SY0-701 exam dumps

SY0-701 practice question 441 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 441

Single answer

A healthcare company is evaluating a cloud-based claims-processing vendor that will store protected health information (PHI). The vendor provides a marketing brochure stating its environment is secure and shares a recent penetration test summary, but it refuses to allow customer audits and will not provide any third-party assessment reports. The security manager must recommend the MOST effective contract and due-diligence actions to reduce supply chain risk before signing. Which of the following is the BEST recommendation?

  1. A

    Accept the penetration test summary as sufficient evidence because it demonstrates technical testing of the vendor's environment

  2. B

    Require a right-to-audit clause in the contract and request independent assessment evidence, such as a SOC 2 report or ISO 27001 certification audit results

  3. C

    Rely on the vendor's internal audit statements because internal teams know the environment better than outside assessors

  4. D

    Proceed with the contract if the vendor agrees to annual vulnerability scans, even if no supply chain review or audit rights are included

Show answer and explanation

Correct answer: B

Explanation

The best answer is to require both a right-to-audit clause and independent assessment evidence. In vendor assessment, especially for high-impact data such as PHI, organizations should not rely solely on vendor marketing materials, self-attestations, or a narrow technical artifact like a penetration test summary. Penetration tests are valuable, but they represent a snapshot of technical security testing and may not cover administrative, operational, and supply chain controls. Independent assessments, such as SOC 2 reports and ISO 27001 certification audits, provide more objective evidence that controls were reviewed against recognized criteria. A right-to-audit clause strengthens the contract by allowing verification when risk, incidents, or regulatory concerns arise. Evidence of internal audits can supplement due diligence, but it should not replace independent validation for a high-risk vendor. This aligns with common third-party risk management best practices, including reviewing contractual controls, obtaining independent assurance, and assessing supply chain risk across the vendor's dependencies and oversight processes.

  • A. Incorrect.

    This is incorrect because a penetration test summary alone is not sufficient for vendor assessment. Penetration testing evaluates certain technical weaknesses at a point in time, but it does not replace broader governance, control validation, or contractual assurance. A summary may also omit scope, findings, remediation status, and testing limitations. For a vendor handling PHI, relying only on this artifact leaves gaps in oversight and supply chain risk management.

  • B. Correct.

    This is correct because combining a right-to-audit clause with independent assessment evidence provides both contractual leverage and objective assurance. A right-to-audit clause allows the customer to verify controls directly or through an agreed mechanism if concerns arise. Independent assessments such as SOC 2 reports or ISO 27001 certification audits provide third-party validation of security controls beyond vendor self-attestation. This approach is stronger than accepting marketing claims or a single technical test and aligns with mature third-party risk management practices.

  • C. Incorrect.

    This is incorrect because internal audit evidence can be useful, but it is not as strong as an independent assessment when the vendor is unwilling to provide third-party reports or permit audit rights. Internal audits may be limited in scope, lack objectivity, or be difficult for customers to validate. Choosing this option reflects the misconception that familiarity with the environment automatically makes internal evidence sufficient for high-risk vendor decisions.

  • D. Incorrect.

    This is incorrect because annual vulnerability scans are narrower than a full vendor assessment and do not address many supply chain concerns, such as governance, incident response, subcontractor oversight, data handling, and compliance obligations. Without audit rights or independent assurance, the customer has limited ability to validate the vendor's security posture over time. Vulnerability scanning can be one control, but it is not an adequate substitute for contractual and independent oversight.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam