SY0-701 Question 442
Single answerA healthcare company is evaluating a cloud-based billing vendor that will process protected health information (PHI). The vendor provides a recent SOC 2 Type II report and marketing material stating that security is a top priority. However, the company's security manager is concerned about third-party risk after a recent industry incident involving malicious code introduced through a software supplier. Which action would BEST improve the company's ability to verify the vendor's ongoing security posture and investigate both control effectiveness and supply chain risk before signing the contract?
- A
Accept the SOC 2 Type II report as sufficient evidence and proceed, because independent assessments eliminate the need for further verification
- B
Require a right-to-audit clause in the contract and request evidence of internal audits, recent penetration testing, and software supply chain controls
- C
Ask the vendor to sign an NDA and provide a copy of its incident response plan, because this is the most direct way to validate security controls
- D
Rely on the vendor's cyber insurance coverage and financial stability review, because these are the strongest indicators of security maturity
Show answer and explanation
Correct answer: B
Explanation
The best answer is to combine contractual oversight with multiple forms of security evidence. In vendor assessments, independent assessments such as SOC reports are valuable, but they should be supplemented when the customer has higher-risk data exposure or specific concerns. A right-to-audit clause is important because it allows the customer to validate security controls, review relevant artifacts, or conduct assessments as permitted by contract. Evidence of internal audits demonstrates that the vendor is actively monitoring and improving its controls, rather than relying only on external attestations. Penetration testing helps validate technical defenses in a practical way, and supply chain analysis is increasingly important due to software dependency, subcontractor, and code integrity risks. This aligns with common third-party risk management practices reflected in frameworks and guidance such as NIST SP 800-161 for cyber supply chain risk management, NIST SP 800-53 supply chain and assessment-related controls, and NIST SP 800-115 for technical security testing considerations.
- A. Incorrect.
Incorrect. A SOC 2 Type II report is useful because it is an independent assessment of control operation over a period of time, but it does not eliminate the need for additional vendor due diligence. It may not fully address the customer's specific risk concerns, such as recent penetration testing results, software component provenance, subcontractor risk, or the customer's ability to validate controls later through contract rights.
- B. Correct.
Correct. A right-to-audit clause gives the customer contractual authority to verify controls and investigate issues during the vendor relationship. Requesting evidence of internal audits helps demonstrate the vendor's ongoing governance and control review process. Recent penetration testing provides insight into technical security validation, while reviewing software supply chain controls addresses the specific concern about malicious code or compromised suppliers. Together, these measures provide layered assurance beyond a single third-party report.
- C. Incorrect.
Incorrect. An NDA may be appropriate to protect shared sensitive information, and an incident response plan is relevant to preparedness, but neither by itself provides strong evidence that controls are effective. This option focuses on documentation access rather than verification of actual control performance, contractual oversight, and supply chain risk evaluation.
- D. Incorrect.
Incorrect. Cyber insurance and financial stability can be part of a broader vendor assessment, especially for business continuity and risk transfer considerations, but they are not strong evidence of security control effectiveness. A financially stable vendor can still have weak security practices or unmanaged supply chain exposure.