Courseiva
Question 59 of 1,013
Security Program Management and OversightmediumMultiple ChoiceObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

A company is evaluating a new cloud-based customer relationship management (CRM) provider. The provider’s documentation includes a SOC 2 Type II report, but the company’s compliance team specifically requires evidence that data in transit is encrypted using TLS 1.2 or higher, and data at rest is encrypted with AES-256. Which of the following actions best demonstrates that the company has performed proper due diligence in vendor risk management?

⚠ Common exam trap

Many exam-takers assume a SOC 2 Type II report is a blanket certification of all security controls, when in fact it only attests to the controls that were specifically selected and tested, so failing to review the detailed control descriptions can lead to accepting a report that does not cover the required encryption standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Review the detailed control descriptions and auditor test results within the SOC 2 Type II report that address encryption of data in transit and at rest.

A SOC 2 Type II report includes detailed control descriptions and independent auditor test results that specifically verify whether encryption controls (TLS 1.2+ for data in transit and AES-256 for data at rest) are designed and operating effectively over a period of time. Reviewing these granular details allows the company to confirm compliance with its specific encryption requirements, which is a core component of due diligence in vendor risk management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Request the provider to sign a contractual service-level agreement (SLA) that guarantees encryption compliance.

    Why it's wrong here

    An SLA is a legal commitment, not evidence that controls are actually in place or effective. It does not replace verifying the provider’s actual implementation. While an SLA can be part of a contract, it should not be the sole basis for due diligence when audit reports are available.

    When this WOULD be correct

    This option would be correct if the question asked for the best way to ensure ongoing compliance after the contract is signed, or if the company had already verified encryption controls and needed a contractual remedy for non-compliance.

  • Accept the SOC 2 Type II report as sufficient and proceed without further review.

    Why it's wrong here

    Simply accepting the existence of a SOC 2 report without examining its details does not confirm that specific encryption requirements (TLS 1.2+ and AES-256) are covered. A SOC 2 report may cover many controls, but the company must verify that the exact control objectives and testing results match its own requirements.

    When this WOULD be correct

    This option would be correct if the compliance team required only a general assurance of security controls without specific encryption requirements, and the SOC 2 Type II report was from a reputable auditor covering all relevant control areas.

  • Review the detailed control descriptions and auditor test results within the SOC 2 Type II report that address encryption of data in transit and at rest.

    Why this is correct

    A SOC 2 Type II report includes a detailed description of controls, the control objectives, and the results of the auditor’s testing over a period of time. Reviewing these specific sections allows the company to verify that encryption controls are designed and operating effectively, which satisfies due diligence requirements for third-party risk management.

  • Conduct an independent penetration test on the provider’s infrastructure before signing the contract.

    Why it's wrong here

    While a penetration test can identify vulnerabilities, it is an additional cost and may not cover all encryption implementations. More importantly, a SOC 2 Type II report already provides audited evidence of control effectiveness; a penetration test would be redundant or complementary but is not the primary method for verifying encryption compliance during due diligence.

    When this WOULD be correct

    This option would be correct if the question asked for the most thorough validation of a provider's security posture when no third-party audit report is available, or if the provider is a high-risk vendor handling extremely sensitive data and the company requires independent verification beyond existing reports.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.

Review the detailed control descriptions and auditor test results within the SOC 2 Type II report that address encryption of data in transit and at rest.Correct answer

Why this is correct

A SOC 2 Type II report includes a detailed description of controls, the control objectives, and the results of the auditor’s testing over a period of time. Reviewing these specific sections allows the company to verify that encryption controls are designed and operating effectively, which satisfies due diligence requirements for third-party risk management.

Request the provider to sign a contractual service-level agreement (SLA) that guarantees encryption compliance.Wrong answer — click to see why

Why this is wrong here

An SLA guarantees future performance but does not provide evidence of current compliance; the company needs to verify encryption controls before accepting the provider, not just contractually promise them.

★ When this WOULD be the correct answer

This option would be correct if the question asked for the best way to ensure ongoing compliance after the contract is signed, or if the company had already verified encryption controls and needed a contractual remedy for non-compliance.

Why candidates choose this

Candidates may think a contractual SLA is a strong legal safeguard that forces compliance, overlooking that due diligence requires verifying actual controls, not just promises.

Accept the SOC 2 Type II report as sufficient and proceed without further review.Wrong answer — click to see why

Why this is wrong here

Accepting the SOC 2 Type II report as sufficient without reviewing its detailed controls and test results fails to verify that the specific encryption requirements (TLS 1.2+ for transit, AES-256 for at rest) are actually addressed, which is necessary for proper due diligence.

★ When this WOULD be the correct answer

This option would be correct if the compliance team required only a general assurance of security controls without specific encryption requirements, and the SOC 2 Type II report was from a reputable auditor covering all relevant control areas.

Why candidates choose this

Candidates may assume that a SOC 2 Type II report is a comprehensive certification that automatically covers all security requirements, leading them to believe no further review is needed.

Conduct an independent penetration test on the provider’s infrastructure before signing the contract.Wrong answer — click to see why

Why this is wrong here

Conducting an independent penetration test is not the best action because the company already has a SOC 2 Type II report that likely covers encryption controls; performing a separate pentest goes beyond the required due diligence and may not directly address the specific encryption requirements.

★ When this WOULD be the correct answer

This option would be correct if the question asked for the most thorough validation of a provider's security posture when no third-party audit report is available, or if the provider is a high-risk vendor handling extremely sensitive data and the company requires independent verification beyond existing reports.

Why candidates choose this

Candidates may think that a penetration test provides direct evidence of encryption implementation, but they overlook that the SOC 2 report already includes auditor-tested controls for encryption, making a separate pentest redundant and not the best demonstration of due diligence for this specific requirement.

Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.