Topic 25 Practice Test 2 covers Third-Party Risk Management for CompTIA Security+ SY0-701 and maps to objective 5.3: Explain the processes associated with third-party risk assessment and management. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
To determine whether a third party meets security requirements, which security approach should be selected?
- Vendor security assessment
- Master service agreement (MSA)
- Independent assessment
- Conflict-of-interest review
Correct Answer: A
Correct Answer
Answer A is correct because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship. The deciding point is functional fit: this option covers the stated need, while Master service agreement (MSA) addresses umbrella contract establishing general legal and commercial terms for ongoing services.
Incorrect Answers
Answer B is incorrect because Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services. The key mismatch is functional: Vendor security assessment addresses evaluation of a supplier’s controls, practices, and risk before or during a business relationship, the need stated by the question.
Answer C is incorrect because Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management. The scenario instead requires evaluation of a supplier’s controls, practices, and risk before or during a business relationship, which is why Vendor security assessment is the better answer; this option serves the different function defined above.
Answer D is incorrect because Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The concept is valid, but it does not match this stem. The required function is evaluation of a supplier’s controls, practices, and risk before or during a business relationship, which maps to Vendor security assessment.
Question 2
To reduce bias and governance risk during procurement, which security approach should be selected?
- Conflict-of-interest review
- Business partners agreement (BPA)
- Non-disclosure agreement (NDA)
- Service-level agreement (SLA)
Correct Answer: A
Correct Answer
Answer A is correct because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight. This matches the requirement as written. Non-disclosure agreement (NDA) can be valid in another context, but it is used for agreement restricting unauthorized disclosure of confidential information.
Incorrect Answers
Answer B is incorrect because Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together. This could be appropriate elsewhere, but the required function is assessment of relationships or incentives that could compromise impartial vendor selection or oversight; that makes Conflict-of-interest review the precise choice.
Answer C is incorrect because Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information. The question is not asking for this function. It is testing assessment of relationships or incentives that could compromise impartial vendor selection or oversight, so Conflict-of-interest review is the stronger fit.
Answer D is incorrect because Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments. That concept can be valid in another scenario, but this question is testing assessment of relationships or incentives that could compromise impartial vendor selection or oversight; Conflict-of-interest review therefore fits the requirement more directly.
Question 3
Which term describes results from authorized security testing used to understand a vendor’s technical exposure?
- Security questionnaire
- Evidence of internal audits
- Conflict-of-interest review
- Third-party penetration test evidence
Correct Answer: D
Correct Answer
Answer D is correct because Third-party penetration test evidence means results from authorized security testing used to understand a vendor’s technical exposure. That makes it the best answer here; Security questionnaire addresses structured set of questions used to collect information about a supplier’s controls and practices, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices. The question is not asking for this function. It is testing results from authorized security testing used to understand a vendor’s technical exposure, so Third-party penetration test evidence is the stronger fit.
Answer B is incorrect because Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews. The scenario instead requires results from authorized security testing used to understand a vendor’s technical exposure, which is why Third-party penetration test evidence is the better answer; this option serves the different function defined above.
Answer C is incorrect because Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The question is not asking for this function. It is testing results from authorized security testing used to understand a vendor’s technical exposure, so Third-party penetration test evidence is the stronger fit.
Question 4
The control set for a third-party risk review must address both contract language giving a customer defined rights to review or assess a supplier’s controls and ongoing review of supplier performance, control changes, incidents, and risk indicators. Which TWO choices map directly to those needs? Choose TWO.
- Master service agreement (MSA)
- Right-to-audit clause
- Statement of work (SOW)
- Non-disclosure agreement (NDA)
- Vendor monitoring
Correct Answers: B, E
Correct Answers
Answer B is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls. It belongs in the fixed-count answer set because it covers one of the stated requirements. Master service agreement (MSA) instead serves umbrella contract establishing general legal and commercial terms for ongoing services and cannot replace this function.
Answer E is correct because Vendor monitoring means ongoing review of supplier performance, control changes, incidents, and risk indicators. This option satisfies a specific requirement in the stem; Non-disclosure agreement (NDA) serves agreement restricting unauthorized disclosure of confidential information and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services. The fixed-count answer set is Vendor monitoring, Right-to-audit clause; this option does not fill one of those named functions.
Answer C is incorrect because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. Every answer slot must map to a stated requirement. The correct set is Vendor monitoring, Right-to-audit clause, so this option cannot replace one of those selections.
Answer D is incorrect because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information. Every answer slot must map to a stated requirement. The correct set is Vendor monitoring, Right-to-audit clause, so this option cannot replace one of those selections.
Question 5
Which term describes security evaluation performed by an external party separate from the vendor’s management?
- Vendor monitoring
- Independent assessment
- Statement of work (SOW)
- Security questionnaire
Correct Answer: B
Correct Answer
Answer B is correct because Independent assessment means security evaluation performed by an external party separate from the vendor’s management. The deciding point is functional fit: this option covers the stated need, while Statement of work (SOW) addresses document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Incorrect Answers
Answer A is incorrect because Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators. That concept can be valid in another scenario, but this question is testing security evaluation performed by an external party separate from the vendor’s management; Independent assessment therefore fits the requirement more directly.
Answer C is incorrect because Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The scenario instead requires security evaluation performed by an external party separate from the vendor’s management, which is why Independent assessment is the better answer; this option serves the different function defined above.
Answer D is incorrect because Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices. This could be appropriate elsewhere, but the required function is security evaluation performed by an external party separate from the vendor’s management; that makes Independent assessment the precise choice.
Question 6
To set expectations and remedies for service quality, which security approach should be selected?
- Vendor security assessment
- Service-level agreement (SLA)
- Right-to-audit clause
- Memorandum of understanding (MOU)
Correct Answer: B
Correct Answer
Answer B is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments. The deciding point is functional fit: this option covers the stated need, while Right-to-audit clause addresses contract language giving a customer defined rights to review or assess a supplier’s controls.
Incorrect Answers
Answer A is incorrect because Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship. The question is not asking for this function. It is testing contractual definition of measurable service performance or availability commitments, so Service-level agreement (SLA) is the stronger fit.
Answer C is incorrect because Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls. This could be appropriate elsewhere, but the required function is contractual definition of measurable service performance or availability commitments; that makes Service-level agreement (SLA) the precise choice.
Answer D is incorrect because Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract. The scenario instead requires contractual definition of measurable service performance or availability commitments, which is why Service-level agreement (SLA) is the better answer; this option serves the different function defined above.
Question 7
To record agreed responsibilities or cooperation at a high level, which security approach should be selected?
- Vendor monitoring
- Third-party penetration test evidence
- Memorandum of understanding (MOU)
- Statement of work (SOW)
Correct Answer: C
Correct Answer
Answer C is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract. This matches the requirement as written. Vendor monitoring can be valid in another context, but it is used for ongoing review of supplier performance, control changes, incidents, and risk indicators.
Incorrect Answers
Answer A is incorrect because Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators. The key mismatch is functional: Memorandum of understanding (MOU) addresses document describing a shared understanding or intent between parties, often less formal than a contract, the need stated by the question.
Answer B is incorrect because Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure. The concept is valid, but it does not match this stem. The required function is document describing a shared understanding or intent between parties, often less formal than a contract, which maps to Memorandum of understanding (MOU).
Answer D is incorrect because Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. This could be appropriate elsewhere, but the required function is document describing a shared understanding or intent between parties, often less formal than a contract; that makes Memorandum of understanding (MOU) the precise choice.
Question 8
To preserve the ability to verify third-party compliance, which security approach should be selected?
- Vendor monitoring
- Vendor security assessment
- Evidence of internal audits
- Right-to-audit clause
Correct Answer: D
Correct Answer
Answer D is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls. That makes it the best answer here; Vendor security assessment addresses evaluation of a supplier’s controls, practices, and risk before or during a business relationship, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators. The concept is valid, but it does not match this stem. The required function is contract language giving a customer defined rights to review or assess a supplier’s controls, which maps to Right-to-audit clause.
Answer B is incorrect because Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship. That concept can be valid in another scenario, but this question is testing contract language giving a customer defined rights to review or assess a supplier’s controls; Right-to-audit clause therefore fits the requirement more directly.
Answer C is incorrect because Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews. This could be appropriate elsewhere, but the required function is contract language giving a customer defined rights to review or assess a supplier’s controls; that makes Right-to-audit clause the precise choice.
Question 9
Which term describes contract language giving a customer defined rights to review or assess a supplier’s controls?
- Vendor monitoring
- Third-party penetration test evidence
- Right-to-audit clause
- Statement of work (SOW)
Correct Answer: C
Correct Answer
Answer C is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls. This matches the requirement as written. Statement of work (SOW) can be valid in another context, but it is used for document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Incorrect Answers
Answer A is incorrect because Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators. The key mismatch is functional: Right-to-audit clause addresses contract language giving a customer defined rights to review or assess a supplier’s controls, the need stated by the question.
Answer B is incorrect because Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure. That concept can be valid in another scenario, but this question is testing contract language giving a customer defined rights to review or assess a supplier’s controls; Right-to-audit clause therefore fits the requirement more directly.
Answer D is incorrect because Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The scenario instead requires contract language giving a customer defined rights to review or assess a supplier’s controls, which is why Right-to-audit clause is the better answer; this option serves the different function defined above.
Question 10
An architect working on a third-party risk review needs one capability that provides contract language giving a customer defined rights to review or assess a supplier’s controls and another that provides agreement restricting unauthorized disclosure of confidential information. Which TWO selections are the best match? Choose TWO.
- Security questionnaire
- Evidence of internal audits
- Right-to-audit clause
- Non-disclosure agreement (NDA)
- Statement of work (SOW)
Correct Answers: C, D
Correct Answers
Answer C is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls. This selection maps directly to one of the named needs. Evidence of internal audits addresses documentation showing a vendor performs its own structured control reviews, so it does not satisfy the same slot.
Answer D is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information. It belongs in the fixed-count answer set because it covers one of the stated requirements. Evidence of internal audits instead serves documentation showing a vendor performs its own structured control reviews and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Security questionnaire means structured set of questions used to collect information about a supplier’s controls and practices. The fixed-count answer set is Non-disclosure agreement (NDA), Right-to-audit clause; this option does not fill one of those named functions.
Answer B is incorrect because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. The fixed-count answer set is Non-disclosure agreement (NDA), Right-to-audit clause; this option does not fill one of those named functions.
Answer E is incorrect because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The fixed-count answer set is Non-disclosure agreement (NDA), Right-to-audit clause; this option does not fill one of those named functions.
Question 11
The control set for a third-party risk review must address both reasonable investigation performed before making a business or risk decision and umbrella contract establishing general legal and commercial terms for ongoing services. Which TWO choices map directly to those needs? Choose TWO.
- Independent assessment
- Master service agreement (MSA)
- Due diligence
- Memorandum of understanding (MOU)
- Statement of work (SOW)
Correct Answers: B, C
Correct Answers
Answer B is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services. It belongs in the fixed-count answer set because it covers one of the stated requirements. Independent assessment instead serves security evaluation performed by an external party separate from the vendor’s management and cannot replace this function.
Answer C is correct because Due diligence means reasonable investigation performed before making a business or risk decision. One required function is exactly what this option provides. Statement of work (SOW) may be useful elsewhere, but it is used for document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement.
Incorrect Answers
Answer A is incorrect because Independent assessment means security evaluation performed by an external party separate from the vendor’s management. Every answer slot must map to a stated requirement. The correct set is Due diligence, Master service agreement (MSA), so this option cannot replace one of those selections.
Answer D is incorrect because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract. The required choices are Due diligence, Master service agreement (MSA). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer E is incorrect because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The question requires exactly 2 selections: Due diligence, Master service agreement (MSA). This option falls outside that required set.
Question 12
Which term describes agreement restricting unauthorized disclosure of confidential information?
- Non-disclosure agreement (NDA)
- Memorandum of understanding (MOU)
- Third-party penetration test evidence
- Right-to-audit clause
Correct Answer: A
Correct Answer
Answer A is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information. This matches the requirement as written. Right-to-audit clause can be valid in another context, but it is used for contract language giving a customer defined rights to review or assess a supplier’s controls.
Incorrect Answers
Answer B is incorrect because Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract. The scenario instead requires agreement restricting unauthorized disclosure of confidential information, which is why Non-disclosure agreement (NDA) is the better answer; this option serves the different function defined above.
Answer C is incorrect because Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure. The key mismatch is functional: Non-disclosure agreement (NDA) addresses agreement restricting unauthorized disclosure of confidential information, the need stated by the question.
Answer D is incorrect because Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls. That concept can be valid in another scenario, but this question is testing agreement restricting unauthorized disclosure of confidential information; Non-disclosure agreement (NDA) therefore fits the requirement more directly.
Question 13
Which term describes umbrella contract establishing general legal and commercial terms for ongoing services?
- Right-to-audit clause
- Master service agreement (MSA)
- Vendor monitoring
- Supply-chain analysis
Correct Answer: B
Correct Answer
Answer B is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services. The requirement maps directly to this function, whereas Right-to-audit clause is aimed at contract language giving a customer defined rights to review or assess a supplier’s controls.
Incorrect Answers
Answer A is incorrect because Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls. The concept is valid, but it does not match this stem. The required function is umbrella contract establishing general legal and commercial terms for ongoing services, which maps to Master service agreement (MSA).
Answer C is incorrect because Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators. The key mismatch is functional: Master service agreement (MSA) addresses umbrella contract establishing general legal and commercial terms for ongoing services, the need stated by the question.
Answer D is incorrect because Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships. The question is not asking for this function. It is testing umbrella contract establishing general legal and commercial terms for ongoing services, so Master service agreement (MSA) is the stronger fit.
Question 14
Reviewers working through a third-party risk review identify three separate needs: documentation showing a vendor performs its own structured control reviews; contractual definition of measurable service performance or availability commitments; structured set of questions used to collect information about a supplier’s controls and practices. Which THREE choices map to those needs? Choose THREE.
- Security questionnaire
- Conflict-of-interest review
- Service-level agreement (SLA)
- Non-disclosure agreement (NDA)
- Evidence of internal audits
- Statement of work (SOW)
Correct Answers: A, C, E
Correct Answers
Answer A is correct because Security questionnaire means structured set of questions used to collect information about a supplier’s controls and practices. One required function is exactly what this option provides. Non-disclosure agreement (NDA) may be useful elsewhere, but it is used for agreement restricting unauthorized disclosure of confidential information.
Answer C is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments. One required function is exactly what this option provides. Conflict-of-interest review may be useful elsewhere, but it is used for assessment of relationships or incentives that could compromise impartial vendor selection or oversight.
Answer E is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. This option satisfies a specific requirement in the stem; Statement of work (SOW) serves document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The scenario calls for Service-level agreement (SLA), Evidence of internal audits, Security questionnaire. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information. The required choices are Service-level agreement (SLA), Evidence of internal audits, Security questionnaire. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer F is incorrect because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The fixed-count answer set is Service-level agreement (SLA), Evidence of internal audits, Security questionnaire; this option does not fill one of those named functions.
Question 15
To avoid renegotiating core terms for every individual work order, which security approach should be selected?
- Master service agreement (MSA)
- Conflict-of-interest review
- Business partners agreement (BPA)
- Non-disclosure agreement (NDA)
Correct Answer: A
Correct Answer
Answer A is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services. The deciding point is functional fit: this option covers the stated need, while Non-disclosure agreement (NDA) addresses agreement restricting unauthorized disclosure of confidential information.
Incorrect Answers
Answer B is incorrect because Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The key mismatch is functional: Master service agreement (MSA) addresses umbrella contract establishing general legal and commercial terms for ongoing services, the need stated by the question.
Answer C is incorrect because Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together. The key mismatch is functional: Master service agreement (MSA) addresses umbrella contract establishing general legal and commercial terms for ongoing services, the need stated by the question.
Answer D is incorrect because Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information. This could be appropriate elsewhere, but the required function is umbrella contract establishing general legal and commercial terms for ongoing services; that makes Master service agreement (MSA) the precise choice.
Question 16
An architect working on a third-party risk review needs one capability that provides contract language giving a customer defined rights to review or assess a supplier’s controls and another that provides documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities. Which TWO selections are the best match? Choose TWO.
- Vendor security assessment
- Statement of work (SOW)
- Rules of engagement
- Right-to-audit clause
- Security questionnaire
Correct Answers: C, D
Correct Answers
Answer C is correct because Rules of engagement means documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities. One required function is exactly what this option provides. Security questionnaire may be useful elsewhere, but it is used for structured set of questions used to collect information about a supplier’s controls and practices.
Answer D is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls. It belongs in the fixed-count answer set because it covers one of the stated requirements. Statement of work (SOW) instead serves document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship. The fixed-count answer set is Rules of engagement, Right-to-audit clause; this option does not fill one of those named functions.
Answer B is incorrect because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The fixed-count answer set is Rules of engagement, Right-to-audit clause; this option does not fill one of those named functions.
Answer E is incorrect because Security questionnaire means structured set of questions used to collect information about a supplier’s controls and practices. The fixed-count answer set is Rules of engagement, Right-to-audit clause; this option does not fill one of those named functions.
Question 17
Which term describes evaluation of a supplier’s controls, practices, and risk before or during a business relationship?
- Due diligence
- Supply-chain analysis
- Vendor security assessment
- Rules of engagement
Correct Answer: C
Correct Answer
Answer C is correct because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship. This matches the requirement as written. Due diligence can be valid in another context, but it is used for reasonable investigation performed before making a business or risk decision.
Incorrect Answers
Answer A is incorrect because Due diligence refers to reasonable investigation performed before making a business or risk decision. The question is not asking for this function. It is testing evaluation of a supplier’s controls, practices, and risk before or during a business relationship, so Vendor security assessment is the stronger fit.
Answer B is incorrect because Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships. The question is not asking for this function. It is testing evaluation of a supplier’s controls, practices, and risk before or during a business relationship, so Vendor security assessment is the stronger fit.
Answer D is incorrect because Rules of engagement refers to documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities. The concept is valid, but it does not match this stem. The required function is evaluation of a supplier’s controls, practices, and risk before or during a business relationship, which maps to Vendor security assessment.
Question 18
Which term describes contractual definition of measurable service performance or availability commitments?
- Business partners agreement (BPA)
- Conflict-of-interest review
- Supply-chain analysis
- Service-level agreement (SLA)
Correct Answer: D
Correct Answer
Answer D is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments. That is the function the question is testing. Business partners agreement (BPA) would instead be used for agreement defining responsibilities and expectations between organizations working together.
Incorrect Answers
Answer A is incorrect because Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together. The scenario instead requires contractual definition of measurable service performance or availability commitments, which is why Service-level agreement (SLA) is the better answer; this option serves the different function defined above.
Answer B is incorrect because Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The question is not asking for this function. It is testing contractual definition of measurable service performance or availability commitments, so Service-level agreement (SLA) is the stronger fit.
Answer C is incorrect because Supply-chain analysis refers to review of upstream vendors, dependencies, components, and service relationships. This could be appropriate elsewhere, but the required function is contractual definition of measurable service performance or availability commitments; that makes Service-level agreement (SLA) the precise choice.
Question 19
A review during a third-party risk review identifies two gaps. One requires document describing a shared understanding or intent between parties, often less formal than a contract. The other requires ongoing review of supplier performance, control changes, incidents, and risk indicators. Which TWO options should be included in the remediation plan? Choose TWO.
- Service-level agreement (SLA)
- Master service agreement (MSA)
- Evidence of internal audits
- Memorandum of understanding (MOU)
- Vendor monitoring
Correct Answers: D, E
Correct Answers
Answer D is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract. This option satisfies a specific requirement in the stem; Master service agreement (MSA) serves umbrella contract establishing general legal and commercial terms for ongoing services and therefore is not interchangeable with it.
Answer E is correct because Vendor monitoring means ongoing review of supplier performance, control changes, incidents, and risk indicators. This selection maps directly to one of the named needs. Evidence of internal audits addresses documentation showing a vendor performs its own structured control reviews, so it does not satisfy the same slot.
Incorrect Answers
Answer A is incorrect because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments. The question requires exactly 2 selections: Vendor monitoring, Memorandum of understanding (MOU). This option falls outside that required set. For example, Vendor monitoring is required for ongoing review of supplier performance, control changes, incidents, and risk indicators.
Answer B is incorrect because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services. The required choices are Vendor monitoring, Memorandum of understanding (MOU). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. Every answer slot must map to a stated requirement. The correct set is Vendor monitoring, Memorandum of understanding (MOU), so this option cannot replace one of those selections.
Question 20
To make one engagement’s tasks and outputs explicit, which security approach should be selected?
- Vendor monitoring
- Independent assessment
- Right-to-audit clause
- Statement of work (SOW)
Correct Answer: D
Correct Answer
Answer D is correct because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The requirement maps directly to this function, whereas Independent assessment is aimed at security evaluation performed by an external party separate from the vendor’s management.
Incorrect Answers
Answer A is incorrect because Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators. The scenario instead requires document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement, which is why Statement of work (SOW) is the better answer; this option serves the different function defined above.
Answer B is incorrect because Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management. The question is not asking for this function. It is testing document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement, so Statement of work (SOW) is the stronger fit.
Answer C is incorrect because Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls. The key mismatch is functional: Statement of work (SOW) addresses document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement, the need stated by the question.