SY0-701 Security Program Management and Oversight Practice Question
Leadership wants to compare two controls for protecting a customer portal. Option A costs $40,000 and reduces annual loss expectancy from $120,000 to $30,000. Option B costs $15,000 and reduces annual loss expectancy to $70,000. Which analysis method best supports this decision?
⚠ Common exam trap
It's easy for candidates to choose qualitative risk analysis because it is simpler and more common, but the presence of specific monetary values in the question explicitly requires quantitative analysis to make a data-driven comparison.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Quantitative risk analysis
Quantitative risk analysis uses monetary values and numerical data to calculate risk, making it the best method to compare the cost-benefit of Option A (ALE reduction from $120,000 to $30,000 with a $40,000 cost) versus Option B (ALE reduction to $70,000 with a $15,000 cost). By computing the annualized loss expectancy (ALE) and comparing the cost of each control against the reduction in expected loss, leadership can determine which option provides a better return on investment. This approach directly supports the decision because it provides objective, dollar-based metrics for comparison.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Qualitative risk analysis
Why it's wrong here
Qualitative risk analysis categorizes risks on subjective scales such as high, medium, or low, often derived from expert judgment or ordinal ratings. Without assigning monetary values to potential losses or control costs, it cannot produce a direct dollar-denominated cost-benefit comparison of two controls. While useful for prioritizing risks quickly, it lacks the numeric precision needed for a financial side-by-side evaluation.
- ✓
Quantitative risk analysis
Why this is correct
Quantitative risk analysis calculates risk in monetary terms using methods such as Single Loss Expectancy (SLE), Annualized Rate of Occurrence (ARO), and Annualized Loss Expectancy (ALE). By comparing the ALE reduction from a control against its annual cost, it yields metrics like Return on Investment (ROI) or residual risk, enabling a direct financial cost-benefit comparison. Leadership's request to compare controls financially points to this approach because it converts threat and mitigation data into dollar figures.
- ✗
Business impact analysis
Why it's wrong here
A Business Impact Analysis (BIA) identifies critical business functions, dependencies, and the operational impact of disruptions, often producing recovery time objectives (RTOs) and recovery point objectives (RPOs). Its purpose is to prioritize continuity and recovery efforts, not to evaluate the cost-effectiveness of specific security controls. While a BIA may inform control selection, it does not itself compare the financial costs and benefits of alternative safeguards.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is a risk treatment decision in which an organization formally acknowledges a risk and chooses to tolerate it without further mitigation. It is not an analysis method; rather, it is the outcome of a decision-making process that follows risk assessment. Financial comparison of control options would occur before a treatment decision, as part of risk analysis, not be replaced by the decision to accept the risk.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Quantitative risk analysis
Quantitative risk analysis is a structured process that uses numerical data and statistical methods to calculate the potential financial impact of risks on an organization's assets and projects.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. The CIO wants to compare two mitigation options for a payment system outage and justify the budget request in dollars. The team already knows the likely downtime window, annual incident frequency, and estimated revenue loss per hour. Which approach would best support the decision?
medium- A.Qualitative risk analysis
- ✓ B.Quantitative risk analysis
- C.Risk avoidance
- D.Risk acceptance
Why B: Quantitative risk analysis (Option B) is correct because it uses numerical data—such as the likely downtime window, annual incident frequency, and estimated revenue loss per hour—to calculate a monetary value (e.g., Annualized Loss Expectancy). This directly supports the CIO's need to compare mitigation options in dollars and justify a budget request with hard numbers, unlike qualitative methods that rely on subjective ratings.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.