SY0-701 exam dumps

SY0-701 practice question 449 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 449

Single answerQuestionnaires

A security analyst is helping the procurement team evaluate a cloud-based payroll vendor before signing a contract. The analyst needs a cost-effective way to collect standardized information about the vendor's security controls, compliance status, incident response process, and data handling practices before deciding whether a deeper technical review is necessary. Which action should the analyst take FIRST?

  1. A

    Send the vendor a security questionnaire aligned to the organization's third-party risk requirements

  2. B

    Require the vendor to complete a full penetration test against the organization's internal systems

  3. C

    Perform a vulnerability scan of the vendor's cloud environment from the internet

  4. D

    Immediately deny the vendor because cloud payroll providers are inherently too risky

Show answer and explanation

Correct answer: A

Explanation

Security questionnaires are commonly used in vendor and third-party risk assessments to collect consistent information before onboarding a provider or renewing a contract. In real environments, procurement, legal, and security teams often use questionnaires to assess areas such as data classification, encryption, identity and access management, business continuity, incident notification, regulatory compliance, and use of subprocessors. This aligns with broadly accepted third-party risk management practices found in frameworks and guidance such as NIST SP 800-171/800-53 control families related to supplier relationships and assessment, as well as SIG-style vendor questionnaires used in industry. A questionnaire is not a substitute for technical validation, but it is often the most practical first step because it is standardized, scalable, and helps determine whether follow-up activities such as document review, contract language updates, or deeper assessments are necessary.

  • A. Correct.

    Correct. A security questionnaire is a standard first-step due diligence tool in third-party risk management. It allows the organization to gather structured, comparable information about the vendor's security program, such as access controls, encryption, logging, incident response, compliance attestations, and subcontractor use. This is especially appropriate when the goal is to determine whether a more detailed assessment is needed.

  • B. Incorrect.

    Incorrect. Requiring a penetration test against the organization's internal systems is unrelated to assessing the vendor's security posture and would be inappropriate at this stage. Even requesting a full vendor penetration test report is typically a later-stage validation activity, not the most efficient first action when procurement needs baseline information.

  • C. Incorrect.

    Incorrect. Scanning a vendor's cloud environment without authorization is generally not appropriate and may violate policy, contracts, or acceptable use restrictions. External scanning also provides only limited technical visibility and does not answer broader governance, compliance, and data handling questions that questionnaires are designed to address.

  • D. Incorrect.

    Incorrect. Rejecting the vendor solely because it is cloud-based is not a risk-based approach. Security+ emphasizes assessing risk using evidence and due diligence rather than making blanket assumptions. Many cloud vendors can meet strong security requirements, but that should be determined through structured evaluation.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam