SY0-701 exam dumps

SY0-701 practice question 423 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 423

Single answerRisk assessment: Ad hoc , Recurring , One-time , Continuous

A healthcare company is migrating several patient-facing applications from an on-premises data center to a cloud platform over the next 18 months. The security manager must ensure risks introduced by configuration drift, new integrations, and frequent deployment changes are identified throughout the migration rather than only at major project milestones. Which type of risk assessment approach best meets this requirement?

  1. A

    Ad hoc risk assessment

  2. B

    Recurring risk assessment

  3. C

    One-time risk assessment

  4. D

    Continuous risk assessment

Show answer and explanation

Correct answer: D

Explanation

The best answer is continuous risk assessment because the scenario emphasizes ongoing change over an extended period. Continuous assessment aligns with modern security practices for dynamic environments, especially cloud and DevOps-based operations, where risk posture can change quickly due to code releases, infrastructure changes, identity modifications, and new third-party connections. By contrast, one-time assessments are point-in-time, recurring assessments are periodic, and ad hoc assessments are unscheduled and reactive. Security best practices from sources such as NIST SP 800-37 (Risk Management Framework) and NIST SP 800-137 (Information Security Continuous Monitoring) support ongoing assessment and monitoring for systems with changing risk conditions. In practice, continuous risk assessment helps organizations detect issues like misconfigurations, unapproved changes, and emerging exposure before the next scheduled review.

  • A. Incorrect.

    Ad hoc risk assessments are performed as needed, often in response to a specific event, concern, or unexpected change. While useful for emerging issues, they are not designed to provide ongoing visibility throughout a long, dynamic migration with frequent changes.

  • B. Incorrect.

    Recurring risk assessments are scheduled at regular intervals, such as quarterly or annually. This approach is useful for periodic review, but it may miss risks introduced between assessment cycles in an environment with constant cloud configuration changes and frequent deployments.

  • C. Incorrect.

    One-time risk assessments are typically performed for a single event, project phase, or point-in-time requirement, such as before a major system launch. This would not adequately address ongoing risk introduced over an 18-month migration with continuous updates.

  • D. Correct.

    Continuous risk assessment is correct because it is intended for environments where risks evolve rapidly and need ongoing evaluation. In a cloud migration with frequent deployments, integration changes, and possible configuration drift, continuous assessment provides the most effective way to identify and respond to risk as conditions change.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam