SY0-701 Question 448
Single answerVendor monitoringA company uses a third-party payroll provider that stores employee tax records and bank account information. During a quarterly review, the security manager discovers the provider passed its annual audit six months ago, but the provider has not submitted the monthly vulnerability scan summaries and incident-status reports required by the contract. The company wants to reduce the risk of a third-party breach going undetected between annual assessments. Which action would BEST improve vendor monitoring in this situation?
- A
Require the vendor to provide ongoing security reporting, such as periodic vulnerability and incident-status reports, and track compliance with the SLA
- B
Replace the annual audit requirement with a one-time vendor security questionnaire completed during contract renewal
- C
Allow the vendor to self-attest that security controls remain effective unless a breach is publicly disclosed
- D
Move all responsibility for vendor security oversight to the payroll provider because the data is hosted externally
Show answer and explanation
Correct answer: A
Explanation
The best answer is to implement stronger ongoing vendor monitoring by requiring periodic security reporting and verifying compliance with contractual requirements. In third-party risk management, annual audits such as SOC reports or other assessments are useful point-in-time reviews, but they do not provide continuous assurance. Best practices call for monitoring vendors throughout the relationship using defined reporting requirements, performance metrics, incident notification clauses, and evidence of remediation for identified issues. This aligns with common third-party risk management guidance from sources such as NIST SP 800-161 on supply chain risk management and NIST SP 800-53 controls related to external service providers and continuous monitoring. In practical Security+ terms, vendor monitoring means maintaining visibility into a supplier's security posture over time, especially when the vendor handles sensitive or regulated data.
- A. Correct.
Correct. Vendor monitoring is an ongoing activity, not a once-per-year event. Requiring regular security reporting such as vulnerability scan summaries, incident-status updates, and evidence of remediation helps the company detect elevated risk between formal audits. Tracking these deliverables against the service-level agreement (SLA) or contractual security requirements is a practical way to enforce accountability and verify the vendor is meeting expected security obligations.
- B. Incorrect.
Incorrect. A one-time questionnaire at renewal provides less visibility than an annual audit and does not address the current gap: lack of continuous or periodic monitoring. Questionnaires can support due diligence, but by themselves they are not sufficient for operational vendor monitoring when sensitive data is involved.
- C. Incorrect.
Incorrect. Self-attestation alone is weaker than independent evidence and periodic reporting. It may be used as a supplemental input, but relying on the vendor to simply state that controls are effective creates a monitoring gap and increases the chance that security issues will go unnoticed until after a breach occurs.
- D. Incorrect.
Incorrect. Outsourcing data hosting does not outsource accountability. The company still owns the business risk, regulatory exposure, and contractual responsibility for protecting employee information. Security+ expects candidates to understand that third-party risk must be managed through governance, oversight, and monitoring rather than transferred completely to the vendor.