Question 536 of 1,013
SY0-701 Security Program Management and Oversight Practice Question
Exhibit
Vendor due diligence summary -------------------------------------------------- Vendor: CloudInvoice SOC 2 Type II report: 22 months old Penetration test: completed, no high findings Subprocessors: 4 listed, 2 operate in another country Business continuity evidence: not provided Contract draft: no breach-notification window, no audit-rights clause
Based on the exhibit, what is the best next step before onboarding the vendor?
⚠ Common exam trap
It's easy for candidates to assume a penetration test is sufficient due diligence, overlooking that contractual security terms are legally binding and address ongoing compliance, not just a one-time technical check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a security addendum with breach-notification timing, subprocessor approval, and audit rights.
The exhibit indicates the vendor has not yet provided a security addendum, which is a critical contractual document that defines security obligations such as breach-notification timing, subprocessor approval, and audit rights. Without this addendum, the organization lacks enforceable guarantees for data protection and incident response, making onboarding premature. Option B directly addresses this gap by requiring the addendum before proceeding.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Approve the vendor because it already passed a penetration test.
Why it's wrong here
A penetration test is a point-in-time assessment and does not prove that the vendor maintains ongoing security controls, contractual protections, or business-continuity capabilities. The exhibit identifies governance gaps such as breach-notification timing, subprocessor oversight, and audit rights; approving based solely on a past pentest leaves those risks unresolved and could violate third-party risk management policy.
- ✓
Require a security addendum with breach-notification timing, subprocessor approval, and audit rights.
Why this is correct
Requiring a security addendum addresses the governance gaps highlighted in the exhibit by forcing the vendor to agree to enforceable breach-notification deadlines, prior approval for subprocessors, and independent audit rights. These contractual controls create accountability and give the organization ongoing visibility into the vendor’s security posture, including downstream subprocessor risks, before the workload is onboarded. This is the best next step because it closes the missing due-diligence and contractual gaps identified.
- ✗
Ask the vendor to provide source code so developers can review it.
Why it's wrong here
Asking for source code is an application-security measure that does not address the exhibit’s missing evidence around business continuity and third-party governance. The vendor may also be unwilling to share proprietary code, and a code review would not identify failures in operational processes like incident response or subprocessor management. Contractual oversight, not code inspection, is the priority when onboarding a vendor with identified governance gaps.
- ✗
Move the workload to an internal shared drive until the vendor is ready.
Why it's wrong here
Moving the workload to an internal shared drive does not resolve the vendor risk decision and may actually increase exposure if the shared drive lacks the organization’s own encryption, access controls, and audit logging. The exhibit’s governance gaps would remain unaddressed, and the organization would still need to negotiate the addendum or reject the vendor. This action is a workaround that avoids the root cause—missing contractual and continuity due diligence—rather than fixing it.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.