SY0-701 Question 443
Single answerVendor selection: Due diligence , Conflict of interestA company is selecting a managed security service provider (MSSP) to monitor its SIEM and incident response processes. During the review, the security manager learns that one of the evaluation committee members previously worked for one of the bidding vendors and still owns stock in that company. The same vendor also refuses to provide recent independent audit reports and declines to answer detailed questions about how customer log data is segregated in its multi-tenant environment. Which action should the company take FIRST to best address both vendor due diligence and conflict-of-interest concerns?
- A
Remove the committee member from the selection process, require formal conflict-of-interest disclosure, and pause award consideration until the vendor provides sufficient security assurance documentation
- B
Continue the evaluation because prior employment does not matter if the committee member signs the final recommendation with the rest of the team
- C
Select the vendor conditionally and plan to validate its controls after contract signature during the first annual review
- D
Ask the vendor for a lower price in exchange for accepting reduced transparency about its internal security controls
Show answer and explanation
Correct answer: A
Explanation
The best answer is to immediately manage the conflict of interest and suspend selection until adequate due diligence is completed. In vendor selection, due diligence includes evaluating the vendor's security posture, reviewing independent assurance documentation when available, understanding how sensitive customer data is protected, and confirming that controls align with business and compliance requirements. For an MSSP, evidence such as SOC reports, ISO/IEC 27001 certification scope, penetration test summaries, shared responsibility details, and data segregation practices can help support the assessment. Conflict-of-interest management is equally important because procurement and security decisions must be objective and defensible. Common best practices include requiring disclosure statements, documenting potential conflicts, and recusing impacted personnel from decision-making. These actions align with standard governance, risk management, and procurement practices emphasized in security programs and reflected in Security+ objectives related to third-party risk, due diligence, and ethical decision-making.
- A. Correct.
Correct. This option addresses both issues appropriately. A committee member with prior employment and ongoing financial interest in a bidder presents a clear conflict-of-interest risk that should be disclosed and managed, typically by recusal or removal from the decision process. Separately, refusing to provide audit reports or explain customer data segregation indicates inadequate due diligence support. Before awarding a security-sensitive contract, the company should obtain sufficient assurance evidence, such as independent assessments, control attestations, or architecture/security documentation.
- B. Incorrect.
Incorrect. This reflects a common misconception that disclosure alone is enough even when the individual still has a financial interest in the vendor. A signature on the final recommendation does not remove bias risk. The company must actively manage the conflict, typically through recusal or removal from the evaluation. It also ignores the vendor's failure to provide due diligence evidence.
- C. Incorrect.
Incorrect. Deferring validation until after contract execution is poor risk management for an MSSP engagement. Due diligence is intended to occur before selection and contract award, especially when the vendor will handle security monitoring and potentially sensitive log data. Waiting until an annual review could expose the organization to unnecessary legal, operational, and security risk.
- D. Incorrect.
Incorrect. Cost negotiation does not address the core security and governance concerns. Reduced transparency about control effectiveness, audit status, and tenant data segregation is a significant red flag for a provider handling security operations. Accepting less visibility in exchange for price is inconsistent with prudent vendor due diligence.