Courseiva
Security Program Management and OversighteasyMultiple SelectObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Before approving a new payroll SaaS provider, the security team wants independent evidence that the vendor's controls operated effectively during the last year and wants the contract to clearly define security responsibilities. Which two items should they request or review? Select two.

⚠ Common exam trap

Many candidates confuse a SOC 2 Type I report (point-in-time design review) with a Type II report (operational effectiveness over time), or they mistakenly believe that marketing materials or user interface screenshots can substitute for independent audit evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A SOC 2 Type II report

A SOC 2 Type II report provides independent, audited evidence that a vendor's controls (e.g., security, availability, confidentiality) were operating effectively over a specified period (typically 6–12 months). This directly meets the requirement for independent evidence of control effectiveness over the last year, unlike a point-in-time assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A SOC 2 Type II report

    Why this is correct

    A SOC 2 Type II report is the strongest evidence because an independent auditor tests and verifies that the vendor's security controls were not only designed properly but also operated effectively over a defined period, typically 6–12 months. This report directly addresses the trust services criteria of security, availability, processing integrity, confidentiality, and privacy, making it a reliable, third-party attestation for a payroll SaaS provider. It provides concrete assurance that control mechanisms such as access management, encryption, and incident response are actually functioning, which is exactly what a security team needs before approving a vendor.

  • A sales presentation from the vendor account team

    Why it's wrong here

    A sales presentation from the vendor account team is marketing material crafted to persuade prospects, and it does not provide independent or objective validation of the vendor's security posture. It often highlights desired features and capabilities while omitting gaps or past incidents, and the claims are made by the vendor itself without external verification. While it may give a high-level overview, it lacks the rigor of an audit report and cannot be trusted as evidence that controls are designed or operating effectively.

  • The vendor's public blog posts

    Why it's wrong here

    Public blog posts are informal, company-authored narratives that typically discuss trends, product updates, or technical topics, but they do not constitute a formal security assessment or independent audit. They are not subject to any standard, nor do they provide verifiable evidence about the vendor's control environment, compliance certifications, or incident response processes. Therefore, blog posts are not a reliable source for making procurement decisions that depend on demonstrated security controls and legal accountability.

  • Contract clauses covering security responsibilities and incident notification

    Why this is correct

    Contract clauses that explicitly specify security responsibilities, data handling requirements, and incident notification procedures are legally binding and provide a enforceable framework for the vendor's obligations. They clearly define which party is responsible for implementing and maintaining controls, what those controls must achieve, and how breaches or security events will be communicated. This makes contract language a vital complement to a SOC 2 report, because it converts security expectations into contractual duties that the vendor must meet or face legal consequences.

  • A screenshot of the login page

    Why it's wrong here

    A screenshot of the login page reveals only the user interface surface, giving no insight into the vendor's underlying security architecture, such as encryption in transit and at rest, backend access controls, logging, or data segmentation. Since a screenshot can be easily staged or altered, it carries no evidentiary weight regarding security posture, and it certainly lacks any information about the vendor's compliance with standards or legal obligations. It does not demonstrate that the organization has implemented effective security measures or that it will follow necessary notification and response protocols.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.