SY0-701 exam dumps

SY0-701 practice question 476 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 476

Single answerIndependent third-party audit

A healthcare company is preparing to sign contracts with several new business partners that will require access to systems storing sensitive customer and regulated data. The partners want objective evidence that the company's security controls are designed appropriately and operating effectively, rather than relying only on the company's internal security team. Which of the following would BEST satisfy this requirement?

  1. A

    Have the internal audit team review the controls and provide a management-approved attestation letter

  2. B

    Provide the partners with results from an independent third-party audit performed by an external assessor

  3. C

    Send the partners copies of the company's security awareness training materials and policies

  4. D

    Ask each business partner to complete its own questionnaire based on the company's self-assessment

Show answer and explanation

Correct answer: B

Explanation

The key phrase in the scenario is 'objective evidence' from a source other than the company's own security team. That points directly to an independent third-party audit performed by an external assessor. In practice, organizations use independent assessments to demonstrate security posture to customers, regulators, and partners because independence reduces conflicts of interest and increases trust in the findings. This aligns with common risk management and assurance practices, including external audits used for control validation and compliance reporting. Internal reviews, policy documents, and self-assessments can support a security program, but they do not provide the same level of assurance as an independent external audit.

  • A. Incorrect.

    This is incorrect because an internal audit team, even if competent, is part of the organization and does not provide the same level of independence as an external third-party assessor. A management attestation letter may be useful as supplementary evidence, but it does not meet the stated requirement for objective, independent validation of control design and effectiveness.

  • B. Correct.

    This is correct because an independent third-party audit provides external validation of security controls by an assessor who is not part of the organization being reviewed. This is exactly what business partners often request when they need objective assurance for due diligence, vendor risk management, or compliance purposes. Independent audits are commonly used to demonstrate that controls have been formally examined and tested by a neutral party.

  • C. Incorrect.

    This is incorrect because policies and training materials show that the organization has documented expectations and awareness efforts, but they do not prove that security controls are independently evaluated or operating effectively in practice. These documents are supporting artifacts, not substitutes for an independent audit.

  • D. Incorrect.

    This is incorrect because partner questionnaires are typically part of a vendor due diligence process, but they largely rely on self-reported information. They do not provide the same credibility or assurance as an independent third-party audit. A self-assessment can help collect information, but it does not satisfy the requirement for objective external evidence.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam