Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

The CIO wants to compare two mitigation options for a payment system outage and justify the budget request in dollars. The team already knows the likely downtime window, annual incident frequency, and estimated revenue loss per hour. Which approach would best support the decision?

⚠ Common exam trap

It's easy for candidates to confuse qualitative risk analysis with quantitative risk analysis, assuming that any risk assessment involving 'analysis' can produce dollar figures, but qualitative methods only yield ordinal rankings, not monetary values.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Quantitative risk analysis

Quantitative risk analysis (Option B) is correct because it uses numerical data—such as the likely downtime window, annual incident frequency, and estimated revenue loss per hour—to calculate a monetary value (e.g., Annualized Loss Expectancy). This directly supports the CIO's need to compare mitigation options in dollars and justify a budget request with hard numbers, unlike qualitative methods that rely on subjective ratings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Qualitative risk analysis

    Why it's wrong here

    Qualitative risk analysis ranks risks using ordinal scales such as high, medium, or low based on subjective judgment. While it helps prioritize risks, it does not assign monetary values to potential losses, making it impossible to directly compare the cost-effectiveness of two mitigation options in dollar terms for budget justification.

  • Quantitative risk analysis

    Why this is correct

    Quantitative risk analysis uses measurable values like threat frequency, downtime, and financial loss to calculate metrics such as Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE). This approach enables a direct monetary comparison of mitigation alternatives, supplying the cost-benefit data the CIO needs to justify spending in budget requests.

  • Risk avoidance

    Why it's wrong here

    Risk avoidance involves eliminating the risk entirely by discontinuing the payment system, which is a business strategy decision, not a mitigation option. It does not help compare two controls because it stops the activity altogether, whereas the CIO wants to evaluate ways to continue operations while reducing risk.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance is the formal decision to tolerate a risk without implementing controls, often documenting the rationale and residual risk. It provides no analysis of potential financial losses or comparative costs of different mitigations, so it cannot support a budget decision between two alternative controls.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.