SY0-701 · Question #588
A systems administrator discovers a system that is no longer receiving support from the vendor. However, this system and its environment are critical to running the business, cannot be modified, and…
The correct answer is B. Accept. Accept is correct because the system cannot be modified, cannot be taken offline, and must remain operational - leaving the organization with no means to eliminate or reduce the risk. Accepting the risk means formally acknowledging it exists and choosing to continue operations…
Question
Options
- AReject
- BAccept
- CTransfer
- DAvoid
How the community answered
(27 responses)- A4% (1)
- B85% (23)
- C4% (1)
- D7% (2)
Explanation
Accept is correct because the system cannot be modified, cannot be taken offline, and must remain operational - leaving the organization with no means to eliminate or reduce the risk. Accepting the risk means formally acknowledging it exists and choosing to continue operations, often with compensating controls like network segmentation or enhanced monitoring.
Reject (A) is a distractor - "reject" is not a recognized risk treatment in standard frameworks (NIST, ISO 27001). Valid options are accept, transfer, avoid, and mitigate.
Transfer (C) is wrong because shifting financial liability (e.g., cyber insurance) doesn't change the operational reality: the unsupported system still runs with the same vulnerabilities, so the technical risk remains.
Avoid (D) is wrong because avoidance requires eliminating the risky activity - but the question explicitly states the system must stay online, making avoidance impossible.
Memory tip: Use the acronym MATA - Mitigate, Avoid, Transfer, Accept. When all other options are blocked (can't modify = can't mitigate, can't shut down = can't avoid, insurance won't fix the problem = transfer is insufficient), you land on Accept by elimination.
Community Discussion
No community discussion yet for this question.