What Constitutes a Treatment Strategy for Continuous Risk?

Which of the following is an example of a treatment strategy for a continuous risk?

  1. Email gateway to block phishing attempts Source Reference Answer
  2. Background checks for new employees
  3. Dual control requirements for wire transfers
  4. Branch protection as part of the CI/CD pipeline

Community Votes

A
57%
D
43%

57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests your capacity to differentiate between persistent operational threats requiring always-on technical safeguards and discrete or lifecycle-specific controls, preventing misapplication of DevSecOps concepts to general risk management scenarios.

This question evaluates your ability to match risk treatment strategies with ongoing, persistent threats. The community consensus identifies email gateways blocking phishing as the strongest example, given the automated and continuous nature of the control against frequently recurring attacks.

Many candidates choose CI/CD branch protection due to the word continuous, but this overlooks that branch protection is a development pipeline safeguard rather than a broad, organization-wide continuous risk treatment like anti-phishing infrastructure.

Community Discussion (5 comments)

MarysSon 👍 1 Selected: A
A is the better answer. Phishing attempts are a continuous risk. Email gateways provide automated and continuous protection. Continuous Integration/Continuous Delivery/Deployment fall under the software development life cycle.
Konversation 👍 1 Selected: D
Again a poor question by CompTIA. All 4 answers are continuous risks and corresponding treatment strategies. A. E-Mails are always a risk. (Phishing) B. New employees are always a security risk, since you don't know them- C. Dual Control is a must in Finance to reduce fraud. D. CI/CD pipeline reduces risks in code. And code is always vulnerable. The only think I can image is, that CompTIA tries to refer to "Integrated Penetration Testing" where they explain this concept related to CI/CD. Sec+ Student Guide . https://informer.io/resources/continuous-penetration-testing Good luck on the exam!
Kamalt 👍 3 Selected: A
CompTIA Security+ Explanation In risk management, a treatment strategy refers to how an organization mitigates, transfers, accepts, or avoids risk. Continuous risks are threats that persist over time and require ongoing security measures. Phishing attacks are a continuous risk because cybercriminals frequently attempt to deceive users via email. An email gateway is a technical control that continuously scans, filters, and blocks malicious emails to reduce phishing attempts. Since phishing is an ongoing (continuous) threat, deploying an email gateway is a proactive treatment strategy to mitigate it. GPT
nocwyn 👍 1 Selected: D
Branch protection in a CI/CD pipeline helps prevent: Unauthorized code changes Introduction of insecure or vulnerable code Supply chain attacks
test_arrow 👍 1 Selected: D
D. Branch protection as part of the CI/CD pipeline Explanation: A continuous risk refers to an ongoing or persistent risk that must be actively managed over time. Branch protection in a CI/CD pipeline helps mitigate continuous risks related to software development, such as unauthorized code changes, vulnerabilities, and misconfigurations. By enforcing rules like required code reviews and automated security checks, organizations continuously manage risks in their development workflow.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding Continuous Risk in CompTIA Security+

In risk management, continuous risks refer to threats that persist over time and require ongoing, automated, or persistent mitigation strategies. Unlike discrete or periodic risks (e.g., annual audits or one-time background checks), continuous risks demand controls that operate without manual intervention to counter ever-evolving attack vectors.

Why Option A is Correct

Email gateways to block phishing attempts perfectly exemplify a continuous risk treatment. Phishing campaigns are relentless, constantly changing, and target users at any time. An email security gateway provides automated, real-time filtering using threat intelligence, URL rewriting, and attachment sandboxing. As noted by community experts, this control operates continuously to mitigate a persistent threat, aligning directly with CompTIA’s emphasis on technical safeguards for ongoing risks.

Why the Other Options Are Incorrect

  • Background checks (B) are a discrete/preventive control applied during hiring. While employee risk is ongoing, the treatment itself is a one-time event, not a continuous monitoring or mitigation strategy.
  • Dual control for wire transfers (C) is a procedural/fraud prevention control. It requires human intervention for each transaction and is designed to catch errors or malicious intent at specific points, rather than operating autonomously against a continuous threat stream.
  • Branch protection in CI/CD (D) is a strong distractor because it operates continuously within software development. However, CompTIA categorizes this under Application Security/SDLC controls rather than general enterprise risk treatment. As community commenters note, while it mitigates ongoing code vulnerabilities, it is scoped to the development pipeline, whereas email gateways address a broader, organization-wide continuous threat vector.

Exam Context & Community Consensus

The split vote (57% A vs. 43% D) highlights how SY0-701 questions sometimes blur lines between operational security and DevSecOps. CompTIA typically expects candidates to prioritize broad, automated technical controls when identifying continuous risk treatments. Phishing remains a top-tier focus area in the exam, making email security the canonical answer for continuous threat mitigation.

Official Reference

Exam Strategy

When you see keywords like continuous, immediately look for controls that operate automatically and persistently (e.g., firewalls, IDS/IPS, email gateways, EDR) rather than procedural or one-time checks. If multiple options seem valid, prioritize the one that addresses a broad, ongoing threat vector over niche or lifecycle-specific implementations unless the question explicitly focuses on software development.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide