CompTIA Security+ SY0-701 Third-Party Risk Management Practice Test
Topic 25 focuses on Third-Party Risk Management for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which term describes evaluation of a supplier’s controls, practices, and risk before or during a business relationship?
Correct Answer: D
Correct Answer
Answer D is correct because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Incorrect Answers
Answer A is incorrect because Due diligence represents a different security function. Due diligence refers to reasonable investigation performed before making a business or risk decision.
Answer B is incorrect because Supply-chain analysis would fit a different scenario. Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships.
Answer C is incorrect because Rules of engagement addresses a different requirement. Rules of engagement refers to documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities.
Question 2
To gain evidence of how well a supplier resists realistic attack, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Third-party penetration test evidence means results from authorized security testing used to understand a vendor’s technical exposure.
Incorrect Answers
Answer B is incorrect because Vendor security assessment addresses a different requirement. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Answer C is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.
Answer D is incorrect because Master service agreement (MSA) addresses a different security requirement. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.
Question 3
Which term describes contract language giving a customer defined rights to review or assess a supplier’s controls?
Correct Answer: C
Correct Answer
Answer C is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls.
Incorrect Answers
Answer A is incorrect because Vendor monitoring represents a different security function. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.
Answer B is incorrect because Statement of work (SOW) addresses a different requirement. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Answer D is incorrect because Third-party penetration test evidence would fit a different scenario. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.
Question 4
To evaluate whether the supplier monitors and governs its security program, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews.
Incorrect Answers
Answer B is incorrect because Business partners agreement (BPA) would fit a different scenario. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Answer C is incorrect because Conflict-of-interest review addresses a different requirement. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Answer D is incorrect because Due diligence addresses a different security requirement. Due diligence refers to reasonable investigation performed before making a business or risk decision.
Question 5
Which term describes security evaluation performed by an external party separate from the vendor’s management?
Correct Answer: D
Correct Answer
Answer D is correct because Independent assessment means security evaluation performed by an external party separate from the vendor’s management.
Incorrect Answers
Answer A is incorrect because Security questionnaire would fit a different scenario. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.
Answer B is incorrect because Vendor monitoring addresses a different requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.
Answer C is incorrect because Statement of work (SOW) represents a different security function. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Question 6
To identify risk inherited through a supplier’s own ecosystem, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships.
Incorrect Answers
Answer A is incorrect because Non-disclosure agreement (NDA) addresses a different requirement. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.
Answer B is incorrect because Business partners agreement (BPA) addresses a different security requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Answer C is incorrect because Due diligence would fit a different scenario. Due diligence refers to reasonable investigation performed before making a business or risk decision.
Question 7
Which term describes reasonable investigation performed before making a business or risk decision?
Correct Answer: B
Correct Answer
Answer B is correct because Due diligence means reasonable investigation performed before making a business or risk decision.
Incorrect Answers
Answer A is incorrect because Service-level agreement (SLA) addresses a different requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.
Answer C is incorrect because Evidence of internal audits would fit a different scenario. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.
Answer D is incorrect because Business partners agreement (BPA) represents a different security function. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Question 8
To reduce bias and governance risk during procurement, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Incorrect Answers
Answer A is incorrect because Business partners agreement (BPA) would fit a different scenario. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Answer C is incorrect because Non-disclosure agreement (NDA) addresses a different security requirement. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.
Answer D is incorrect because Service-level agreement (SLA) addresses a different requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.
Question 9
Which term describes contractual definition of measurable service performance or availability commitments?
Correct Answer: D
Correct Answer
Answer D is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments.
Incorrect Answers
Answer A is incorrect because Conflict-of-interest review would fit a different scenario. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Answer B is incorrect because Supply-chain analysis represents a different security function. Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships.
Answer C is incorrect because Business partners agreement (BPA) addresses a different requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Question 10
To record agreed responsibilities or cooperation at a high level, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract.
Incorrect Answers
Answer B is incorrect because Third-party penetration test evidence addresses a different requirement. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.
Answer C is incorrect because Statement of work (SOW) would fit a different scenario. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Answer D is incorrect because Vendor monitoring addresses a different security requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.
Question 11
Which term describes umbrella contract establishing general legal and commercial terms for ongoing services?
Correct Answer: B
Correct Answer
Answer B is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services.
Incorrect Answers
Answer A is incorrect because Vendor monitoring addresses a different requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.
Answer C is incorrect because Supply-chain analysis represents a different security function. Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships.
Answer D is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.
Question 12
To make one engagement’s tasks and outputs explicit, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Incorrect Answers
Answer B is incorrect because Independent assessment addresses a different security requirement. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.
Answer C is incorrect because Vendor monitoring would fit a different scenario. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.
Answer D is incorrect because Right-to-audit clause addresses a different requirement. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.
Question 13
Which term describes agreement restricting unauthorized disclosure of confidential information?
Correct Answer: C
Correct Answer
Answer C is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information.
Incorrect Answers
Answer A is incorrect because Third-party penetration test evidence represents a different security function. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.
Answer B is incorrect because Memorandum of understanding (MOU) addresses a different requirement. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.
Answer D is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.
Question 14
To formalize security and operational obligations in a partnership, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Business partners agreement (BPA) means agreement defining responsibilities and expectations between organizations working together.
Incorrect Answers
Answer A is incorrect because Non-disclosure agreement (NDA) addresses a different requirement. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.
Answer C is incorrect because Security questionnaire would fit a different scenario. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.
Answer D is incorrect because Right-to-audit clause addresses a different security requirement. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.
Question 15
Which term describes ongoing review of supplier performance, control changes, incidents, and risk indicators?
Correct Answer: B
Correct Answer
Answer B is correct because Vendor monitoring means ongoing review of supplier performance, control changes, incidents, and risk indicators.
Incorrect Answers
Answer A is incorrect because Service-level agreement (SLA) addresses a different requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.
Answer C is incorrect because Memorandum of understanding (MOU) would fit a different scenario. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.
Answer D is incorrect because Conflict-of-interest review represents a different security function. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Question 16
To screen or assess vendors efficiently using standardized evidence requests, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Security questionnaire means structured set of questions used to collect information about a supplier’s controls and practices.
Incorrect Answers
Answer A is incorrect because Statement of work (SOW) addresses a different security requirement. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Answer B is incorrect because Independent assessment would fit a different scenario. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.
Answer D is incorrect because Master service agreement (MSA) addresses a different requirement. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.
Question 17
Which term describes documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities?
Correct Answer: A
Correct Answer
Answer A is correct because Rules of engagement means documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities.
Incorrect Answers
Answer B is incorrect because Security questionnaire addresses a different requirement. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.
Answer C is incorrect because Service-level agreement (SLA) represents a different security function. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.
Answer D is incorrect because Non-disclosure agreement (NDA) would fit a different scenario. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.
Question 18
To determine whether a third party meets security requirements, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Incorrect Answers
Answer A is incorrect because Master service agreement (MSA) would fit a different scenario. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.
Answer B is incorrect because Conflict-of-interest review represents a different security function. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Answer D is incorrect because Independent assessment addresses a different requirement. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.
Question 19
Which term describes results from authorized security testing used to understand a vendor’s technical exposure?
Correct Answer: B
Correct Answer
Answer B is correct because Third-party penetration test evidence means results from authorized security testing used to understand a vendor’s technical exposure.
Incorrect Answers
Answer A is incorrect because Evidence of internal audits addresses a different security requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.
Answer C is incorrect because Security questionnaire addresses a different requirement. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.
Answer D is incorrect because Conflict-of-interest review would fit a different scenario. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Question 20
To preserve the ability to verify third-party compliance, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls.
Incorrect Answers
Answer B is incorrect because Evidence of internal audits addresses a different requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.
Answer C is incorrect because Vendor monitoring represents a different security function. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.
Answer D is incorrect because Vendor security assessment would fit a different scenario. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Question 21
Which term describes documentation showing a vendor performs its own structured control reviews?
Correct Answer: C
Correct Answer
Answer C is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews.
Incorrect Answers
Answer A is incorrect because Rules of engagement would fit a different scenario. Rules of engagement refers to documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities.
Answer B is incorrect because Master service agreement (MSA) addresses a different requirement. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.
Answer D is incorrect because Vendor security assessment addresses a different security requirement. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Question 22
To gain more objective assurance about a supplier’s controls, which security approach should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because Independent assessment means security evaluation performed by an external party separate from the vendor’s management.
Incorrect Answers
Answer A is incorrect because Evidence of internal audits would fit a different scenario. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.
Answer C is incorrect because Business partners agreement (BPA) represents a different security function. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Answer D is incorrect because Third-party penetration test evidence addresses a different requirement. Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure.
Question 23
Which term describes review of upstream vendors, dependencies, components, and service relationships?
Correct Answer: B
Correct Answer
Answer B is correct because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships.
Incorrect Answers
Answer A is incorrect because Independent assessment would fit a different scenario. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.
Answer C is incorrect because Evidence of internal audits addresses a different requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.
Answer D is incorrect because Memorandum of understanding (MOU) addresses a different security requirement. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.
Question 24
To understand a vendor’s security posture before commitment, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Due diligence means reasonable investigation performed before making a business or risk decision.
Incorrect Answers
Answer A is incorrect because Independent assessment would fit a different scenario. Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management.
Answer B is incorrect because Statement of work (SOW) addresses a different requirement. Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Answer C is incorrect because Memorandum of understanding (MOU) represents a different security function. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.
Question 25
Which term describes assessment of relationships or incentives that could compromise impartial vendor selection or oversight?
Correct Answer: A
Correct Answer
Answer A is correct because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Incorrect Answers
Answer B is incorrect because Due diligence addresses a different requirement. Due diligence refers to reasonable investigation performed before making a business or risk decision.
Answer C is incorrect because Service-level agreement (SLA) addresses a different security requirement. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.
Answer D is incorrect because Memorandum of understanding (MOU) would fit a different scenario. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.
Question 26
To set expectations and remedies for service quality, which security approach should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments.
Incorrect Answers
Answer B is incorrect because Memorandum of understanding (MOU) addresses a different requirement. Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract.
Answer C is incorrect because Vendor security assessment represents a different security function. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Answer D is incorrect because Right-to-audit clause would fit a different scenario. Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls.
Question 27
Which term describes document describing a shared understanding or intent between parties, often less formal than a contract?
Correct Answer: D
Correct Answer
Answer D is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract.
Incorrect Answers
Answer A is incorrect because Vendor security assessment would fit a different scenario. Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Answer B is incorrect because Security questionnaire addresses a different security requirement. Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices.
Answer C is incorrect because Vendor monitoring addresses a different requirement. Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators.
Question 28
To avoid renegotiating core terms for every individual work order, which security approach should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services.
Incorrect Answers
Answer A is incorrect because Conflict-of-interest review represents a different security function. Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Answer B is incorrect because Business partners agreement (BPA) addresses a different requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Answer D is incorrect because Non-disclosure agreement (NDA) would fit a different scenario. Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information.
Question 29
Which term describes document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement?
Correct Answer: C
Correct Answer
Answer C is correct because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Incorrect Answers
Answer A is incorrect because Evidence of internal audits addresses a different requirement. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.
Answer B is incorrect because Business partners agreement (BPA) addresses a different security requirement. Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together.
Answer D is incorrect because Master service agreement (MSA) would fit a different scenario. Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services.
Question 30
To protect sensitive information shared with a third party, which security approach should be selected?
Correct Answer: D
Correct Answer
Answer D is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information.
Incorrect Answers
Answer A is incorrect because Service-level agreement (SLA) represents a different security function. Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments.
Answer B is incorrect because Evidence of internal audits would fit a different scenario. Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews.
Answer C is incorrect because Due diligence addresses a different requirement. Due diligence refers to reasonable investigation performed before making a business or risk decision.
Popular posts
Recent Posts
