Drag a concept onto its matching description — or click a concept then click the description.
SOC 2 Type II report
Data processing agreement (DPA)
Software bill of materials (SBOM)
Right-to-audit clause
Disaster recovery test report
Match each procurement or oversight need to the best vendor due diligence artifact or clause. Use each item once.
Drag a concept onto its matching description — or click a concept then click the description.
SOC 2 Type II report
Data processing agreement (DPA)
Software bill of materials (SBOM)
Right-to-audit clause
Disaster recovery test report
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Assess security controls: Security questionnaire
These artifacts support vendor due diligence: questionnaires assess controls, SOC 2 reports provide independent assurance, audit clauses enable customer verification, DPAs govern data handling, BCPs ensure resilience, and pen tests validate security.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Assess security controls: Security questionnaire
Why this is correct
Security questionnaires are structured, vendor-specific assessments used during the pre-contract due diligence phase to gather self-reported information about controls such as access management, encryption, incident response, and compliance. They are the primary mechanism for initially assessing a vendor's security posture because they can be tailored to the customer's industry, regulatory burdens, and risk tolerance, and they surface red flags before a deeper review. Unlike independent audits, questionnaires rely on vendor disclosures but are cost-effective and efficient for screening a broad set of potential vendors.
Independent assurance: SOC 2 report
Why this is correct
A SOC 2 report provides independent, third-party assurance from a licensed CPA firm that a service organization's controls over security, availability, processing integrity, confidentiality, and privacy are suitably designed and operating effectively. It is not a general questionnaire but a formal attestation report issued under the AICPA Trust Services Criteria, often with a Type II opinion covering operational effectiveness over a specific period. This makes SOC 2 the correct option when a customer needs objective evidence of a vendor's control environment rather than a simple self-assessment.
Right to audit: Audit clause
Why this is correct
An audit clause is a contractual provision that grants the customer the explicit right to perform or commission audits of the vendor's systems, facilities, and controls to verify ongoing compliance with contractual and regulatory obligations. It establishes the terms for on-site inspections, access to relevant documentation, and even third-party assessments, and is essential for customers that cannot rely solely on self-reported or periodic third-party reports. This right is exercised when the customer needs direct, hands-on assurance of the vendor's security posture over the life of the contract.
Assess security controls: SOC 2 report
Why it's wrong here
Using a SOC 2 report to 'assess security controls' is a mismatch because a SOC 2 report is a retrospective, period-based independent attestation, not an interactive discovery tool for evaluating a specific vendor's fitness at onboarding. It may not cover all the unique risks the customer cares about, such as subprocessor arrangements, geographic data residency, or compliance with niche regulations, and it may be out of date by the time it is shared. Therefore, the standard method for initial security assessment remains a security questionnaire that directly queries the vendor on the relevant controls and lets the customer follow up on gaps.
Data protection: Business continuity plan
Why it's wrong here
Mapping 'data protection' to a business continuity plan is incorrect because a BCP is designed to keep critical business functions running during and after a disruption, addressing resilience and recovery times, not the legal or security controls required to protect personal data. Data protection, in contrast, revolves around lawful processing, confidentiality, breach notification, and data subject rights, which are typically governed by a data processing agreement (DPA) between the customer and vendor. A BCP might include backup and restoration measures, but that is only a tiny slice of data protection and doesn't address privacy obligations.
Go deeper
Learn chapter
Security Policies and Procedures
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.