What Constitutes a Treatment Strategy for Continuous Risk?
Which of the following is an example of a treatment strategy for a continuous risk?
Community Votes
57% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests your capacity to differentiate between persistent operational threats requiring always-on technical safeguards and discrete or lifecycle-specific controls, preventing misapplication of DevSecOps concepts to general risk management scenarios.
This question evaluates your ability to match risk treatment strategies with ongoing, persistent threats. The community consensus identifies email gateways blocking phishing as the strongest example, given the automated and continuous nature of the control against frequently recurring attacks.
Many candidates choose CI/CD branch protection due to the word continuous, but this overlooks that branch protection is a development pipeline safeguard rather than a broad, organization-wide continuous risk treatment like anti-phishing infrastructure.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding Continuous Risk in CompTIA Security+
In risk management, continuous risks refer to threats that persist over time and require ongoing, automated, or persistent mitigation strategies. Unlike discrete or periodic risks (e.g., annual audits or one-time background checks), continuous risks demand controls that operate without manual intervention to counter ever-evolving attack vectors.Why Option A is Correct
Email gateways to block phishing attempts perfectly exemplify a continuous risk treatment. Phishing campaigns are relentless, constantly changing, and target users at any time. An email security gateway provides automated, real-time filtering using threat intelligence, URL rewriting, and attachment sandboxing. As noted by community experts, this control operates continuously to mitigate a persistent threat, aligning directly with CompTIA’s emphasis on technical safeguards for ongoing risks.Why the Other Options Are Incorrect
- Background checks (B) are a discrete/preventive control applied during hiring. While employee risk is ongoing, the treatment itself is a one-time event, not a continuous monitoring or mitigation strategy.
- Dual control for wire transfers (C) is a procedural/fraud prevention control. It requires human intervention for each transaction and is designed to catch errors or malicious intent at specific points, rather than operating autonomously against a continuous threat stream.
- Branch protection in CI/CD (D) is a strong distractor because it operates continuously within software development. However, CompTIA categorizes this under Application Security/SDLC controls rather than general enterprise risk treatment. As community commenters note, while it mitigates ongoing code vulnerabilities, it is scoped to the development pipeline, whereas email gateways address a broader, organization-wide continuous threat vector.
Exam Context & Community Consensus
The split vote (57% A vs. 43% D) highlights how SY0-701 questions sometimes blur lines between operational security and DevSecOps. CompTIA typically expects candidates to prioritize broad, automated technical controls when identifying continuous risk treatments. Phishing remains a top-tier focus area in the exam, making email security the canonical answer for continuous threat mitigation.Official Reference
- https://www.comptia.org/content/guides/security-sy0-701-study-guide
- NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments (Continuous Monitoring)
- CompTIA SY0-701 Objective 1.3: Threats, Vulnerabilities, and Mitigations
Exam Strategy
When you see keywords like continuous, immediately look for controls that operate automatically and persistently (e.g., firewalls, IDS/IPS, email gateways, EDR) rather than procedural or one-time checks. If multiple options seem valid, prioritize the one that addresses a broad, ongoing threat vector over niche or lifecycle-specific implementations unless the question explicitly focuses on software development.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →