SY0-701 exam dumps

SY0-701 practice question 448 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 448

Single answerVendor monitoring

A company uses a third-party payroll provider that stores employee tax records and bank account information. During a quarterly review, the security manager discovers the provider passed its annual audit six months ago, but the provider has not submitted the monthly vulnerability scan summaries and incident-status reports required by the contract. The company wants to reduce the risk of a third-party breach going undetected between annual assessments. Which action would BEST improve vendor monitoring in this situation?

  1. A

    Require the vendor to provide ongoing security reporting, such as periodic vulnerability and incident-status reports, and track compliance with the SLA

  2. B

    Replace the annual audit requirement with a one-time vendor security questionnaire completed during contract renewal

  3. C

    Allow the vendor to self-attest that security controls remain effective unless a breach is publicly disclosed

  4. D

    Move all responsibility for vendor security oversight to the payroll provider because the data is hosted externally

Show answer and explanation

Correct answer: A

Explanation

The best answer is to implement stronger ongoing vendor monitoring by requiring periodic security reporting and verifying compliance with contractual requirements. In third-party risk management, annual audits such as SOC reports or other assessments are useful point-in-time reviews, but they do not provide continuous assurance. Best practices call for monitoring vendors throughout the relationship using defined reporting requirements, performance metrics, incident notification clauses, and evidence of remediation for identified issues. This aligns with common third-party risk management guidance from sources such as NIST SP 800-161 on supply chain risk management and NIST SP 800-53 controls related to external service providers and continuous monitoring. In practical Security+ terms, vendor monitoring means maintaining visibility into a supplier's security posture over time, especially when the vendor handles sensitive or regulated data.

  • A. Correct.

    Correct. Vendor monitoring is an ongoing activity, not a once-per-year event. Requiring regular security reporting such as vulnerability scan summaries, incident-status updates, and evidence of remediation helps the company detect elevated risk between formal audits. Tracking these deliverables against the service-level agreement (SLA) or contractual security requirements is a practical way to enforce accountability and verify the vendor is meeting expected security obligations.

  • B. Incorrect.

    Incorrect. A one-time questionnaire at renewal provides less visibility than an annual audit and does not address the current gap: lack of continuous or periodic monitoring. Questionnaires can support due diligence, but by themselves they are not sufficient for operational vendor monitoring when sensitive data is involved.

  • C. Incorrect.

    Incorrect. Self-attestation alone is weaker than independent evidence and periodic reporting. It may be used as a supplemental input, but relying on the vendor to simply state that controls are effective creates a monitoring gap and increases the chance that security issues will go unnoticed until after a breach occurs.

  • D. Incorrect.

    Incorrect. Outsourcing data hosting does not outsource accountability. The company still owns the business risk, regulatory exposure, and contractual responsibility for protecting employee information. Security+ expects candidates to understand that third-party risk must be managed through governance, oversight, and monitoring rather than transferred completely to the vendor.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam