Courseiva
Question 710 of 1,013
Security Program Management and OversighthardMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Exhibit

Supplier diligence summary:
- Vendor: Northstar Payroll Services
- SOC 2 Type II report received; one low-severity exception noted for delayed log review
- Subprocessor change notice: Vendor plans to move backup processing to SkyCove Hosting next month
- Contract terms: No clause requiring prior approval for new subprocessors
- Security team concern: Customer bank details will be included in the backup set

Based on the exhibit, what should the security team add before approving the vendor's requested change?

⚠ Common exam trap

CompTIA often tests the distinction between reactive controls (like insurance or monitoring) and proactive contractual controls (like approval clauses) in vendor change management scenarios, leading candidates to pick a monitoring or financial solution instead of the correct governance measure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A contract clause requiring prior written approval for new subprocessors and flow-down security obligations.

The exhibit shows the vendor requesting a change to use a new subprocessor for data storage. The security team must ensure that the vendor's contract includes a clause requiring prior written approval for new subprocessors and that security obligations flow down to them. This directly addresses the risk of unauthorized data handling by third parties, which is a key concern in vendor risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A broader employee awareness training requirement for the vendor's staff.

    Why it's wrong here

    Broader employee awareness training improves the vendor staff's phishing resistance and general security hygiene, but it does nothing to govern changes in the vendor's own supply chain. An unapproved subprocessor can be introduced without any training affecting that decision. This option misses the specific contractual and approval gap that created the exposure, so it fails as a direct mitigating control.

  • A contract clause requiring prior written approval for new subprocessors and flow-down security obligations.

    Why this is correct

    This is the strongest control because the risk comes from an unapproved change in the supply chain. Prior approval gives the customer visibility into who will process the data, and flow-down obligations ensure the subcontractor must meet the same security requirements. That directly addresses third-party risk, unlike insurance or generic training.

  • A larger cyber insurance policy to cover possible losses if the vendor is breached.

    Why it's wrong here

    A larger cyber insurance policy is a risk transfer mechanism that only reimburses financial losses after a breach occurs; it does nothing to prevent the vendor from handing payroll data to an unvetted subprocessor. Insurance policies typically contain exclusions for subcontractor negligence unless contractually vetted, and they never establish data-handling obligations or visibility. This is a reactive financial tool, not a proactive third-party risk control.

  • A request for the vendor to send monthly screenshots of its backup jobs.

    Why it's wrong here

    Requesting monthly backup screenshots is an artifact-based, point-in-time check that provides virtually no assurance about subprocessor changes or data-processing exposure. Screenshots can be manually generated or edited, and they do not prove that backup jobs are encrypted, restorable, or segregated from unapproved subcontractors. This option lacks any contractual force or ongoing verification mechanism, so it fails to address the core issue of unauthorized subprocessors.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 30, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.