Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Leadership wants to compare two controls for protecting a customer portal. Option A costs $40,000 and reduces annual loss expectancy from $120,000 to $30,000. Option B costs $15,000 and reduces annual loss expectancy to $70,000. Which analysis method best supports this decision?

⚠ Common exam trap

It's easy for candidates to choose qualitative risk analysis because it is simpler and more common, but the presence of specific monetary values in the question explicitly requires quantitative analysis to make a data-driven comparison.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Quantitative risk analysis

Quantitative risk analysis uses monetary values and numerical data to calculate risk, making it the best method to compare the cost-benefit of Option A (ALE reduction from $120,000 to $30,000 with a $40,000 cost) versus Option B (ALE reduction to $70,000 with a $15,000 cost). By computing the annualized loss expectancy (ALE) and comparing the cost of each control against the reduction in expected loss, leadership can determine which option provides a better return on investment. This approach directly supports the decision because it provides objective, dollar-based metrics for comparison.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Qualitative risk analysis

    Why it's wrong here

    Qualitative risk analysis categorizes risks on subjective scales such as high, medium, or low, often derived from expert judgment or ordinal ratings. Without assigning monetary values to potential losses or control costs, it cannot produce a direct dollar-denominated cost-benefit comparison of two controls. While useful for prioritizing risks quickly, it lacks the numeric precision needed for a financial side-by-side evaluation.

  • Quantitative risk analysis

    Why this is correct

    Quantitative risk analysis calculates risk in monetary terms using methods such as Single Loss Expectancy (SLE), Annualized Rate of Occurrence (ARO), and Annualized Loss Expectancy (ALE). By comparing the ALE reduction from a control against its annual cost, it yields metrics like Return on Investment (ROI) or residual risk, enabling a direct financial cost-benefit comparison. Leadership's request to compare controls financially points to this approach because it converts threat and mitigation data into dollar figures.

  • Business impact analysis

    Why it's wrong here

    A Business Impact Analysis (BIA) identifies critical business functions, dependencies, and the operational impact of disruptions, often producing recovery time objectives (RTOs) and recovery point objectives (RPOs). Its purpose is to prioritize continuity and recovery efforts, not to evaluate the cost-effectiveness of specific security controls. While a BIA may inform control selection, it does not itself compare the financial costs and benefits of alternative safeguards.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance is a risk treatment decision in which an organization formally acknowledges a risk and chooses to tolerate it without further mitigation. It is not an analysis method; rather, it is the outcome of a decision-making process that follows risk assessment. Financial comparison of control options would occur before a treatment decision, as part of risk analysis, not be replaced by the decision to accept the risk.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. The CIO wants to compare two mitigation options for a payment system outage and justify the budget request in dollars. The team already knows the likely downtime window, annual incident frequency, and estimated revenue loss per hour. Which approach would best support the decision?

medium
  • A.Qualitative risk analysis
  • B.Quantitative risk analysis
  • C.Risk avoidance
  • D.Risk acceptance

Why B: Quantitative risk analysis (Option B) is correct because it uses numerical data—such as the likely downtime window, annual incident frequency, and estimated revenue loss per hour—to calculate a monetary value (e.g., Annualized Loss Expectancy). This directly supports the CIO's need to compare mitigation options in dollars and justify a budget request with hard numbers, unlike qualitative methods that rely on subjective ratings.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.