SY0-701 Question 444
Single answerVendor selection: Due diligence , Conflict of interestA company is selecting a managed security service provider (MSSP) to monitor its cloud environment. During the review, the security manager learns that one member of the evaluation committee previously worked for one of the bidders and still owns stock in that company. At the same time, the bidder's proposal claims strong security controls but provides only marketing material and no independent assessment reports. Which action should the company take FIRST to best address both the conflict-of-interest risk and vendor due-diligence requirements?
- A
Remove the committee member from scoring decisions involving that vendor, disclose the relationship, and require objective due-diligence evidence such as audit reports and control attestations before proceeding
- B
Continue the evaluation because prior employment does not matter if the committee member signs an NDA, and accept the vendor's proposal if its pricing is competitive
- C
Award the contract to a different bidder immediately to avoid any appearance of bias, even if the other bidder has not completed security review
- D
Ask the committee member to verbally confirm impartiality and allow the procurement team to rely on the vendor's website and brochure for security validation
Show answer and explanation
Correct answer: A
Explanation
In vendor selection, two key Security+ concerns are conflict-of-interest management and due diligence. A conflict of interest does not automatically prove misconduct, but it must be disclosed and mitigated to preserve fairness, defensibility, and trust in the procurement process. Common mitigations include recusal from scoring, reassignment of decision authority, and documentation of the relationship. Due diligence requires the organization to validate a vendor's security posture using reliable evidence rather than relying solely on claims in proposals or brochures. In practice, organizations commonly request independent assessments such as SOC 2 reports, ISO/IEC 27001 certification details, SIG questionnaires, PCI DSS attestation where applicable, recent penetration test summaries, incident-response procedures, and contract terms covering security obligations. These practices align with standard procurement governance and third-party risk management approaches reflected in frameworks such as NIST SP 800-161 for supply chain risk management and NIST SP 800-53 controls related to external providers and assessment. The best answer is the one that addresses both governance risk and security validation before the selection proceeds.
- A. Correct.
Correct. This addresses both issues in a practical and defensible way. A potential conflict of interest should be formally disclosed and mitigated, commonly by recusal from evaluation or scoring where bias could exist. Separately, vendor due diligence requires objective evidence, not just marketing claims. Examples include SOC 2 reports, ISO/IEC 27001 certification scope statements, independent audit results, penetration test summaries, security questionnaires, and contractual security requirements. This is the most appropriate first step because it preserves procurement integrity while ensuring the vendor's security claims are validated.
- B. Incorrect.
Incorrect. An NDA does not resolve a conflict of interest; it addresses confidentiality, not evaluator bias or the appearance of impropriety. Competitive pricing also does not satisfy security due diligence. A common misconception is that legal paperwork or cost savings can substitute for impartial governance and independent validation of controls.
- C. Incorrect.
Incorrect. Avoiding the appearance of bias is important, but immediately awarding to another vendor without completing due diligence creates a separate risk. The right response is to manage the conflict appropriately and continue a fair, evidence-based selection process. Security+ expects candidates to recognize that process integrity and security validation both matter.
- D. Incorrect.
Incorrect. A verbal assurance is not a sufficient mitigation for a known potential conflict of interest, especially in a formal vendor selection process. Likewise, a website and brochure are vendor-produced marketing materials, not independent evidence of control effectiveness. This option reflects the misconception that informal assurances are enough for governance and security review.