SY0-701 exam dumps

SY0-701 practice question 421 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 421

Single answerRisk identification

A healthcare company is preparing to deploy a new internet-facing patient scheduling portal. During a planning meeting, the security analyst is asked to identify risks before the system goes live. The analyst learns that the web server will be placed in a DMZ, the application will process protected health information (PHI), one third-party library has several recently disclosed vulnerabilities, and the business requires 24/7 availability. Which of the following BEST represents a risk that should be documented during risk identification?

  1. A

    The third-party library contains known vulnerabilities that could be exploited to expose PHI through the public-facing portal

  2. B

    The organization should purchase cyber insurance before the portal is launched

  3. C

    The web server will be installed in a DMZ to reduce direct exposure to the internal network

  4. D

    The business owner expects the portal to improve patient satisfaction and reduce call center volume

Show answer and explanation

Correct answer: A

Explanation

The best answer is the known vulnerable third-party library because risk identification is the process of finding and documenting threats, vulnerabilities, and conditions that could affect organizational assets. In this scenario, the combination of a public-facing application, sensitive regulated data (PHI), known software vulnerabilities, and high availability requirements creates a concrete security risk that should be recorded in the risk register. CompTIA Security+ expects candidates to distinguish among risk identification, assessment, and treatment. A control such as a DMZ is part of mitigation, while cyber insurance is a transfer strategy. Business benefits are not risks. This approach aligns with common guidance from NIST risk management practices, such as NIST SP 800-30, which emphasizes identifying threat sources, vulnerabilities, likelihood, and impact to organizational assets.

  • A. Correct.

    Correct. Risk identification focuses on recognizing conditions that could negatively affect confidentiality, integrity, or availability. A vulnerable third-party library used by an internet-facing application that handles PHI is a clear, identifiable risk because it creates a realistic path for compromise and data exposure. This ties together an asset (PHI and the portal), a vulnerability (known flaws in the library), and a threat event (external exploitation).

  • B. Incorrect.

    Incorrect. Purchasing cyber insurance is a risk treatment or risk transfer decision, not a risk itself. During risk identification, the analyst should first document the actual exposure or condition that could cause harm. Insurance may later be considered during risk response planning, but it does not represent the identified risk.

  • C. Incorrect.

    Incorrect. Placing the web server in a DMZ is a security control intended to reduce risk, not a risk that should be documented. A common mistake is confusing an implemented safeguard with the underlying risk. The DMZ may help limit impact from compromise, but it is not itself a negative condition.

  • D. Incorrect.

    Incorrect. This is a business objective or expected benefit, not a risk. Risk identification is concerned with potential adverse events or weaknesses. Improved patient satisfaction and lower call volume may be relevant to business justification, but they do not describe a security risk.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam