SY0-701 Security Program Management and Oversight Practice Question
The CIO wants to compare two mitigation options for a payment system outage and justify the budget request in dollars. The team already knows the likely downtime window, annual incident frequency, and estimated revenue loss per hour. Which approach would best support the decision?
⚠ Common exam trap
It's easy for candidates to confuse qualitative risk analysis with quantitative risk analysis, assuming that any risk assessment involving 'analysis' can produce dollar figures, but qualitative methods only yield ordinal rankings, not monetary values.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Quantitative risk analysis
Quantitative risk analysis (Option B) is correct because it uses numerical data—such as the likely downtime window, annual incident frequency, and estimated revenue loss per hour—to calculate a monetary value (e.g., Annualized Loss Expectancy). This directly supports the CIO's need to compare mitigation options in dollars and justify a budget request with hard numbers, unlike qualitative methods that rely on subjective ratings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Qualitative risk analysis
Why it's wrong here
Qualitative risk analysis ranks risks using ordinal scales such as high, medium, or low based on subjective judgment. While it helps prioritize risks, it does not assign monetary values to potential losses, making it impossible to directly compare the cost-effectiveness of two mitigation options in dollar terms for budget justification.
- ✓
Quantitative risk analysis
Why this is correct
Quantitative risk analysis uses measurable values like threat frequency, downtime, and financial loss to calculate metrics such as Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE). This approach enables a direct monetary comparison of mitigation alternatives, supplying the cost-benefit data the CIO needs to justify spending in budget requests.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance involves eliminating the risk entirely by discontinuing the payment system, which is a business strategy decision, not a mitigation option. It does not help compare two controls because it stops the activity altogether, whereas the CIO wants to evaluate ways to continue operations while reducing risk.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is the formal decision to tolerate a risk without implementing controls, often documenting the rationale and residual risk. It provides no analysis of potential financial losses or comparative costs of different mitigations, so it cannot support a budget decision between two alternative controls.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Quantitative risk analysis
Quantitative risk analysis is a structured process that uses numerical data and statistical methods to calculate the potential financial impact of risks on an organization's assets and projects.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.