Courseiva

SY0-701 Security Program Management and Oversight Practice Question

A security manager is developing a third-party risk management program. The organization plans to engage several new vendors that will process sensitive customer data. Which two actions should the security manager include to effectively manage third-party risk? (Choose two.)

⚠ Common exam trap

The trap here is thinking that cyber insurance or self-attestation can replace direct security assessments and monitoring, but these are not substitutes for verifying a vendor's security posture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a security assessment of each vendor before onboarding.

The correct actions are conducting a security assessment before onboarding and monitoring vendor security performance on an ongoing basis. Pre-onboarding assessments evaluate the vendor's security controls and compliance, while ongoing monitoring ensures continued adherence and early detection of changes. Together, they provide a proactive approach to third-party risk management. The other options—cyber insurance, full delegation to legal, and unverified self-attestation—are either insufficient or inappropriate as primary risk management actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delegate all vendor management to the legal department.

    Why it's wrong here

    Delegating all vendor management to the legal department is inappropriate because legal expertise focuses on contracts and compliance, not technical security controls. Security managers must be involved in assessing and monitoring vendor security. While legal should be part of the process, fully delegating to them would neglect the necessary security oversight. This action would not effectively manage third-party risk.

  • ✓

    Conduct a security assessment of each vendor before onboarding.

    Why this is correct

    Conducting a security assessment before onboarding is critical to evaluate the vendor's security posture, controls, and compliance with relevant standards. This due diligence helps identify risks early and informs contract negotiations. It ensures that the vendor meets the organization's security requirements and can be trusted with sensitive data. Without this step, the organization may unknowingly accept unacceptable risks.

  • ✗

    Require vendors to carry cyber insurance.

    Why it's wrong here

    Requiring cyber insurance can transfer some financial risk, but it does not assess or mitigate the vendor's security weaknesses. Insurance is a risk transference tactic, not a primary risk management action. While it can be part of a contract, it should not replace proactive measures like assessments and monitoring. The scenario asks for actions to manage third-party risk, and insurance alone is insufficient.

  • ✗

    Allow vendors to self-attest compliance without evidence.

    Why it's wrong here

    Permitting vendors to self-attest compliance without evidence is risky because it relies solely on the vendor's claims and does not verify the actual state of their security controls. Self-attestation can be easily falsified or outdated. Effective third-party risk management requires validation through assessments, audits, or independent reports. Therefore, this action would not adequately manage risk.

  • ✓

    Monitor vendor security performance on an ongoing basis.

    Why this is correct

    Ongoing monitoring of vendor security performance ensures that the vendor continues to meet contractual security requirements and that any changes in their risk profile are detected. This includes regular reviews, audits, and tracking of security incidents. Monitoring is essential because a vendor's security posture can degrade over time. It allows the organization to take timely corrective actions and maintain risk at acceptable levels.

About these practice questions

One of 1,030 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.