Courseiva
Security Program Management and OversighteasyMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

The executive team wants to know which payment services are most critical and how long each can be offline before the business is seriously harmed. Which activity should security support?

⚠ Common exam trap

Many candidates confuse a tabletop exercise (a reactive drill) with a business impact analysis (a proactive assessment), leading them to choose Option A because it involves leadership discussion, while missing that the BIA is the only activity that formally identifies critical functions and quantifies outage impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A business impact analysis, because it identifies critical functions and outage impact.

A business impact analysis (BIA) is the correct activity because it systematically identifies critical business functions—such as payment processing—and quantifies the maximum tolerable downtime (MTD) and recovery time objectives (RTO). This directly answers the executive team's question about which payment services are most critical and how long each can be offline before causing serious harm.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A tabletop exercise, because leaders are practicing response discussions.

    Why it's wrong here

    A tabletop exercise is a discussion-based session where leadership and response teams rehearse decision-making and coordination during a simulated incident. It validates roles, communication, and response procedures, but it is not an impact analysis tool. It cannot quantify the operational or financial consequences of losing a payment service, nor does it produce recovery time objectives or acceptable downtime thresholds. Thus, while useful for practicing responses, it does not directly answer which services are most critical to the business.

  • A business impact analysis, because it identifies critical functions and outage impact.

    Why this is correct

    A business impact analysis helps determine which services matter most, what impact downtime causes, and how long outages can last before causing serious business harm. It is the right activity when leaders need prioritization and recovery expectations.

  • Incident containment, because the goal is to stop an active breach.

    Why it's wrong here

    Incident containment is a reactive, time-sensitive action taken during an active security breach to isolate affected systems and limit lateral movement. It occurs after an incident has already been detected, so it does not inform pre-incident planning priorities or outage tolerances. The executive team's question is about proactive business impact assessment, not about executing an emergency response. Containment procedures are guided by an existing incident response plan, which is typically developed from a business impact analysis, not the other way around.

  • Vulnerability scanning, because it finds weaknesses in systems.

    Why it's wrong here

    Vulnerability scanning is a technical security control that identifies known weaknesses, missing patches, misconfigurations, and exposure to common exploits in systems and applications. It evaluates the security posture of infrastructure, but it does not consider the criticality of a business function or the financial, legal, or operational impact of its unavailability. For example, a scan may reveal a vulnerability on a payment gateway, but it cannot determine how long that gateway can be down before the business suffers severe harm. That determination requires a business impact analysis, which maps services to their supporting assets and establishes recovery priorities.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.