SY0-701 exam dumps

SY0-701 practice question 434 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 434

Single answerRisk management strategies: Transfer , Accept (Exemption , Exception ), Avoid , Mitigate

A healthcare company wants to launch a patient outreach web portal before the end of the quarter. During the risk assessment, the security team identifies that the portal depends on a legacy third-party plug-in with a known vulnerability. The vendor has announced a fix, but it will not be available for 90 days. Replacing the plug-in now would delay the launch and break a required business workflow. The CIO formally documents that the portal may go live for 60 days only if compensating controls are implemented, including web application firewall rules, enhanced logging, and daily vulnerability scans. After 60 days, the exception must be reviewed again. Which risk management strategy BEST describes the CIO's decision?

  1. A

    Transfer the risk by purchasing cyber insurance for the portal

  2. B

    Accept the risk through a time-bound exception with compensating controls

  3. C

    Avoid the risk by canceling the portal launch until the plug-in is replaced

  4. D

    Mitigate the risk by eliminating the vulnerable plug-in before production release

Show answer and explanation

Correct answer: B

Explanation

The best answer is accept the risk through a time-bound exception with compensating controls. In risk management, accept means the organization acknowledges a risk and chooses to tolerate it, usually because the cost or operational impact of immediate remediation outweighs the current business need. An exception or exemption is a formal mechanism used when a policy or required control cannot be met under specific circumstances; strong governance requires documentation, defined scope, expiration or review dates, and management approval. Compensating controls such as WAF rules, logging, and frequent scans reduce exposure, but they do not remove the underlying vulnerability. That is why the scenario is not best classified as avoid or fully mitigate. It is also not transfer, because insurance or contractual arrangements do not match the actual decision made. This aligns with common guidance in risk management frameworks such as NIST SP 800-37 and NIST SP 800-39, which distinguish accepting residual risk from applying controls to reduce risk.

  • A. Incorrect.

    This is incorrect because transfer shifts some financial impact of a risk to another party, such as through insurance or outsourcing, but it does not describe the CIO's documented approval to operate temporarily with the known issue. Cyber insurance may help with losses after an incident, but it does not itself authorize continued operation of a vulnerable system.

  • B. Correct.

    This is correct because the organization is knowingly proceeding with a documented, limited-duration acceptance of risk under defined conditions. The language about a 60-day approval, formal documentation, and required compensating controls aligns with a risk acceptance exception rather than simple informal acceptance. In practice, exemptions and exceptions are commonly used when a control cannot be fully met for a specific period or business need, provided leadership approves the residual risk.

  • C. Incorrect.

    This is incorrect because avoidance means stopping the activity that creates the risk, such as delaying or canceling the launch, removing the business process, or deciding not to deploy the portal at all. The scenario explicitly states the CIO approved going live rather than canceling or postponing the initiative.

  • D. Incorrect.

    This is incorrect because mitigation reduces risk likelihood or impact by implementing safeguards, and the compensating controls do mitigate risk to some extent. However, the decision being asked about is the CIO's formal choice to proceed despite the remaining residual risk for a limited period. Since the vulnerable plug-in is not being eliminated before launch, the primary strategy described is accepted risk through an exception, not full mitigation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam