220-1102 Question 744
Single answerNon-disclosure agreement (NDA)/mutual non-disclosure agreement (MNDA)A support technician is preparing to work with a third-party software vendor to troubleshoot crashes in a line-of-business application. During the session, the technician may need to share internal log files, screenshots, and configuration details from the company's systems. The vendor will also provide proprietary diagnostic tools and documentation that the company must not share externally. Which agreement should be put in place before any information is exchanged?
- A
A mutual non-disclosure agreement (MNDA), because both the company and the vendor will be sharing confidential information
- B
A non-disclosure agreement (NDA), because only the company needs to protect its internal system information
- C
An acceptable use policy (AUP), because it defines how the vendor can use company systems during troubleshooting
- D
A service-level agreement (SLA), because it sets confidentiality rules for diagnostic data shared between both parties
Show answer and explanation
Correct answer: A
Explanation
The best answer is a mutual non-disclosure agreement (MNDA) because both parties in the scenario are sharing confidential information. In IT support and vendor coordination, NDAs are commonly used to protect sensitive data such as system logs, network details, screenshots, customer information, and internal configurations. When only one side is disclosing protected information, a one-way NDA may be sufficient. When both sides are disclosing confidential material, such as a company sharing internal data and a vendor sharing proprietary tools or documentation, an MNDA is the correct choice. This aligns with standard business and legal best practices for handling confidential information before troubleshooting, escalation, or third-party collaboration begins. Related documents like AUPs and SLAs may still be used in the overall relationship, but they serve different purposes and do not replace a confidentiality agreement.
- A. Correct.
Correct. A mutual non-disclosure agreement (MNDA) is appropriate when both parties will disclose confidential information to each other. In this scenario, the company is sharing internal logs and configuration details, while the vendor is sharing proprietary tools and documentation. An MNDA is specifically designed to protect both sides.
- B. Incorrect.
Incorrect. A standard NDA is often used when only one party is disclosing confidential information. Someone might choose this because the company's logs and screenshots are clearly sensitive, but the scenario also states that the vendor will share proprietary materials. Since confidentiality obligations apply in both directions, an MNDA is the better choice.
- C. Incorrect.
Incorrect. An acceptable use policy (AUP) defines permitted and prohibited use of systems, networks, or devices. While an AUP may be relevant if the vendor is granted access to company resources, it does not replace a confidentiality agreement governing the exchange of sensitive business information.
- D. Incorrect.
Incorrect. A service-level agreement (SLA) defines expectations for service performance, such as response times, uptime, and support commitments. Although an SLA may exist with a vendor, it is not the primary document used to establish mutual confidentiality obligations for shared proprietary information.