SY0-701 Security Program Management and Oversight Practice Question
A company is signing a contract with a SaaS expense platform. Security wants the vendor to notify the company within 24 hours of a confirmed incident, maintain customer data segregation, and allow the company to verify security commitments if required. Which control should be added to the agreement?
⚠ Common exam trap
SY0-701 often tests the difference between an NDA (confidentiality only) and a security addendum/SLA (enforceable security and performance obligations) — candidates who pick the NDA overlook the need for incident notification and audit rights.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A security addendum with SLA terms
A security addendum with SLA terms is the correct control because it contractually binds the vendor to specific security obligations — 24-hour incident notification, data segregation, and the right to audit or verify security commitments. An addendum supplements the master agreement with enforceable security requirements, and SLA terms define measurable performance and response expectations. This gives the company legal recourse if the vendor fails to meet those commitments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A non-disclosure agreement only
Why it's wrong here
An NDA only restricts disclosure of confidential information; it imposes no 24-hour incident notification, no data segregation obligation and no verification rights. It is tempting because NDAs are standard pre-contract documents, but they address confidentiality alone, not the operational security commitments this scenario demands.
- ✓
A security addendum with SLA terms
Why this is correct
A security addendum with SLA terms contractually binds the vendor to the 24-hour breach notification window, enforces logical customer data segregation, and grants audit rights to verify commitments. Embedding these as enforceable service-level obligations satisfies all three stem constraints, unlike generic policy statements or technical controls the company cannot impose on a SaaS provider.
- ✗
A verbal assurance from the account representative
Why it's wrong here
A verbal assurance creates no enforceable obligation, so the 24-hour notification, data segregation and audit rights cannot be compelled. It is tempting because account representatives readily promise responsiveness, but verbal commitments belong nowhere in vendor risk management; only written contract terms bind the provider.
- ✗
The vendor's standard public terms without changes
Why it's wrong here
Standard public terms are drafted for the vendor's benefit and typically omit breach notification windows, segregation guarantees and customer audit rights. It is tempting because accepting them avoids negotiation delay, but unmodified terms cannot be tailored to the company's specific security requirements.
Go deeper
Related to this question
Learn chapter
Contractual Security Requirements
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A supplier tells your company it wants to use a new subcontractor to process customer data. What is the BEST contract control to reduce this risk?
easy- ✓ A.Require the vendor to notify the company before adding subcontractors
- B.Allow subcontractors without review if the vendor remains responsible
- C.Only require a verbal promise that the subcontractor is secure
- D.Remove all contract language related to third parties
Why A: Requiring the vendor to notify the company before adding subcontractors is the best contract control because it ensures the company retains visibility and approval authority over any third party that will process customer data. This aligns with the principle of due diligence and third-party risk management, as the company can assess the subcontractor's security posture before data is shared. Without such a clause, the vendor could unilaterally introduce a subcontractor with inadequate security controls, increasing the risk of a data breach or compliance violation.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.