Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager at a healthcare organization is reviewing the results of a third-party vendor risk assessment for a cloud-based email service that will store protected health information (PHI). The assessment reveals that the vendor encrypts data at rest using AES-256 but does not support customer-managed encryption keys. The vendor's data center is located in a country that is not subject to HIPAA jurisdiction. The vendor's previous penetration test report is over 18 months old. Which of the following is the most appropriate risk management action for the security manager to take?

⚠ Common exam trap

A common mix-up: candidates assume strong encryption (AES-256) alone is sufficient for HIPAA compliance, ignoring the broader context of jurisdictional risk, key management, and the need for current third-party audit evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Request the vendor to obtain a current SOC 2 Type II report and review the findings before making a decision.

A SOC 2 Type II report provides an independent assessment of a vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time. Given the vendor's lack of customer-managed keys and outdated penetration test, the security manager needs a current, comprehensive audit report to evaluate whether compensating controls adequately mitigate the risks of storing PHI outside HIPAA jurisdiction. This action allows an informed risk acceptance or mitigation decision without prematurely terminating a potentially compliant service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the risk because the vendor uses strong encryption.

    Why it's wrong here

    While AES-256 encryption is strong, it does not address the full range of risks, such as the lack of customer-managed keys, the outdated penetration test, or legal/compliance exposure from storing PHI in a non-HIPAA jurisdiction. Accepting the risk based on encryption alone ignores these other critical factors.

    When this WOULD be correct

    A question where the vendor is fully compliant with all relevant regulations, has current audits, and the only residual risk is encryption strength—then accepting risk based on strong encryption would be appropriate.

  • Request the vendor to obtain a current SOC 2 Type II report and review the findings before making a decision.

    Why this is correct

    A SOC 2 Type II report provides an independent assessment of a service organization's controls over a period of time, including security, availability, and confidentiality. This is directly relevant for a cloud email service handling PHI. Reviewing this report gives the manager sufficient evidence to decide whether the vendor's current controls meet organizational and regulatory requirements.

  • Terminate the contract immediately and select a different vendor.

    Why it's wrong here

    Terminating immediately without further investigation may be an overreaction. The risks identified are notable but do not necessarily indicate that the vendor is in violation of HIPAA or unable to provide adequate security. A more measured approach, such as requesting updated documentation, should be taken first.

    When this WOULD be correct

    This option would be correct if the vendor had a critical security vulnerability that poses an immediate and unacceptable risk to PHI, such as a known data breach or failure to meet minimum security requirements, and no remediation is possible.

  • Require the vendor to implement customer-managed keys and provide a new penetration test report within 30 days.

    Why it's wrong here

    While customer-managed keys and current penetration testing are desirable, the vendor may not be able to support customer-managed keys in their product architecture, and requiring implementation within 30 days is likely unrealistic. This option attempts to treat the risk through a technical control that the vendor may not offer, making it less practical than requesting an existing SOC 2 report.

    When this WOULD be correct

    This option would be correct if the vendor already supported customer-managed keys and the penetration test report was only slightly outdated (e.g., 6 months old), and the organization had contractual leverage to enforce these changes quickly. For example, in a scenario where the vendor's service is critical and the risk is high but remediable.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Request the vendor to obtain a current SOC 2 Type II report and review the findings before making a decision.Correct answer

Why this is correct

A SOC 2 Type II report provides an independent assessment of a service organization's controls over a period of time, including security, availability, and confidentiality. This is directly relevant for a cloud email service handling PHI. Reviewing this report gives the manager sufficient evidence to decide whether the vendor's current controls meet organizational and regulatory requirements.

Accept the risk because the vendor uses strong encryption.Wrong answer — click to see why

Why this is wrong here

Accepting risk solely because AES-256 encryption is used ignores other critical risks: the vendor lacks customer-managed keys, is outside HIPAA jurisdiction, and has an outdated penetration test. Strong encryption alone does not ensure HIPAA compliance or adequate security posture.

★ When this WOULD be the correct answer

A question where the vendor is fully compliant with all relevant regulations, has current audits, and the only residual risk is encryption strength—then accepting risk based on strong encryption would be appropriate.

Why candidates choose this

Candidates may focus on the strong encryption as a positive factor and underestimate the importance of other controls like key management, jurisdiction, and current testing, leading them to believe the risk is acceptable.

Terminate the contract immediately and select a different vendor.Wrong answer — click to see why

Why this is wrong here

Terminating the contract immediately is premature because the vendor's lack of customer-managed keys and outdated penetration test are issues that can be addressed through further assessment, such as reviewing a current SOC 2 Type II report, before deciding to terminate.

★ When this WOULD be the correct answer

This option would be correct if the vendor had a critical security vulnerability that poses an immediate and unacceptable risk to PHI, such as a known data breach or failure to meet minimum security requirements, and no remediation is possible.

Why candidates choose this

Candidates may think that any non-compliance or outdated assessment warrants immediate termination, overlooking the need for a measured risk management process that includes further evaluation and remediation before contract termination.

Require the vendor to implement customer-managed keys and provide a new penetration test report within 30 days.Wrong answer — click to see why

Why this is wrong here

Requiring the vendor to implement customer-managed keys and provide a new penetration test report within 30 days is not feasible because the vendor does not support customer-managed keys, and 30 days is likely insufficient for a new penetration test. The security manager should first gather more information (e.g., SOC 2 Type II report) before imposing requirements.

★ When this WOULD be the correct answer

This option would be correct if the vendor already supported customer-managed keys and the penetration test report was only slightly outdated (e.g., 6 months old), and the organization had contractual leverage to enforce these changes quickly. For example, in a scenario where the vendor's service is critical and the risk is high but remediable.

Why candidates choose this

Candidates may think that demanding stronger controls (customer-managed keys) and up-to-date testing directly addresses the risks, without considering vendor capabilities or the need for evidence-based risk assessment first.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.