SY0-701 Security Program Management and Oversight Practice Question
A software supplier used by your organization begins subcontracting a critical part of its service to an unknown hosting company. Which contractual control would BEST help manage this supply chain risk?
⚠ Common exam trap
Many exam-takers confuse operational reporting (Option A) with security governance, or they assume immediate termination (Option D) is a valid risk response without considering contractual due process and business continuity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require advance notice and approval for subcontractor changes, plus right-to-audit and security obligations.
It establishes a contractual control that requires the supplier to notify and obtain approval before subcontracting critical services, while also imposing right-to-audit and security obligations. This directly addresses supply chain risk by ensuring the organization can vet and monitor the subcontractor's security posture, as recommended by NIST SP 800-161 for supply chain risk management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require the supplier to send monthly sales updates to the procurement team.
Why it's wrong here
Requiring monthly sales updates is a business/performance metric, not a security control. It gives procurement financial visibility but provides no insight into the subcontractor's security posture, access privileges, or compliance with your organization's security requirements. Without contractual authority to audit or approve the subcontractor, the new attack surface remains completely unmanaged and unmitigated.
- ✓
Require advance notice and approval for subcontractor changes, plus right-to-audit and security obligations.
Why this is correct
This is the strongest contractual approach because it gives the organization visibility into changes, authority to review added risk, and leverage to enforce security requirements. When a supplier introduces a new subcontractor, advance notice, approval rights, and auditability help prevent hidden dependencies from undermining security expectations or compliance obligations.
- ✗
Ask the supplier to place all responsibility for the subcontractor on the customer.
Why it's wrong here
Asking the supplier to shift all responsibility for the subcontractor to the customer is not a control; it is an abdication of due diligence. As the customer, you would lack any contractual relationship, audit rights, or technical oversight of the third party, making you both legally exposed and operationally blind. This approach violates the core third-party risk management principle that you must maintain visibility and enforceable obligations across the entire supply chain.
- ✗
Disable all vendor access immediately without reviewing the change.
Why it's wrong here
Immediately disabling all vendor access is a disproportionate, reactive response that does not constitute a sustainable risk management control. While termination might be warranted in a critical incident, doing so without first assessing the actual risk of the new subcontractor disrupts operations and creates downtime without reducing long-term exposure. This approach also fails to establish a repeatable process for evaluating future supplier changes, leaving the organization without a proactive framework for supply chain risk.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.