SY0-701 Question 277
Single answerAcquisition/procurement processA company is procuring a cloud-based document management platform to store contracts, customer records, and internal HR files. The security manager is concerned that a low-cost vendor may not meet the organization's regulatory and security requirements. During the acquisition process, which action should the security manager take FIRST to reduce the risk of purchasing a solution that fails to meet security needs?
- A
Require the vendor to complete a security and compliance questionnaire aligned to the organization's requirements before contract award
- B
Rely on the vendor's marketing materials and select the product with the lowest total cost of ownership
- C
Purchase the platform first and plan to add compensating controls after deployment if gaps are discovered
- D
Approve the purchase only after the help desk confirms the product is easy for employees to use
Show answer and explanation
Correct answer: A
Explanation
Security should be embedded early in the acquisition/procurement lifecycle. Before awarding a contract, organizations should define security requirements, assess vendor responses, and verify that the product aligns with data sensitivity, legal obligations, and internal policy. Common best practices include issuing security requirements in the RFP or procurement package, using vendor security questionnaires, reviewing independent attestations where appropriate, evaluating contract language such as breach notification and right-to-audit terms, and ensuring the solution supports required controls. This approach aligns with third-party risk management and secure procurement principles reflected in common frameworks and guidance such as NIST SP 800-161 for supply chain risk management and NIST SP 800-53 control families related to acquisition and system services.
- A. Correct.
Correct. In the acquisition/procurement process, security requirements should be defined and evaluated before purchase. A structured security and compliance questionnaire, often tied to internal standards, regulatory obligations, data classification, and third-party risk management processes, helps determine whether the vendor can meet required controls such as encryption, logging, retention, identity federation, incident response support, and regulatory commitments. This is the best first step because it integrates security into procurement rather than treating it as an afterthought.
- B. Incorrect.
Incorrect. Cost is an important procurement factor, but selecting a vendor based primarily on marketing claims and lowest cost creates significant risk. Marketing materials are not a substitute for due diligence, documented control validation, or contractual review. This option reflects a common mistake of prioritizing price over security, privacy, and compliance requirements.
- C. Incorrect.
Incorrect. Buying first and planning to remediate later is poor procurement practice and can lead to expensive rework, failed audits, contractual lock-in, or inability to meet regulatory obligations. While compensating controls may sometimes be used, they should not replace pre-purchase security assessment during acquisition.
- D. Incorrect.
Incorrect. Usability and operational support matter, but help desk feedback does not address whether the product satisfies security, privacy, legal, or compliance requirements. This option is plausible because ease of use influences adoption, but it is not the first action to reduce procurement risk in a security-sensitive acquisition.