Courseiva
Security Program Management and OversightmediumMatchingObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Match each procurement need to the vendor due diligence artifact or control that best fits. 1. Procurement wants independent evidence that a SaaS provider's controls operated effectively during the last year. 2. The team wants to know what files, libraries, and modules were included in a supplier's software build. 3. The business needs a signed agreement that defines how customer data is handled and what the vendor must do if an incident occurs. 4. The procurement team wants answers about MFA, logging, and incident response before onboarding a cloud supplier.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

SOC 2 Type II report

Software bill of materials (SBOM)

Data processing agreement (DPA)

Security questionnaire

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SOC 2 Type II: Independent evidence that a SaaS provider's controls operated effectively during the last year.

Each artifact or control directly addresses the procurement need: SOC 2 Type II provides independent audit evidence; SBOM lists software components; DPA is the legal agreement for data handling; security questionnaires gather specific security practices; pen test reports validate controls; BCP ensures continuity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SOC 2 Type II: Independent evidence that a SaaS provider's controls operated effectively during the last year.

    Why this is correct

    A SOC 2 Type II report is an independent attestation by a CPA firm that evaluates the effectiveness of a service organization's controls over a specified period, typically 6–12 months. It tests the design and operating effectiveness of controls against AICPA Trust Services Criteria (e.g., security, availability, and confidentiality). This is the appropriate artifact for a procurement need seeking continuous, period-based operational assurance, unlike a point-in-time test.

  • SBOM: A list of files, libraries, and modules included in a supplier's software build.

    Why this is correct

    A Software Bill of Materials (SBOM) is a machine-readable inventory of every third-party component, open-source library, and module included in a software build, along with version numbers and dependency relationships. For procurement, it directly answers the question of what exactly is inside the vendor's software, enabling security teams to cross-reference vulnerabilities (e.g., CVEs) and assess license and supply-chain risk. This artifact is essential for verifying that the supplier is not shipping code with known vulnerable dependencies.

  • DPA: A signed agreement that defines how customer data is handled and what the vendor must do if an incident occurs.

    Why this is correct

    A Data Processing Agreement (DPA) is a legally binding contract, required under regulations like GDPR and HIPAA, that defines the roles (controller/processor), processing instructions, subprocessor relationships, data subject rights, and security safeguards. It also mandates specific incident-response obligations, including breach notification timelines and liability allocation. This is the proper artifact for a procurement need centered on data-handling rules and post-incident commitments, as it creates enforceable legal duties rather than just describing intent.

  • Security questionnaire: A set of questions about MFA, logging, and incident response before onboarding a cloud supplier.

    Why this is correct

    A vendor security questionnaire is a standardized set of questions about security policies and technical controls, such as whether MFA is enforced, whether audit logs are retained, and whether there is an incident response team and plan. It is a primary pre-onboarding screening tool, allowing procurement to rapidly compare cloud suppliers' postures and identify red flags before deeper review. This artifact is best suited for gathering explicit assertions from the vendor about specific security practices, rather than relying on external audit reports.

  • Pen test report: Independent evidence that a SaaS provider's controls operated effectively during the last year.

    Why it's wrong here

    A penetration test report is wrong as evidence of controls operating effectively during the last year because it is a point-in-time assessment of a defined scope (e.g., network, web app) at a specific moment. A pen test evaluates exploitable vulnerabilities and demonstrates a security weakness or its absence, but it does not test the consistent operation of processes like access reviewing, patching, or monitoring. To prove controls worked continuously over 12 months, you need a SOC 2 Type II (or similar) attestation, not a single pentest snapshot.

  • BCP: A signed agreement that defines how customer data is handled and what the vendor must do if an incident occurs.

    Why it's wrong here

    A Business Continuity Plan (BCP) is an internal operational document that outlines how an organization will continue or restore critical business functions during a disruption, such as a natural disaster or cyberattack. It does not contain agreed terms for handling customer data or contractual incident-notification obligations between vendor and client; those conditions live in a Data Processing Agreement (DPA). Confusing the two is dangerous because a BCP lacks force of law, while a DPA creates enforceable responsibilities for data handling and breach response.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.