SY0-701 exam dumps

SY0-701 practice question 277 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 277

Single answerAcquisition/procurement process

A company is procuring a cloud-based document management platform to store contracts, customer records, and internal HR files. The security manager is concerned that a low-cost vendor may not meet the organization's regulatory and security requirements. During the acquisition process, which action should the security manager take FIRST to reduce the risk of purchasing a solution that fails to meet security needs?

  1. A

    Require the vendor to complete a security and compliance questionnaire aligned to the organization's requirements before contract award

  2. B

    Rely on the vendor's marketing materials and select the product with the lowest total cost of ownership

  3. C

    Purchase the platform first and plan to add compensating controls after deployment if gaps are discovered

  4. D

    Approve the purchase only after the help desk confirms the product is easy for employees to use

Show answer and explanation

Correct answer: A

Explanation

Security should be embedded early in the acquisition/procurement lifecycle. Before awarding a contract, organizations should define security requirements, assess vendor responses, and verify that the product aligns with data sensitivity, legal obligations, and internal policy. Common best practices include issuing security requirements in the RFP or procurement package, using vendor security questionnaires, reviewing independent attestations where appropriate, evaluating contract language such as breach notification and right-to-audit terms, and ensuring the solution supports required controls. This approach aligns with third-party risk management and secure procurement principles reflected in common frameworks and guidance such as NIST SP 800-161 for supply chain risk management and NIST SP 800-53 control families related to acquisition and system services.

  • A. Correct.

    Correct. In the acquisition/procurement process, security requirements should be defined and evaluated before purchase. A structured security and compliance questionnaire, often tied to internal standards, regulatory obligations, data classification, and third-party risk management processes, helps determine whether the vendor can meet required controls such as encryption, logging, retention, identity federation, incident response support, and regulatory commitments. This is the best first step because it integrates security into procurement rather than treating it as an afterthought.

  • B. Incorrect.

    Incorrect. Cost is an important procurement factor, but selecting a vendor based primarily on marketing claims and lowest cost creates significant risk. Marketing materials are not a substitute for due diligence, documented control validation, or contractual review. This option reflects a common mistake of prioritizing price over security, privacy, and compliance requirements.

  • C. Incorrect.

    Incorrect. Buying first and planning to remediate later is poor procurement practice and can lead to expensive rework, failed audits, contractual lock-in, or inability to meet regulatory obligations. While compensating controls may sometimes be used, they should not replace pre-purchase security assessment during acquisition.

  • D. Incorrect.

    Incorrect. Usability and operational support matter, but help desk feedback does not address whether the product satisfies security, privacy, legal, or compliance requirements. This option is plausible because ease of use influences adoption, but it is not the first action to reduce procurement risk in a security-sensitive acquisition.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam