SY0-701 exam dumps

SY0-701 practice question 276 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 276

Single answerAcquisition/procurement process

A healthcare company is acquiring a cloud-based document management platform to store contracts, HR files, and internal audit records. The security team is concerned that the vendor may not meet the organization's regulatory and security requirements after the contract is signed. The procurement manager wants to reduce this risk before purchase and ensure the vendor can be held accountable for security controls. Which action should the company take FIRST during the acquisition/procurement process?

  1. A

    Require the vendor to sign an agreement that includes security requirements, right-to-audit language, and breach notification timelines before finalizing the purchase

  2. B

    Deploy a web application firewall in front of the vendor's service after implementation to compensate for any provider security gaps

  3. C

    Wait until the annual risk assessment to determine whether the vendor's controls are sufficient for regulated data

  4. D

    Rely on the vendor's marketing materials and pricing sheet to confirm compliance with security and privacy obligations

Show answer and explanation

Correct answer: A

Explanation

This question focuses on integrating security into the acquisition/procurement process. When procuring a third-party product or service, especially one that will store regulated or sensitive data, the organization should establish security requirements before the purchase is finalized. These requirements are typically documented in procurement artifacts and enforced through contracts, statements of work, service agreements, and vendor risk management processes. Important clauses may include minimum security controls, compliance obligations, data ownership, incident and breach notification timelines, audit rights, logging expectations, and termination/data return requirements. This aligns with common industry guidance on supplier and third-party risk management, such as NIST SP 800-161 for cyber supply chain risk management and NIST SP 800-53 controls related to external systems and services. In Security+ terms, the best answer is the one that embeds security requirements into the procurement process early, rather than relying on technical workarounds or post-purchase review.

  • A. Correct.

    Correct. In the acquisition/procurement process, security requirements should be defined and contractually enforced before purchase. This includes security clauses, service-level expectations, breach notification requirements, data handling obligations, and right-to-audit provisions. Establishing these requirements up front is a core part of vendor due diligence and supply chain risk management, especially when regulated or sensitive data will be handled.

  • B. Incorrect.

    Incorrect. A web application firewall may provide some compensating protection for certain web-based threats, but it does not address core procurement risk. It cannot replace contractual controls, due diligence, or assurance that the vendor meets regulatory, privacy, and security obligations. This option reflects the misconception that technical controls alone can solve third-party governance issues.

  • C. Incorrect.

    Incorrect. Waiting until the annual risk assessment is too late because the organization may already be contractually committed to a vendor that does not meet requirements. Procurement decisions involving sensitive data should include security review and vendor risk evaluation before acquisition, not after deployment.

  • D. Incorrect.

    Incorrect. Marketing materials and pricing sheets are not authoritative evidence of security compliance or operational capability. Procurement best practice requires formal documentation such as contracts, security questionnaires, attestations, reports, and defined legal obligations. This option reflects the common mistake of confusing sales claims with validated security assurance.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam