SY0-701 exam dumps

SY0-701 practice question 76 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 76

Single answerSupply chain: Managed service providers (MSPs) , Vendors , Suppliers

A company uses a managed service provider (MSP) to administer endpoints and patch servers. During a security review, the company discovers the MSP uses a shared remote administration platform to access multiple clients and stores client backups in the same cloud tenant. Leadership is concerned that a compromise of the MSP could expose the company through the supply chain. Which action would BEST reduce this risk before renewing the MSP contract?

  1. A

    Require the MSP to implement tenant isolation, dedicated administrative accounts for the company, and MFA for all remote administrative access

  2. B

    Ask the MSP to provide a copy of its antivirus deployment report each month

  3. C

    Move all company patching responsibilities to internal IT while leaving backup management and remote administration unchanged

  4. D

    Require the MSP to sign a statement that it will accept liability for any future breach

Show answer and explanation

Correct answer: A

Explanation

This question focuses on supply-chain risk management involving an MSP. In Security+ terms, third-party relationships such as MSPs, vendors, and suppliers introduce risk when they have privileged access, shared tooling, or co-mingled data. The strongest response is to require compensating and preventive controls that limit cross-tenant exposure and harden privileged access. Best practices include vendor due diligence, clear security requirements in contracts and service-level agreements, segregation of customer environments, least privilege, unique accounts, MFA, logging, and periodic assessment. These principles align with common guidance from NIST supply-chain risk management and third-party security practices, including vendor risk reviews and access control requirements. The key exam takeaway is that when a supplier or MSP creates concentration risk through shared infrastructure, the best mitigation is stronger isolation and access controls rather than reporting, partial insourcing, or liability language alone.

  • A. Correct.

    This is the best answer because it directly addresses the identified supply-chain risk: shared management infrastructure and cross-client exposure. Tenant isolation reduces the chance that one customer environment can affect another. Dedicated administrative accounts improve accountability and limit shared credentials. MFA on remote administrative access is a core control to reduce the risk of unauthorized access through the MSP. These are practical third-party risk reduction measures that should be defined contractually and validated during vendor due diligence.

  • B. Incorrect.

    This is incorrect because antivirus reporting provides only a narrow operational view and does not address the primary issue in the scenario: the MSP's shared administration platform and co-mingled customer environments. A company might choose this option because reporting sounds like oversight, but it does not materially reduce the risk of lateral impact from an MSP compromise.

  • C. Incorrect.

    This is incorrect because it removes only one service area while leaving the most concerning risks in place: shared remote administration and shared backup tenancy. Someone might select this option because patching is security-sensitive, but the scenario specifically highlights third-party access architecture and customer separation as the key concerns.

  • D. Incorrect.

    This is incorrect because liability language may help with legal recourse after an incident, but it does not itself reduce the likelihood or impact of compromise. Organizations sometimes confuse contractual penalties with security controls. The question asks for the action that best reduces risk before renewal, which requires technical and administrative safeguards, not just legal terms.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam