the business reason and ensures the risk is accepted and tracked until the approved platform returns. This tests your understanding of governance documentation on the Security+ SY0-701 exam, where the key distinction is that an exception request applies to a specific, temporary deviation with a defined expiration, while a policy deviation is a broader term that may not imply a fixed timeline or formal review process. A common trap is confusing exception requests with waivers or exemptions, but remember: exceptions are always time-limited and require explicit re-approval after expiry. Memory tip: “Exception = Expiration date” — if it has a clock, it’s an exception.
⚠ Common exam trap
A common mix-up: candidates confuse an exception request with a standard or procedure, thinking any documented change to security controls requires a new policy document, rather than recognizing that an exception is a temporary, authorized waiver of an existing rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An exception request, because it records a deviation from the normal security requirement.
An exception request is the formal governance document used to record, review, and time-limit a deviation from the organization's security baseline. In this scenario, the temporary use of an unapproved file-sharing service for two weeks requires documented authorization, including the business reason, to ensure the risk is accepted and tracked until the approved platform returns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A guideline, because it provides optional best practices for users to follow.
Why it's wrong here
Guidelines are flexible recommendations, not formal approvals for exceptions.
- ✓
An exception request, because it records a deviation from the normal security requirement.
Why this is correct
An exception request documents a specific deviation from policy or standard, including the business justification, approval path, and expiration date. That is exactly what is needed when a team must temporarily use an alternative service. It keeps the deviation visible, reviewed, and accountable instead of silently bypassing security controls.
- ✗
A standard, because it defines the mandatory company-wide rule for file sharing.
Why it's wrong here
Standards set mandatory requirements, but they do not approve temporary departures from those requirements.
- ✗
A procedure, because it gives step-by-step instructions for employees to follow.
Why it's wrong here
Procedures explain how to perform a task, but they do not authorize a security exception.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security manager at a healthcare organization is responsible for maintaining the information security policy. A project manager requests a policy exception to use a cloud-based analytics platform that stores patient data. The platform currently encrypts data at rest with AES-128 instead of the required AES-256. The security manager assesses the risk and determines that the likelihood of data exposure is low due to other compensating controls already in place, but the impact would be high. The residual risk is within the organization's risk appetite. Which of the following is the most appropriate action for the security manager to take?
medium- A.Deny the exception and require the project to use an approved platform that meets the AES-256 requirement.
- ✓ B.Approve the exception and document the compensating controls and a review date.
- C.Accept the risk and allow the project to proceed without a formal exception.
- D.Escalate the request to the chief information officer for a final decision.
Why B: The security manager has assessed the risk, determined that compensating controls reduce the likelihood of data exposure, and confirmed that the residual risk is within the organization's risk appetite. Formally approving the exception with documented compensating controls and a review date ensures governance, accountability, and a timeline for reassessment, which aligns with the policy exception process in security program management.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.