SY0-701 Question 447
Single answerVendor monitoringA healthcare company uses a third-party billing vendor that connects to internal systems through a site-to-site VPN and processes protected health information (PHI). During a quarterly security review, the company discovers the vendor recently changed ownership and migrated part of its infrastructure to a new cloud provider. The security manager is concerned that the vendor's risk profile may have changed since the last annual assessment. Which of the following is the BEST action to improve vendor monitoring and reduce third-party risk going forward?
- A
Require the vendor to complete an updated security assessment and provide current evidence such as SOC 2 reports, penetration test summaries, and notice of any material control changes
- B
Immediately terminate the vendor relationship because ownership changes automatically invalidate all previous security agreements
- C
Rely on the original due diligence package because annual assessments are sufficient if the VPN connection is still operational
- D
Ask the internal network team to increase bandwidth monitoring on the VPN tunnel instead of requesting updated vendor security documentation
Show answer and explanation
Correct answer: A
Explanation
The best answer is to perform event-driven vendor monitoring by requesting an updated security assessment and supporting evidence. In third-party risk management, organizations should not rely solely on annual reviews; they should also reassess vendors when significant changes occur, including ownership changes, mergers, major infrastructure migrations, new subcontractors, or security incidents. This aligns with widely used best practices from NIST SP 800-161 (Cybersecurity Supply Chain Risk Management), NIST SP 800-53 controls related to external service providers and supply chain risk, and general third-party risk management practices used in regulated industries such as healthcare. For a vendor handling PHI, updated assurance documentation, contractual notifications of material changes, and review of security responsibilities are key parts of ongoing vendor monitoring.
- A. Correct.
Correct. Vendor monitoring is an ongoing process, not a one-time onboarding activity. A significant event such as a change in ownership or a migration to a new cloud provider can materially affect a vendor's security posture, subcontractor exposure, compliance scope, and control environment. Requiring an updated assessment and current assurance artifacts is the most appropriate response because it validates whether the vendor still meets contractual, regulatory, and security requirements after the change.
- B. Incorrect.
Incorrect. A change in ownership increases risk and justifies reassessment, but it does not automatically require termination. Security teams should follow the organization's third-party risk management process, review contract terms, and determine whether the vendor can still meet security and compliance obligations. Immediate termination without reassessment is typically an overreaction and may disrupt business operations unnecessarily.
- C. Incorrect.
Incorrect. This reflects a common misconception that vendor due diligence is only performed at onboarding or on a fixed annual schedule. Effective vendor monitoring includes reassessment when triggering events occur, such as mergers, acquisitions, major architectural changes, breaches, or use of new subprocessors. The VPN still functioning says nothing about the vendor's current control effectiveness or compliance status.
- D. Incorrect.
Incorrect. Monitoring bandwidth or tunnel usage may support operational oversight, but it does not address the primary third-party risk concern: whether the vendor's security controls, governance, and compliance posture changed after the ownership and infrastructure changes. Technical connection monitoring is not a substitute for updated vendor risk documentation and reassessment.