SY0-701 Security Program Management and Oversight Practice Question
A payroll SaaS provider has passed initial review, but before contract signing it announces that customer data will be processed by a new subcontractor in another country. The business wants to keep the onboarding timeline short, but security still needs assurance that the change does not increase exposure. What is the BEST next step?
⚠ Common exam trap
Many candidates assume passing initial review means all future changes are automatically acceptable, overlooking the need for reassessment when the data processing environment changes, especially with a new subcontractor in a different country.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the third-party risk assessment and require evidence of the subcontractor's controls before approval.
The introduction of a new subcontractor in a different country represents a material change to the data processing environment, which invalidates the initial risk assessment. Security must update the third-party risk assessment to evaluate the subcontractor's controls, such as data protection, encryption standards, and compliance with local regulations, before approval. This ensures that the change does not increase exposure, even if the primary provider passed initial review.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Approve the vendor because the primary provider already passed the initial review.
Why it's wrong here
Approving the vendor solely because it passed an initial review is insufficient because that review assessed the original service model, not the newly introduced subcontractor. In vendor risk management, a material change such as adding a subcontractor invalidates the prior assessment and creates a new attack surface for payroll data. The initial review's conclusions cannot be extended to an unvetted downstream party, which may have different security controls, legal obligations, or data-handling practices. Security must re-evaluate the entire supply chain before granting continued approval.
- ✓
Update the third-party risk assessment and require evidence of the subcontractor's controls before approval.
Why this is correct
This is the best next step because the change in subcontracting materially alters the risk profile. Security should reassess the provider, review the downstream party's controls, and confirm contractual obligations such as incident notification, data handling, and location requirements. This balances speed with due diligence and ensures the organization has current evidence before customer data is exposed to a new party.
- ✗
Wait until the first quarterly audit to review the subcontractor change.
Why it's wrong here
Waiting until the first quarterly audit before reviewing the subcontractor change leaves a window of unmonitored risk, and in that interval the subcontractor will already be processing sensitive payroll data. Third-party risk must be assessed before the new relationship becomes operational, not after the fact, because an adverse security event could occur before any audit catches it. The principle is that risk is accepted the moment data is shared, so due diligence must precede data sharing. Deferring review converts a controllable decision into an incident-response scenario.
- ✗
Accept the change if the vendor provides a marketing brochure describing its security program.
Why it's wrong here
A marketing brochure is not evidence of control effectiveness because it is promotional material with no independent verification of the subcontractor's actual security posture. Accepting it would bypass the requirement for verifiable documentation such as SOC 2 Type II reports, ISO 27001 certificates, or evidence of penetration testing. Marketing claims may highlight capabilities while omitting known weaknesses or incidents. The organization needs objective, third-party attestation to make an informed approval decision.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.