Courseiva
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A security manager at a hospital is reviewing the annual vendor risk assessment for a cloud-based electronic health record (EHR) provider. The provider's SOC 2 Type II report, issued six months ago, identifies a significant deficiency in logical access controls: the provider failed to revoke access for former employees in a timely manner. The provider's management has asserted that this deficiency has been fully remediated, but the next SOC 2 audit is not scheduled for another eight months. The hospital's data protection policy requires that any vendor handling protected health information (PHI) must have a current SOC 2 Type II report with no unresolved significant deficiencies. Which of the following is the most appropriate next step for the security manager?

⚠ Common exam trap

Many exam-takers think a vendor's self-attestation (Option A) is sufficient, but the SY0-701 exam emphasizes that independent third-party verification (like a bridge letter) is required when a significant deficiency exists and the next audit is months away.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require the vendor to provide a bridge letter from their external auditor confirming that the remediation has been implemented and is operating effectively.

The hospital's policy requires a current SOC 2 Type II report with no unresolved significant deficiencies. Since the deficiency was reported but is claimed to be fixed, a bridge letter from the external auditor provides independent assurance that the remediation is effective and operating as intended, bridging the gap until the next formal audit. This is the most appropriate step because it maintains compliance without prematurely terminating a critical vendor relationship.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the vendor's assertion that the deficiency has been remediated and continue the relationship as is.

    Why it's wrong here

    Accepting the vendor's unsupported assertion is unacceptable because it substitutes a self-serving management representation for the independent, attestation-level evidence the hospital's policy explicitly demands. A vendor stating it has 'fixed' the issue provides no verifiable data about control design, implementation, or operating effectiveness over time. This approach also ignores the policy's requirement for a current SOC 2 report with no unresolved significant deficiencies, and it creates an audit trail risk for the hospital if regulators or accreditation bodies question why no corroborating evidence was obtained. The correct action is to insist on an external auditor's bridge letter, not to rely on the vendor's word.

    When this WOULD be correct

    If the hospital's policy allowed reliance on vendor assertions for remediated findings, or if the vendor provided a detailed remediation report with evidence that was independently verified by the hospital's own audit team, then accepting the assertion could be appropriate.

  • Require the vendor to provide a bridge letter from their external auditor confirming that the remediation has been implemented and is operating effectively.

    Why this is correct

    A bridge letter is a formal letter issued by the vendor's external service auditor that addresses the period between the original SOC 2 report's end date and the current date. It provides independent, auditor-attested confirmation that the previously identified significant deficiency has been remediated and that the controls were operating effectively during the interim period. This is the standard industry practice for accepting client remediation when a full new SOC 2 report is not yet available, because it gives the hospital third-party assurance rather than relying solely on the vendor's own claim. Requiring this letter satisfies the policy's demand for independent verification while avoiding unnecessary contract termination.

  • Immediately terminate the contract with the EHR provider and begin the process of selecting a new vendor.

    Why it's wrong here

    Termination is a severe action that should be reserved for cases where the vendor cannot or will not demonstrate remediation. Since the vendor claims to have fixed the issue and can provide a bridge letter, termination is premature and would cause significant operational disruption.

    When this WOULD be correct

    If the vendor had a history of non-compliance, refused to provide evidence of remediation, or the deficiency posed an imminent risk to patient safety or data integrity, immediate termination might be justified.

  • Increase the frequency of manual access reviews performed by the hospital's internal IT staff on the vendor's systems.

    Why it's wrong here

    Manual reviews by internal staff are not a substitute for an independent audit report. The hospital's policy specifically requires a current SOC 2 report; internal reviews do not fulfill this requirement and are not scalable or reliable for this purpose.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Require the vendor to provide a bridge letter from their external auditor confirming that the remediation has been implemented and is operating effectively.Correct answer

Why this is correct

A bridge letter is a formal letter issued by the vendor's external service auditor that addresses the period between the original SOC 2 report's end date and the current date. It provides independent, auditor-attested confirmation that the previously identified significant deficiency has been remediated and that the controls were operating effectively during the interim period. This is the standard industry practice for accepting client remediation when a full new SOC 2 report is not yet available, because it gives the hospital third-party assurance rather than relying solely on the vendor's own claim. Requiring this letter satisfies the policy's demand for independent verification while avoiding unnecessary contract termination.

Accept the vendor's assertion that the deficiency has been remediated and continue the relationship as is.Wrong answer — click to see why

Why this is wrong here

The hospital's policy requires a current SOC 2 Type II report with no unresolved significant deficiencies. Accepting the vendor's assertion without independent verification violates this policy and exposes the hospital to compliance risk.

★ When this WOULD be the correct answer

If the hospital's policy allowed reliance on vendor assertions for remediated findings, or if the vendor provided a detailed remediation report with evidence that was independently verified by the hospital's own audit team, then accepting the assertion could be appropriate.

Why candidates choose this

Candidates may assume that a vendor's assertion is sufficient, especially if the vendor is trusted or the deficiency seems minor, but they overlook the policy requirement for independent verification.

Immediately terminate the contract with the EHR provider and begin the process of selecting a new vendor.Wrong answer — click to see why

Why this is wrong here

Immediate termination is too drastic; the vendor has asserted remediation and a bridge letter can provide interim assurance without disrupting healthcare operations.

★ When this WOULD be the correct answer

If the vendor had a history of non-compliance, refused to provide evidence of remediation, or the deficiency posed an imminent risk to patient safety or data integrity, immediate termination might be justified.

Why candidates choose this

Candidates may overreact to the significant deficiency and believe that any unresolved issue requires immediate contract termination, ignoring the possibility of interim controls or remediation verification.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.