CompTIA Security+ SY0-701 Third-Party Risk Management Practice Test

 

Topic 25 focuses on Third-Party Risk Management for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which term describes evaluation of a supplier’s controls, practices, and risk before or during a business relationship?

  1. Due diligence
  2. Supply-chain analysis
  3. Rules of engagement
  4. Vendor security assessment

Correct Answer: D

 

Correct Answer

Answer D is correct because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship.

Incorrect Answers

Answer A is incorrect because Due diligence represents a different security function. Due diligence refers to reasonable investigation performed before making a business or risk decision.

Answer B is incorrect because Supply-chain analysis would fit a different scenario. Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships.

Answer C is incorrect because Rules of engagement addresses a different requirement. Rules of engagement refers to documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities.

 

Question 2

To gain evidence of how well a supplier resists realistic attack, which security approach should be selected?

  1. Third-party penetration test evidence
  2. Vendor security assessment
  3. Right-to-audit clause
  4. Master service agreement (MSA)

Correct Answer: A

 

Correct Answer

Answer A is correct because Third-party penetration test evidence means results from authorized security testing used to understand a vendor’s technical exposure.

Incorrect Answers

Answer B is incorrect because Vendor security assessment addresses a different requirement. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.

Answer C is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.

Answer D is incorrect because Master service agreement (MSA) addresses a different security requirement. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.

 

Question 3

Which term describes contract language giving a customer defined rights to review or assess a supplier’s controls?

  1. Vendor monitoring
  2. Statement of work (SOW)
  3. Right-to-audit clause
  4. Third-party penetration test evidence

Correct Answer: C

 

Correct Answer

Answer C is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls.

Incorrect Answers

Answer A is incorrect because Vendor monitoring represents a different security function. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.

Answer B is incorrect because Statement of work (SOW) addresses a different requirement. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.

Answer D is incorrect because Third-party penetration test evidence would fit a different scenario. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.

 

Question 4

To evaluate whether the supplier monitors and governs its security program, which security approach should be selected?

  1. Evidence of internal audits
  2. Business partners agreement (BPA)
  3. Conflict-of-interest review
  4. Due diligence

Correct Answer: A

 

Correct Answer

Answer A is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews.

Incorrect Answers

Answer B is incorrect because Business partners agreement (BPA) would fit a different scenario. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

Answer C is incorrect because Conflict-of-interest review addresses a different requirement. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

Answer D is incorrect because Due diligence addresses a different security requirement. Due diligence refers to reasonable investigation performed before making a business or risk decision.

 

Question 5

Which term describes security evaluation performed by an external party separate from the vendor’s management?

  1. Security questionnaire
  2. Vendor monitoring
  3. Statement of work (SOW)
  4. Independent assessment

Correct Answer: D

 

Correct Answer

Answer D is correct because Independent assessment means security evaluation performed by an external party separate from the vendor’s management.

Incorrect Answers

Answer A is incorrect because Security questionnaire would fit a different scenario. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.

Answer B is incorrect because Vendor monitoring addresses a different requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.

Answer C is incorrect because Statement of work (SOW) represents a different security function. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.

 

Question 6

To identify risk inherited through a supplier’s own ecosystem, which security approach should be selected?

  1. Non-disclosure agreement (NDA)
  2. Business partners agreement (BPA)
  3. Due diligence
  4. Supply-chain analysis

Correct Answer: D

 

Correct Answer

Answer D is correct because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships.

Incorrect Answers

Answer A is incorrect because Non-disclosure agreement (NDA) addresses a different requirement. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.

Answer B is incorrect because Business partners agreement (BPA) addresses a different security requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

Answer C is incorrect because Due diligence would fit a different scenario. Due diligence refers to reasonable investigation performed before making a business or risk decision.

 

Question 7

Which term describes reasonable investigation performed before making a business or risk decision?

  1. Service-level agreement (SLA)
  2. Due diligence
  3. Evidence of internal audits
  4. Business partners agreement (BPA)

Correct Answer: B

 

Correct Answer

Answer B is correct because Due diligence means reasonable investigation performed before making a business or risk decision.

Incorrect Answers

Answer A is incorrect because Service-level agreement (SLA) addresses a different requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.

Answer C is incorrect because Evidence of internal audits would fit a different scenario. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.

Answer D is incorrect because Business partners agreement (BPA) represents a different security function. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

 

Question 8

To reduce bias and governance risk during procurement, which security approach should be selected?

  1. Business partners agreement (BPA)
  2. Conflict-of-interest review
  3. Non-disclosure agreement (NDA)
  4. Service-level agreement (SLA)

Correct Answer: B

 

Correct Answer

Answer B is correct because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

Incorrect Answers

Answer A is incorrect because Business partners agreement (BPA) would fit a different scenario. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

Answer C is incorrect because Non-disclosure agreement (NDA) addresses a different security requirement. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.

Answer D is incorrect because Service-level agreement (SLA) addresses a different requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.

 

Question 9

Which term describes contractual definition of measurable service performance or availability commitments?

  1. Conflict-of-interest review
  2. Supply-chain analysis
  3. Business partners agreement (BPA)
  4. Service-level agreement (SLA)

Correct Answer: D

 

Correct Answer

Answer D is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments.

Incorrect Answers

Answer A is incorrect because Conflict-of-interest review would fit a different scenario. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

Answer B is incorrect because Supply-chain analysis represents a different security function. Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships.

Answer C is incorrect because Business partners agreement (BPA) addresses a different requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

 

Question 10

To record agreed responsibilities or cooperation at a high level, which security approach should be selected?

  1. Memorandum of understanding (MOU)
  2. Third-party penetration test evidence
  3. Statement of work (SOW)
  4. Vendor monitoring

Correct Answer: A

 

Correct Answer

Answer A is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract.

Incorrect Answers

Answer B is incorrect because Third-party penetration test evidence addresses a different requirement. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.

Answer C is incorrect because Statement of work (SOW) would fit a different scenario. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.

Answer D is incorrect because Vendor monitoring addresses a different security requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.

 

Question 11

Which term describes umbrella contract establishing general legal and commercial terms for ongoing services?

  1. Vendor monitoring
  2. Master service agreement (MSA)
  3. Supply-chain analysis
  4. Right-to-audit clause

Correct Answer: B

 

Correct Answer

Answer B is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services.

Incorrect Answers

Answer A is incorrect because Vendor monitoring addresses a different requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.

Answer C is incorrect because Supply-chain analysis represents a different security function. Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships.

Answer D is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.

 

Question 12

To make one engagement’s tasks and outputs explicit, which security approach should be selected?

  1. Statement of work (SOW)
  2. Independent assessment
  3. Vendor monitoring
  4. Right-to-audit clause

Correct Answer: A

 

Correct Answer

Answer A is correct because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.

Incorrect Answers

Answer B is incorrect because Independent assessment addresses a different security requirement. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.

Answer C is incorrect because Vendor monitoring would fit a different scenario. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.

Answer D is incorrect because Right-to-audit clause addresses a different requirement. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.

 

Question 13

Which term describes agreement restricting unauthorized disclosure of confidential information?

  1. Third-party penetration test evidence
  2. Memorandum of understanding (MOU)
  3. Non-disclosure agreement (NDA)
  4. Right-to-audit clause

Correct Answer: C

 

Correct Answer

Answer C is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information.

Incorrect Answers

Answer A is incorrect because Third-party penetration test evidence represents a different security function. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.

Answer B is incorrect because Memorandum of understanding (MOU) addresses a different requirement. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.

Answer D is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.

 

Question 14

To formalize security and operational obligations in a partnership, which security approach should be selected?

  1. Non-disclosure agreement (NDA)
  2. Business partners agreement (BPA)
  3. Security questionnaire
  4. Right-to-audit clause

Correct Answer: B

 

Correct Answer

Answer B is correct because Business partners agreement (BPA) means agreement defining responsibilities and expectations between organizations working together.

Incorrect Answers

Answer A is incorrect because Non-disclosure agreement (NDA) addresses a different requirement. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.

Answer C is incorrect because Security questionnaire would fit a different scenario. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.

Answer D is incorrect because Right-to-audit clause addresses a different security requirement. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.

 

Question 15

Which term describes ongoing review of supplier performance, control changes, incidents, and risk indicators?

  1. Service-level agreement (SLA)
  2. Vendor monitoring
  3. Memorandum of understanding (MOU)
  4. Conflict-of-interest review

Correct Answer: B

 

Correct Answer

Answer B is correct because Vendor monitoring means ongoing review of supplier performance, control changes, incidents, and risk indicators.

Incorrect Answers

Answer A is incorrect because Service-level agreement (SLA) addresses a different requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.

Answer C is incorrect because Memorandum of understanding (MOU) would fit a different scenario. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.

Answer D is incorrect because Conflict-of-interest review represents a different security function. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

 

Question 16

To screen or assess vendors efficiently using standardized evidence requests, which security approach should be selected?

  1. Statement of work (SOW)
  2. Independent assessment
  3. Security questionnaire
  4. Master service agreement (MSA)

Correct Answer: C

 

Correct Answer

Answer C is correct because Security questionnaire means structured set of questions used to collect information about a supplier’s controls and practices.

Incorrect Answers

Answer A is incorrect because Statement of work (SOW) addresses a different security requirement. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.

Answer B is incorrect because Independent assessment would fit a different scenario. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.

Answer D is incorrect because Master service agreement (MSA) addresses a different requirement. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.

 

Question 17

Which term describes documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities?

  1. Rules of engagement
  2. Security questionnaire
  3. Service-level agreement (SLA)
  4. Non-disclosure agreement (NDA)

Correct Answer: A

 

Correct Answer

Answer A is correct because Rules of engagement means documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities.

Incorrect Answers

Answer B is incorrect because Security questionnaire addresses a different requirement. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.

Answer C is incorrect because Service-level agreement (SLA) represents a different security function. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.

Answer D is incorrect because Non-disclosure agreement (NDA) would fit a different scenario. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.

 

Question 18

To determine whether a third party meets security requirements, which security approach should be selected?

  1. Master service agreement (MSA)
  2. Conflict-of-interest review
  3. Vendor security assessment
  4. Independent assessment

Correct Answer: C

 

Correct Answer

Answer C is correct because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship.

Incorrect Answers

Answer A is incorrect because Master service agreement (MSA) would fit a different scenario. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.

Answer B is incorrect because Conflict-of-interest review represents a different security function. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

Answer D is incorrect because Independent assessment addresses a different requirement. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.

 

Question 19

Which term describes results from authorized security testing used to understand a vendor’s technical exposure?

  1. Evidence of internal audits
  2. Third-party penetration test evidence
  3. Security questionnaire
  4. Conflict-of-interest review

Correct Answer: B

 

Correct Answer

Answer B is correct because Third-party penetration test evidence means results from authorized security testing used to understand a vendor’s technical exposure.

Incorrect Answers

Answer A is incorrect because Evidence of internal audits addresses a different security requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.

Answer C is incorrect because Security questionnaire addresses a different requirement. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.

Answer D is incorrect because Conflict-of-interest review would fit a different scenario. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

 

Question 20

To preserve the ability to verify third-party compliance, which security approach should be selected?

  1. Right-to-audit clause
  2. Evidence of internal audits
  3. Vendor monitoring
  4. Vendor security assessment

Correct Answer: A

 

Correct Answer

Answer A is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls.

Incorrect Answers

Answer B is incorrect because Evidence of internal audits addresses a different requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.

Answer C is incorrect because Vendor monitoring represents a different security function. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.

Answer D is incorrect because Vendor security assessment would fit a different scenario. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.

 

Question 21

Which term describes documentation showing a vendor performs its own structured control reviews?

  1. Rules of engagement
  2. Master service agreement (MSA)
  3. Evidence of internal audits
  4. Vendor security assessment

Correct Answer: C

 

Correct Answer

Answer C is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews.

Incorrect Answers

Answer A is incorrect because Rules of engagement would fit a different scenario. Rules of engagement refers to documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities.

Answer B is incorrect because Master service agreement (MSA) addresses a different requirement. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.

Answer D is incorrect because Vendor security assessment addresses a different security requirement. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.

 

Question 22

To gain more objective assurance about a supplier’s controls, which security approach should be selected?

  1. Evidence of internal audits
  2. Independent assessment
  3. Business partners agreement (BPA)
  4. Third-party penetration test evidence

Correct Answer: B

 

Correct Answer

Answer B is correct because Independent assessment means security evaluation performed by an external party separate from the vendor’s management.

Incorrect Answers

Answer A is incorrect because Evidence of internal audits would fit a different scenario. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.

Answer C is incorrect because Business partners agreement (BPA) represents a different security function. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

Answer D is incorrect because Third-party penetration test evidence addresses a different requirement. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.

 

Question 23

Which term describes review of upstream vendors, dependencies, components, and service relationships?

  1. Independent assessment
  2. Supply-chain analysis
  3. Evidence of internal audits
  4. Memorandum of understanding (MOU)

Correct Answer: B

 

Correct Answer

Answer B is correct because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships.

Incorrect Answers

Answer A is incorrect because Independent assessment would fit a different scenario. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.

Answer C is incorrect because Evidence of internal audits addresses a different requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.

Answer D is incorrect because Memorandum of understanding (MOU) addresses a different security requirement. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.

 

Question 24

To understand a vendor’s security posture before commitment, which security approach should be selected?

  1. Independent assessment
  2. Statement of work (SOW)
  3. Memorandum of understanding (MOU)
  4. Due diligence

Correct Answer: D

 

Correct Answer

Answer D is correct because Due diligence means reasonable investigation performed before making a business or risk decision.

Incorrect Answers

Answer A is incorrect because Independent assessment would fit a different scenario. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.

Answer B is incorrect because Statement of work (SOW) addresses a different requirement. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.

Answer C is incorrect because Memorandum of understanding (MOU) represents a different security function. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.

 

Question 25

Which term describes assessment of relationships or incentives that could compromise impartial vendor selection or oversight?

  1. Conflict-of-interest review
  2. Due diligence
  3. Service-level agreement (SLA)
  4. Memorandum of understanding (MOU)

Correct Answer: A

 

Correct Answer

Answer A is correct because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

Incorrect Answers

Answer B is incorrect because Due diligence addresses a different requirement. Due diligence refers to reasonable investigation performed before making a business or risk decision.

Answer C is incorrect because Service-level agreement (SLA) addresses a different security requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.

Answer D is incorrect because Memorandum of understanding (MOU) would fit a different scenario. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.

 

Question 26

To set expectations and remedies for service quality, which security approach should be selected?

  1. Service-level agreement (SLA)
  2. Memorandum of understanding (MOU)
  3. Vendor security assessment
  4. Right-to-audit clause

Correct Answer: A

 

Correct Answer

Answer A is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments.

Incorrect Answers

Answer B is incorrect because Memorandum of understanding (MOU) addresses a different requirement. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.

Answer C is incorrect because Vendor security assessment represents a different security function. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.

Answer D is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.

 

Question 27

Which term describes document describing a shared understanding or intent between parties, often less formal than a contract?

  1. Vendor security assessment
  2. Security questionnaire
  3. Vendor monitoring
  4. Memorandum of understanding (MOU)

Correct Answer: D

 

Correct Answer

Answer D is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract.

Incorrect Answers

Answer A is incorrect because Vendor security assessment would fit a different scenario. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.

Answer B is incorrect because Security questionnaire addresses a different security requirement. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.

Answer C is incorrect because Vendor monitoring addresses a different requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.

 

Question 28

To avoid renegotiating core terms for every individual work order, which security approach should be selected?

  1. Conflict-of-interest review
  2. Business partners agreement (BPA)
  3. Master service agreement (MSA)
  4. Non-disclosure agreement (NDA)

Correct Answer: C

 

Correct Answer

Answer C is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services.

Incorrect Answers

Answer A is incorrect because Conflict-of-interest review represents a different security function. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.

Answer B is incorrect because Business partners agreement (BPA) addresses a different requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

Answer D is incorrect because Non-disclosure agreement (NDA) would fit a different scenario. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.

 

Question 29

Which term describes document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement?

  1. Evidence of internal audits
  2. Business partners agreement (BPA)
  3. Statement of work (SOW)
  4. Master service agreement (MSA)

Correct Answer: C

 

Correct Answer

Answer C is correct because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.

Incorrect Answers

Answer A is incorrect because Evidence of internal audits addresses a different requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.

Answer B is incorrect because Business partners agreement (BPA) addresses a different security requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.

Answer D is incorrect because Master service agreement (MSA) would fit a different scenario. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.

 

Question 30

To protect sensitive information shared with a third party, which security approach should be selected?

  1. Service-level agreement (SLA)
  2. Evidence of internal audits
  3. Due diligence
  4. Non-disclosure agreement (NDA)

Correct Answer: D

 

Correct Answer

Answer D is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information.

Incorrect Answers

Answer A is incorrect because Service-level agreement (SLA) represents a different security function. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.

Answer B is incorrect because Evidence of internal audits would fit a different scenario. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.

Answer C is incorrect because Due diligence addresses a different requirement. Due diligence refers to reasonable investigation performed before making a business or risk decision.

img