Question 1,068 of 1,013
SY0-701 Security Program Management and Oversight Practice Question
A software supplier is adding a new subcontractor to process your company's customer data. The security team wants to understand the new exposure before allowing the change. Which three items should it request or review first? Select three.
⚠ Common exam trap
The trap here is that candidates may mistakenly think marketing materials or logos are relevant for security assessments, when in fact only operational, legal, and technical documentation (like locations and DPAs) provide actionable risk information.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A list of the subcontractor's locations and where the data will be processed.
Understanding where data will be processed and the subcontractor's physical locations is critical for assessing jurisdictional risks, data sovereignty requirements, and compliance with regulations like GDPR or CCPA. The security team needs this information to evaluate potential exposure to different legal frameworks and physical security controls before granting access to customer data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A list of the subcontractor's locations and where the data will be processed.
Why this is correct
Knowing the specific locations where a subcontractor operates and where it will process data allows the organization to map data flows to legal jurisdictions. This is essential for assessing compliance with data protection regulations such as GDPR, which restrict cross-border transfers to countries without an adequacy decision, and for understanding whether data will be subject to foreign government access or conflicting privacy laws. Without this information, the organization cannot properly perform a risk assessment or meet its own regulatory obligations.
- ✗
The subcontractor's logo and marketing brochure.
Why it's wrong here
A logo and marketing brochure are promotional artifacts that describe what a vendor claims to do, not evidence of how it protects data. They contain no verifiable details about security controls, data privacy practices, access management, or incident response capabilities, and they are easily embellished. Relying on such materials would be superficial due diligence that fails to identify actual risk exposure, making them irrelevant to evaluating a new subcontractor.
- ✓
A data-processing agreement that flows down security and notification obligations.
Why this is correct
A data-processing agreement (DPA) that explicitly flows down security and breach-notification obligations ensures the subcontractor is contractually bound to the same standards as the primary supplier. This legal instrument creates enforceable duties to implement appropriate technical and organizational measures, to notify the controller of personal data breaches within the required timeframe, and to cooperate with audits or regulatory requests. It also establishes liability and recourse in the event of non-compliance, which is critical when a supplier introduces another party into the processing chain.
- ✓
An independent security assessment, such as a SOC report or equivalent.
Why this is correct
An independent security assessment, such as a SOC 2 Type II report or an ISO 27001 certification, provides objective evidence that the subcontractor has implemented suitable controls over a defined period. Unlike a self-assessment or contractual promise, these reports are produced by qualified third parties who examine actual security practices against established criteria, including security, availability, and confidentiality. Reviewing the report's scope and exceptions is necessary because a report may exclude certain systems or services, and a certification can become outdated if the environment changes.
- ✗
The supplier's quarterly sales forecast.
Why it's wrong here
The subcontractor's quarterly sales forecast is a financial projection of expected revenue, containing no information about any aspect of data security, privacy protection, or regulatory compliance. It neither demonstrates the existence of security controls nor reveals how data will be processed, stored, or protected, and it has no bearing on access management or breach response. Consequently, it provides zero value in the due diligence process for onboarding a new subcontractor.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.