SY0-701 Security Program Management and Oversight • Set 3
SY0-701 Security Program Management and Oversight Practice Test 3 — 15 questions with explanations. Free, no signup.
A security manager at a healthcare organization is reviewing the results of a third-party vendor risk assessment for a cloud-based email service that will store protected health information (PHI). The assessment reveals that the vendor encrypts data at rest using AES-256 but does not support customer-managed encryption keys. The vendor's data center is located in a country that is not subject to HIPAA jurisdiction. The vendor's previous penetration test report is over 18 months old. Which of the following is the most appropriate risk management action for the security manager to take?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.