SY0-701 exam dumps

SY0-701 practice question 440 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 440

Single answer5.3 Explain the processes associated with third-party risk assessment and management.

A healthcare company is evaluating a cloud-based billing vendor that will process protected health information (PHI) and connect to the company's internal scheduling platform through an API. The security manager must complete the third-party risk assessment before approving the contract. Which action is the BEST way to reduce organizational risk during the vendor onboarding process?

  1. A

    Require the vendor to complete a security questionnaire, review independent audit evidence such as SOC 2 reports, and include contractual requirements for incident notification, right to audit, and minimum security controls

  2. B

    Rely on the vendor's marketing materials and uptime guarantees because the billing platform is externally hosted and therefore outside the company's security boundary

  3. C

    Approve the vendor if the API traffic is encrypted with TLS, since encryption in transit removes the primary third-party risk

  4. D

    Delay any security review until after deployment so production monitoring can identify whether the vendor introduces actual risk

Show answer and explanation

Correct answer: A

Explanation

Third-party risk assessment and management in Security+ focuses on performing due diligence before onboarding, validating vendor security claims, and formally managing risk through contracts, monitoring, and governance. In a scenario involving PHI, the organization must assess the vendor's controls and compliance obligations before data is shared. Best practices include vendor questionnaires, review of independent assurance artifacts such as SOC 2 reports or similar assessments, confirmation of legal and regulatory alignment, and contract terms covering security requirements, breach notification, audit rights, data ownership, and termination handling. This aligns with common guidance from NIST supply chain risk management practices, vendor due diligence processes, and healthcare compliance expectations such as HIPAA business associate requirements when PHI is involved. Encryption is valuable, but it is only one control and does not replace a full assessment of the vendor's security posture.

  • A. Correct.

    Correct. This reflects a mature third-party risk management process: perform due diligence before onboarding, validate claims with independent evidence, and use contractual controls to define security obligations. Security questionnaires help assess the vendor's practices, SOC 2 or similar reports provide third-party assurance, and contract clauses such as incident notification timelines, right to audit, data handling requirements, and baseline security controls help transfer and manage risk. This is the best answer because it combines assessment, validation, and governance.

  • B. Incorrect.

    Incorrect. Marketing materials and service availability commitments do not demonstrate adequate security controls. Even though the service is externally hosted, the company still retains responsibility for protecting PHI and managing supply chain risk. This option reflects the common misconception that outsourcing infrastructure also outsources accountability.

  • C. Incorrect.

    Incorrect. TLS is important, but encryption in transit addresses only one portion of the risk. The organization still needs to evaluate access control, logging, data retention, breach response, subcontractor use, compliance posture, and how the vendor secures stored PHI. Candidates may choose this because encryption is highly visible, but it is not sufficient for a full third-party risk assessment.

  • D. Incorrect.

    Incorrect. Security review should occur before deployment, not after. Monitoring in production is useful for continuous oversight, but onboarding without due diligence increases the chance of introducing unmanaged risk into the environment. This option confuses ongoing vendor monitoring with initial risk assessment.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam