Courseiva
Security Program Management and OversightmediumMatchingObjective-mapped

SY0-701 Security Program Management and Oversight Practice Question

Match each vendor-risk concern to the contractual control that best addresses it. 1. The company wants the right to review the vendor's controls and supporting records after the contract is signed. 2. The company wants to know when the vendor will use subcontractors that may touch its data. 3. The company wants written notice within 24 hours if the vendor suffers an incident affecting company data. 4. The company wants assurance that the vendor's controls are independently assessed each year.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Right-to-audit clause

Subprocessor disclosure requirement

Breach-notification clause

SOC 2 Type II report

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vendor control review: Right to audit

Right to audit allows reviewing controls; subcontractor clause requires notification; incident clause mandates timely breach notification; independent assessment ensures annual audits; DPA covers data protection; SLA defines service levels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Vendor control review: Right to audit

    Why this is correct

    The right to audit clause grants the customer contractual authority to inspect, review, and assess the vendor's security controls, processes, and evidence of compliance. This is the proper mechanism for verifying that the vendor's implemented safeguards actually meet the agreed-upon security requirements, rather than relying on vendor self-attestation. It typically includes provisions for reasonable notice, scope, frequency, and access to relevant documentation and systems.

  • Subcontractor notification: Subcontractor clause

    Why this is correct

    A subcontractor clause obligates the vendor to inform the customer when it plans to engage third-party subprocessors or subcontractors, and often requires the customer's consent before such engagement. This addresses the supply chain risk of unknown parties handling sensitive data, ensuring transparency and allowing the customer to assess the subvendor's security posture. It should also require that subcontractors be bound by equivalent data protection and security obligations.

  • Incident notification: Incident response clause

    Why this is correct

    An incident response clause defines the vendor's duty to detect, respond to, and report security incidents, including specific notification timelines such as within 24 hours of discovery. This is the contractual control that directly addresses the concern about timely notification, as it establishes clear procedures, escalation paths, and communication requirements. It goes beyond generic data handling rules by mandating action and transparency when a breach or security event occurs.

  • Annual independent assessment: Independent audit requirement

    Why this is correct

    An independent audit requirement mandates that the vendor undergo periodic assessments, such as SOC 2 Type II, ISO 27001 certification, or a third-party penetration test, on an annual basis. This ensures that the vendor's security controls are consistently and objectively evaluated by an external party, providing the customer with renewed assurance that the control environment remains effective over time. This is distinct from a right to audit, which allows the customer to conduct its own review, whereas this requires a formal independent evaluation.

  • Vendor control review: Subcontractor clause

    Why it's wrong here

    The subcontractor clause is designed to provide notification and consent mechanisms for the vendor's use of third-party subprocessors, not to grant the customer a right to review the vendor's own controls. While it may require subcontractors to meet security requirements, it does not give the customer the ability to inspect the vendor's systems, data handling, or security policies. Therefore, pairing vendor control review with a subcontractor clause is a mismatch because the clause addresses downstream parties, not the vendor's direct control environment.

  • Incident notification: Data protection agreement

    Why it's wrong here

    A data protection agreement (DPA) typically defines how data must be handled, processed, stored, and safeguarded, along with legal compliance obligations. While it may mention security measures and breach notifications in general terms, it does not establish a specific, operational incident notification timeline or response procedure. Thus, it is insufficient as the primary control for ensuring prompt notification; an incident response clause with defined notice periods is required to meet that concern.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.