SY0-701 exam dumps

SY0-701 practice question 154 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 154

Single answerThird-party vendors

A healthcare company is onboarding a third-party billing vendor that will process insurance claims and store patient data in the vendor's cloud platform. The security administrator is concerned about reducing organizational risk before any protected health information is shared. Which action should the administrator take FIRST?

  1. A

    Require the vendor to complete a security and compliance assessment, including a review of contractual requirements such as data handling, incident notification, and right-to-audit clauses

  2. B

    Deploy the vendor's application immediately and rely on the cyber insurance policy to offset any losses from a breach

  3. C

    Allow the vendor to connect after verifying that its employees have signed acceptable use policies

  4. D

    Share a limited set of production patient records first and monitor for misuse before signing a formal agreement

Show answer and explanation

Correct answer: A

Explanation

The best first step is to conduct a formal third-party/vendor risk assessment and ensure the contract includes clear security and compliance requirements before any sensitive data is shared. In practice, organizations use due diligence questionnaires, review independent audit reports when available, validate regulatory alignment, and define obligations in the agreement. Important contractual elements often include data ownership, minimum security controls, incident reporting timelines, audit rights, subcontractor restrictions, and secure data return or destruction at termination. In regulated environments such as healthcare, this approach supports compliance expectations around protecting sensitive information and is consistent with common third-party risk management practices described by sources such as NIST guidance on supply chain and cybersecurity risk management, as well as standard contractual governance controls used in security programs.

  • A. Correct.

    Correct. Before sharing sensitive data with a third-party vendor, the organization should perform due diligence through a vendor risk assessment and ensure the contract addresses security obligations. This commonly includes reviewing security controls, compliance status, data retention and disposal requirements, breach notification timelines, service-level expectations, and audit rights. For a healthcare context, this aligns with third-party risk management best practices and supports legal and regulatory requirements before protected health information is disclosed.

  • B. Incorrect.

    Incorrect. Cyber insurance can help with financial recovery, but it is not a substitute for vendor due diligence or contractual security controls. Relying on insurance before assessing the vendor leaves the organization exposed to preventable operational, legal, and compliance risk.

  • C. Incorrect.

    Incorrect. Employee acceptable use policies at the vendor may be useful, but they do not provide sufficient assurance that the vendor's organization has appropriate technical, administrative, and contractual safeguards in place. This is too narrow and does not address broader third-party risk.

  • D. Incorrect.

    Incorrect. Sharing production patient data before a formal agreement and security review is a serious mistake. Even a limited data set can create compliance and privacy exposure. Monitoring after disclosure does not replace pre-engagement assessment, data protection terms, and approval processes.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam