SY0-701 exam dumps

SY0-701 practice question 450 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 450

Single answerQuestionnaires

A healthcare organization is onboarding a cloud-based billing vendor that will process patient account data and connect to an internal application through an API. The security team wants to quickly identify the vendor's security posture, compliance status, and major control gaps before deciding whether to proceed with a deeper review and contract negotiations. Which of the following is the BEST first step?

  1. A

    Require the vendor to complete a standardized security questionnaire covering areas such as access control, encryption, incident response, and regulatory compliance

  2. B

    Run an internal vulnerability scan against the vendor's public IP space to determine whether their environment is secure enough for integration

  3. C

    Approve the vendor provisionally and rely on the right-to-audit clause later if a security issue is discovered

  4. D

    Request the vendor's administrator passwords temporarily so the security team can directly validate their cloud configuration

Show answer and explanation

Correct answer: A

Explanation

Questionnaires are widely used in Security+ third-party risk and vendor assessment scenarios because they provide a structured, scalable way to gather information about an external party's security controls and compliance posture. In practice, organizations often begin with a standardized questionnaire, then validate high-risk responses through follow-up interviews, document reviews, independent attestations such as SOC reports, or contractually authorized technical testing. This aligns with common vendor risk management practices described by NIST guidance, including NIST SP 800-161 for supply chain risk management and NIST SP 800-53 control families related to external service providers and assessments. For healthcare or other regulated environments, questionnaires are especially useful for determining whether the vendor's controls are likely to meet legal, contractual, and organizational requirements before integration proceeds.

  • A. Correct.

    Correct. A standardized security questionnaire is a common and appropriate first step in third-party risk management. It allows the organization to gather consistent information about the vendor's security controls, data handling practices, compliance obligations, and maturity before investing time in deeper due diligence. For a healthcare-related vendor, questionnaire topics should include access control, encryption, logging, incident response, data retention, subcontractor use, and support for relevant compliance requirements such as HIPAA-related safeguards where applicable.

  • B. Incorrect.

    Incorrect. Scanning a vendor's public infrastructure without authorization is generally inappropriate and may violate policy, contracts, or law. Even if permitted, a vulnerability scan would provide only a limited technical view and would not answer broader risk questions such as incident response processes, employee screening, encryption of stored data, or regulatory compliance. A questionnaire is better suited for initial vendor assessment.

  • C. Incorrect.

    Incorrect. Provisionally approving the vendor before performing initial due diligence creates unnecessary risk. A right-to-audit clause can be valuable in a contract, but it is not a substitute for collecting baseline security information before onboarding. The misconception here is treating contractual remedies as equivalent to pre-engagement risk assessment.

  • D. Incorrect.

    Incorrect. Requesting administrator passwords is not an acceptable or realistic third-party assessment practice. It would violate basic security principles such as least privilege, accountability, and proper credential handling. Vendor reviews should rely on approved evidence collection methods such as questionnaires, documentation review, attestations, interviews, and contractually authorized assessments.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam