SY0-701 exam dumps

SY0-701 practice question 383 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 383

Single answerOther considerations: Complexity , Cost , Single point of failure , Technical debt , Ongoing supportability

A mid-sized company is replacing its legacy remote access solution. The security team proposes a highly customized VPN platform that requires several internally developed scripts for user provisioning, certificate renewal, and log parsing. The platform is less expensive to purchase than a managed alternative, but only one senior engineer fully understands the implementation. During the design review, the CISO asks which concern should be prioritized because it creates the greatest long-term security risk if the company adopts this solution as designed. Which of the following is the BEST answer?

  1. A

    The solution introduces technical debt and an ongoing supportability problem because critical security operations depend on custom processes and one specialized administrator

  2. B

    The solution should be selected because the lower upfront cost outweighs the risk of relying on custom scripts for security administration

  3. C

    The main concern is complexity alone, because complex systems are inherently insecure even when they are well documented and supported

  4. D

    The primary issue is that certificate-based VPNs cannot be secured unless the organization eliminates all automation

Show answer and explanation

Correct answer: A

Explanation

The best answer is the option identifying technical debt and ongoing supportability risk driven by custom security processes and reliance on a single administrator. In Security+ design scenarios, candidates are expected to evaluate more than just technical capability or purchase price. They must also assess complexity, cost over time, single points of failure, technical debt, and the ability to sustain secure operations. A solution that depends on custom scripts for core security functions such as user provisioning, certificate renewal, and log parsing can create maintenance challenges, especially when institutional knowledge resides with only one engineer. That combination increases the risk of missed renewals, failed onboarding/offboarding, delayed patching, incomplete logging, and slow incident response. Industry best practices from sources such as NIST emphasize maintainability, documented procedures, least dependence on individual personnel, and lifecycle management when selecting and operating security controls. From a risk management perspective, total cost of ownership and operational resilience are often more important than lower upfront cost.

  • A. Correct.

    Correct. This scenario highlights multiple related concerns: technical debt, ongoing supportability, and a single point of failure. The custom scripts increase operational fragility, make troubleshooting and upgrades harder, and can break silently over time. Depending on one senior engineer for provisioning, certificate management, and log handling creates a knowledge concentration risk. In practice, this becomes a security issue when patching, incident response, onboarding/offboarding, and certificate renewal are delayed or performed incorrectly because the environment is difficult to maintain.

  • B. Incorrect.

    Incorrect. Lower upfront cost is only one factor in a security architecture decision. A cheaper purchase price can be offset by higher lifecycle costs, increased operational risk, and maintenance burden. In this case, the hidden cost of maintaining custom scripts and dependence on one expert can increase the likelihood of outages, misconfigurations, and delayed security updates. This option reflects the common mistake of focusing on acquisition cost instead of total cost of ownership and risk.

  • C. Incorrect.

    Incorrect. Complexity is a valid concern, but saying complexity alone is the main issue is too narrow and overstates the principle. Complex systems are not automatically insecure if they are properly designed, documented, monitored, and supported. The larger issue in this scenario is not just complexity; it is that complexity is paired with custom tooling, weak maintainability, and reliance on a single individual, which together create long-term security and availability risk.

  • D. Incorrect.

    Incorrect. Certificate-based VPNs are commonly used and can be very secure. Automation for certificate lifecycle management and provisioning is also common and often recommended when implemented properly. The problem here is not automation itself, but brittle, internally developed automation that lacks resilience, documentation, and broad support. This option reflects a misconception that manual processes are inherently safer than automated ones.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam