Drag a concept onto its matching description — or click a concept then click the description.
Right-to-audit clause
Subprocessor disclosure requirement
Breach-notification clause
SOC 2 Type II report
Match each vendor-risk concern to the contractual control that best addresses it. 1. The company wants the right to review the vendor's controls and supporting records after the contract is signed. 2. The company wants to know when the vendor will use subcontractors that may touch its data. 3. The company wants written notice within 24 hours if the vendor suffers an incident affecting company data. 4. The company wants assurance that the vendor's controls are independently assessed each year.
Drag a concept onto its matching description — or click a concept then click the description.
Right-to-audit clause
Subprocessor disclosure requirement
Breach-notification clause
SOC 2 Type II report
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Vendor control review: Right to audit
Right to audit allows reviewing controls; subcontractor clause requires notification; incident clause mandates timely breach notification; independent assessment ensures annual audits; DPA covers data protection; SLA defines service levels.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
Vendor control review: Right to audit
Why this is correct
The right to audit clause grants the customer contractual authority to inspect, review, and assess the vendor's security controls, processes, and evidence of compliance. This is the proper mechanism for verifying that the vendor's implemented safeguards actually meet the agreed-upon security requirements, rather than relying on vendor self-attestation. It typically includes provisions for reasonable notice, scope, frequency, and access to relevant documentation and systems.
Subcontractor notification: Subcontractor clause
Why this is correct
A subcontractor clause obligates the vendor to inform the customer when it plans to engage third-party subprocessors or subcontractors, and often requires the customer's consent before such engagement. This addresses the supply chain risk of unknown parties handling sensitive data, ensuring transparency and allowing the customer to assess the subvendor's security posture. It should also require that subcontractors be bound by equivalent data protection and security obligations.
Incident notification: Incident response clause
Why this is correct
An incident response clause defines the vendor's duty to detect, respond to, and report security incidents, including specific notification timelines such as within 24 hours of discovery. This is the contractual control that directly addresses the concern about timely notification, as it establishes clear procedures, escalation paths, and communication requirements. It goes beyond generic data handling rules by mandating action and transparency when a breach or security event occurs.
Annual independent assessment: Independent audit requirement
Why this is correct
An independent audit requirement mandates that the vendor undergo periodic assessments, such as SOC 2 Type II, ISO 27001 certification, or a third-party penetration test, on an annual basis. This ensures that the vendor's security controls are consistently and objectively evaluated by an external party, providing the customer with renewed assurance that the control environment remains effective over time. This is distinct from a right to audit, which allows the customer to conduct its own review, whereas this requires a formal independent evaluation.
Vendor control review: Subcontractor clause
Why it's wrong here
The subcontractor clause is designed to provide notification and consent mechanisms for the vendor's use of third-party subprocessors, not to grant the customer a right to review the vendor's own controls. While it may require subcontractors to meet security requirements, it does not give the customer the ability to inspect the vendor's systems, data handling, or security policies. Therefore, pairing vendor control review with a subcontractor clause is a mismatch because the clause addresses downstream parties, not the vendor's direct control environment.
Incident notification: Data protection agreement
Why it's wrong here
A data protection agreement (DPA) typically defines how data must be handled, processed, stored, and safeguarded, along with legal compliance obligations. While it may mention security measures and breach notifications in general terms, it does not establish a specific, operational incident notification timeline or response procedure. Thus, it is insufficient as the primary control for ensuring prompt notification; an incident response clause with defined notice periods is required to meet that concern.
Go deeper
Learn chapter
Risk Management Concepts
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.