SY0-701 exam dumps

SY0-701 practice question 424 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 424

Single answerRisk assessment: Ad hoc , Recurring , One-time , Continuous

A healthcare company is migrating several patient-facing applications to a new cloud platform over the next 12 months. The security manager must choose the most appropriate risk assessment approach for each situation: a formal review before the first production migration, additional reviews when a major architecture change occurs, and ongoing visibility into newly introduced vulnerabilities and control drift after go-live. Which approach BEST meets these requirements?

  1. A

    Use a one-time assessment before migration, ad hoc assessments only if an incident occurs, and no further review after deployment because the initial assessment established the baseline.

  2. B

    Use a recurring assessment every three years for all phases of the migration and avoid additional assessments during changes to maintain consistency.

  3. C

    Use a one-time assessment before the initial migration, ad hoc assessments when major architecture changes occur, and continuous assessment after go-live to monitor risk exposure.

  4. D

    Use only continuous assessment from the beginning of the project and skip the initial formal review because cloud environments change too quickly for point-in-time assessments to be useful.

Show answer and explanation

Correct answer: C

Explanation

The best answer is the combination of one-time, ad hoc, and continuous assessments because the scenario includes three distinct needs: an initial formal review, event-driven reviews for significant changes, and ongoing monitoring after deployment. In Security+ terms, a one-time risk assessment is commonly used for a specific event or project, such as a major migration. Ad hoc assessments are unscheduled and performed as needed, often when substantial changes, unusual conditions, or emerging concerns arise. Continuous assessment supports ongoing awareness of risk by identifying new vulnerabilities, control failures, and environmental changes in near real time. Recurring assessments are still useful in many organizations, such as annual or quarterly risk reviews, but they do not fully satisfy this scenario by themselves. This approach aligns with common risk management practices described in NIST guidance, including NIST SP 800-30 for risk assessments and NIST SP 800-137 for information security continuous monitoring, which emphasize that risk management should include both point-in-time assessments and ongoing monitoring based on organizational needs and system changes.

  • A. Incorrect.

    This is incorrect because it underestimates the need for ongoing risk management. A one-time assessment is appropriate before the initial migration, but relying on ad hoc reviews only after incidents is reactive rather than risk-based. It also ignores the need for continuous monitoring after deployment, which is critical in cloud environments where vulnerabilities, misconfigurations, and control drift can emerge over time.

  • B. Incorrect.

    This is incorrect because a recurring assessment on a fixed long-term schedule alone does not address major changes or provide ongoing visibility. Recurring assessments are useful when risk reviews need to happen at defined intervals, such as quarterly or annually, but waiting years during an active migration would leave significant gaps. It also fails to account for event-driven reviews when the architecture materially changes.

  • C. Correct.

    This is correct because it matches the scenario requirements to the appropriate assessment types. A one-time assessment is appropriate before the first production migration to establish a baseline understanding of risk. Ad hoc assessments are suitable when major architecture changes occur outside the normal schedule and require targeted review. Continuous assessment after go-live provides ongoing visibility into vulnerabilities, configuration drift, and changing threat conditions, which is especially important in dynamic cloud environments.

  • D. Incorrect.

    This is incorrect because continuous assessment is valuable but does not replace the need for an initial formal risk assessment. A point-in-time review before production migration helps identify design issues, regulatory concerns, and control gaps before exposure increases. The misconception here is that continuous monitoring alone is sufficient; in practice, organizations benefit from both initial and ongoing assessment activities.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam