SY0-701 exam dumps

SY0-701 practice question 433 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 433

Single answerRisk management strategies: Transfer , Accept (Exemption , Exception ), Avoid , Mitigate

A healthcare company uses a legacy imaging system that controls MRI machines. The vendor no longer provides security patches, but replacing the system this year would require taking critical equipment offline for months and exceed the approved budget. A recent risk assessment found that the system's unsupported operating system increases the likelihood of compromise. After review, leadership approves continued use of the system for 12 months, documents the business justification, requires annual review, and mandates compensating controls such as network segmentation and restricted administrator access. Which risk management strategy BEST describes leadership's decision regarding the unsupported system?

  1. A

    Risk transfer, because the organization is shifting the operational risk to the MRI vendor

  2. B

    Risk acceptance through an exception, because leadership is formally allowing a known risk for a defined period under documented conditions

  3. C

    Risk avoidance, because the organization is eliminating the risk by isolating the legacy system from the rest of the network

  4. D

    Risk mitigation, because implementing compensating controls means the underlying risk is fully remediated

Show answer and explanation

Correct answer: B

Explanation

The best answer is risk acceptance through an exception. In security governance, organizations sometimes cannot immediately remediate a risk due to operational, financial, or safety constraints. When leadership knowingly allows that risk to continue under documented terms, that is risk acceptance. When the acceptance is limited in scope or time and formally approved outside standard policy requirements, it is commonly handled as an exception. By contrast, an exemption is typically a broader release from a requirement, often based on a role, system class, or long-term business need, rather than a short-term, case-specific allowance. The compensating controls in the scenario, such as segmentation and restricted administrative access, are examples of mitigation measures that reduce residual risk, but they do not change the fact that the organization has chosen to accept the remaining risk temporarily. This aligns with common risk management practices described in frameworks such as NIST SP 800-37 and NIST SP 800-39, where risk responses include accept, avoid, mitigate, and transfer, and where leadership formally authorizes operation with understood residual risk.

  • A. Incorrect.

    Incorrect. Risk transfer means shifting some financial or operational impact to a third party, commonly through insurance, outsourcing, or contractual arrangements. In this scenario, the vendor no longer supports the platform, and the company is not shifting responsibility or impact to another party. Simply continuing to use a vendor product does not constitute transfer.

  • B. Correct.

    Correct. This is risk acceptance in the form of an exception: leadership is knowingly permitting a risk to remain because immediate remediation is not feasible, while documenting the rationale, scope, time limit, and review requirements. The defined 12-month period and approval conditions are key indicators of a formal exception rather than informal acceptance.

  • C. Incorrect.

    Incorrect. Risk avoidance means discontinuing the activity that creates the risk, such as retiring the legacy system, replacing it, or stopping use of the vulnerable process entirely. Network segmentation reduces exposure, but the company is still operating the unsupported system, so the risk is not being avoided.

  • D. Incorrect.

    Incorrect. Risk mitigation reduces likelihood or impact through controls such as segmentation, least privilege, and monitoring, but it does not mean the risk is fully removed. In this scenario, compensating controls are being applied alongside a decision to accept the residual risk for a limited time. The primary management decision described is acceptance by exception, not pure mitigation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam