SY0-701 Security Program Management and Oversight Practice Question
A company is evaluating a new cloud-based customer relationship management (CRM) provider. The provider’s documentation includes a SOC 2 Type II report, but the company’s compliance team specifically requires evidence that data in transit is encrypted using TLS 1.2 or higher, and data at rest is encrypted with AES-256. Which of the following actions best demonstrates that the company has performed proper due diligence in vendor risk management?
⚠ Common exam trap
Many exam-takers assume a SOC 2 Type II report is a blanket certification of all security controls, when in fact it only attests to the controls that were specifically selected and tested, so failing to review the detailed control descriptions can lead to accepting a report that does not cover the required encryption standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the detailed control descriptions and auditor test results within the SOC 2 Type II report that address encryption of data in transit and at rest.
A SOC 2 Type II report includes detailed control descriptions and independent auditor test results that specifically verify whether encryption controls (TLS 1.2+ for data in transit and AES-256 for data at rest) are designed and operating effectively over a period of time. Reviewing these granular details allows the company to confirm compliance with its specific encryption requirements, which is a core component of due diligence in vendor risk management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request the provider to sign a contractual service-level agreement (SLA) that guarantees encryption compliance.
Why it's wrong here
An SLA is a legal commitment, not evidence that controls are actually in place or effective. It does not replace verifying the provider’s actual implementation. While an SLA can be part of a contract, it should not be the sole basis for due diligence when audit reports are available.
When this WOULD be correct
This option would be correct if the question asked for the best way to ensure ongoing compliance after the contract is signed, or if the company had already verified encryption controls and needed a contractual remedy for non-compliance.
- ✗
Accept the SOC 2 Type II report as sufficient and proceed without further review.
Why it's wrong here
Simply accepting the existence of a SOC 2 report without examining its details does not confirm that specific encryption requirements (TLS 1.2+ and AES-256) are covered. A SOC 2 report may cover many controls, but the company must verify that the exact control objectives and testing results match its own requirements.
When this WOULD be correct
This option would be correct if the compliance team required only a general assurance of security controls without specific encryption requirements, and the SOC 2 Type II report was from a reputable auditor covering all relevant control areas.
- ✓
Review the detailed control descriptions and auditor test results within the SOC 2 Type II report that address encryption of data in transit and at rest.
Why this is correct
A SOC 2 Type II report includes a detailed description of controls, the control objectives, and the results of the auditor’s testing over a period of time. Reviewing these specific sections allows the company to verify that encryption controls are designed and operating effectively, which satisfies due diligence requirements for third-party risk management.
- ✗
Conduct an independent penetration test on the provider’s infrastructure before signing the contract.
Why it's wrong here
While a penetration test can identify vulnerabilities, it is an additional cost and may not cover all encryption implementations. More importantly, a SOC 2 Type II report already provides audited evidence of control effectiveness; a penetration test would be redundant or complementary but is not the primary method for verifying encryption compliance during due diligence.
When this WOULD be correct
This option would be correct if the question asked for the most thorough validation of a provider's security posture when no third-party audit report is available, or if the provider is a high-risk vendor handling extremely sensitive data and the company requires independent verification beyond existing reports.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SY0-701 exam frequently reuses these exact scenarios with slightly different constraints.
✓Review the detailed control descriptions and auditor test results within the SOC 2 Type II report that address encryption of data in transit and at rest.Correct answer▾
Why this is correct
A SOC 2 Type II report includes a detailed description of controls, the control objectives, and the results of the auditor’s testing over a period of time. Reviewing these specific sections allows the company to verify that encryption controls are designed and operating effectively, which satisfies due diligence requirements for third-party risk management.
✗Request the provider to sign a contractual service-level agreement (SLA) that guarantees encryption compliance.Wrong answer — click to see why▾
Why this is wrong here
An SLA guarantees future performance but does not provide evidence of current compliance; the company needs to verify encryption controls before accepting the provider, not just contractually promise them.
★ When this WOULD be the correct answer
This option would be correct if the question asked for the best way to ensure ongoing compliance after the contract is signed, or if the company had already verified encryption controls and needed a contractual remedy for non-compliance.
Why candidates choose this
Candidates may think a contractual SLA is a strong legal safeguard that forces compliance, overlooking that due diligence requires verifying actual controls, not just promises.
✗Accept the SOC 2 Type II report as sufficient and proceed without further review.Wrong answer — click to see why▾
Why this is wrong here
Accepting the SOC 2 Type II report as sufficient without reviewing its detailed controls and test results fails to verify that the specific encryption requirements (TLS 1.2+ for transit, AES-256 for at rest) are actually addressed, which is necessary for proper due diligence.
★ When this WOULD be the correct answer
This option would be correct if the compliance team required only a general assurance of security controls without specific encryption requirements, and the SOC 2 Type II report was from a reputable auditor covering all relevant control areas.
Why candidates choose this
Candidates may assume that a SOC 2 Type II report is a comprehensive certification that automatically covers all security requirements, leading them to believe no further review is needed.
✗Conduct an independent penetration test on the provider’s infrastructure before signing the contract.Wrong answer — click to see why▾
Why this is wrong here
Conducting an independent penetration test is not the best action because the company already has a SOC 2 Type II report that likely covers encryption controls; performing a separate pentest goes beyond the required due diligence and may not directly address the specific encryption requirements.
★ When this WOULD be the correct answer
This option would be correct if the question asked for the most thorough validation of a provider's security posture when no third-party audit report is available, or if the provider is a high-risk vendor handling extremely sensitive data and the company requires independent verification beyond existing reports.
Why candidates choose this
Candidates may think that a penetration test provides direct evidence of encryption implementation, but they overlook that the SOC 2 report already includes auditor-tested controls for encryption, making a separate pentest redundant and not the best demonstration of due diligence for this specific requirement.
Analysis generated from the official SY0-701blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Hypertext Transfer Protocol Secure
Hypertext Transfer Protocol Secure, or HTTPS, is the secure version of HTTP that encrypts data between a web browser and a website using SSL/TLS to protect sensitive information like passwords and credit card numbers.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.