Courseiva

SY0-701 Security Program Management and Oversight Practice Question

A company is signing a contract with a SaaS expense platform. Security wants the vendor to notify the company within 24 hours of a confirmed incident, maintain customer data segregation, and allow the company to verify security commitments if required. Which control should be added to the agreement?

⚠ Common exam trap

SY0-701 often tests the difference between an NDA (confidentiality only) and a security addendum/SLA (enforceable security and performance obligations) — candidates who pick the NDA overlook the need for incident notification and audit rights.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A security addendum with SLA terms

A security addendum with SLA terms is the correct control because it contractually binds the vendor to specific security obligations — 24-hour incident notification, data segregation, and the right to audit or verify security commitments. An addendum supplements the master agreement with enforceable security requirements, and SLA terms define measurable performance and response expectations. This gives the company legal recourse if the vendor fails to meet those commitments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A non-disclosure agreement only

    Why it's wrong here

    An NDA only restricts disclosure of confidential information; it imposes no 24-hour incident notification, no data segregation obligation and no verification rights. It is tempting because NDAs are standard pre-contract documents, but they address confidentiality alone, not the operational security commitments this scenario demands.

  • ✓

    A security addendum with SLA terms

    Why this is correct

    A security addendum with SLA terms contractually binds the vendor to the 24-hour breach notification window, enforces logical customer data segregation, and grants audit rights to verify commitments. Embedding these as enforceable service-level obligations satisfies all three stem constraints, unlike generic policy statements or technical controls the company cannot impose on a SaaS provider.

  • ✗

    A verbal assurance from the account representative

    Why it's wrong here

    A verbal assurance creates no enforceable obligation, so the 24-hour notification, data segregation and audit rights cannot be compelled. It is tempting because account representatives readily promise responsiveness, but verbal commitments belong nowhere in vendor risk management; only written contract terms bind the provider.

  • ✗

    The vendor's standard public terms without changes

    Why it's wrong here

    Standard public terms are drafted for the vendor's benefit and typically omit breach notification windows, segregation guarantees and customer audit rights. It is tempting because accepting them avoids negotiation delay, but unmodified terms cannot be tailored to the company's specific security requirements.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SY0-701

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A supplier tells your company it wants to use a new subcontractor to process customer data. What is the BEST contract control to reduce this risk?

easy
  • ✓ A.Require the vendor to notify the company before adding subcontractors
  • B.Allow subcontractors without review if the vendor remains responsible
  • C.Only require a verbal promise that the subcontractor is secure
  • D.Remove all contract language related to third parties

Why A: Requiring the vendor to notify the company before adding subcontractors is the best contract control because it ensures the company retains visibility and approval authority over any third party that will process customer data. This aligns with the principle of due diligence and third-party risk management, as the company can assess the subcontractor's security posture before data is shared. Without such a clause, the vendor could unilaterally introduce a subcontractor with inadequate security controls, increasing the risk of a data breach or compliance violation.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.