Topic 25 Practice Test 1 covers Third-Party Risk Management for CompTIA Security+ SY0-701 and maps to objective 5.3: Explain the processes associated with third-party risk assessment and management. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
To understand a vendor’s security posture before commitment, which security approach should be selected?
- Memorandum of understanding (MOU)
- Statement of work (SOW)
- Independent assessment
- Due diligence
Correct Answer: D
Correct Answer
Answer D is correct because Due diligence means reasonable investigation performed before making a business or risk decision. The requirement maps directly to this function, whereas Independent assessment is aimed at security evaluation performed by an external party separate from the vendor’s management.
Incorrect Answers
Answer A is incorrect because Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract. The key mismatch is functional: Due diligence addresses reasonable investigation performed before making a business or risk decision, the need stated by the question.
Answer B is incorrect because Statement of work (SOW) refers to document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The concept is valid, but it does not match this stem. The required function is reasonable investigation performed before making a business or risk decision, which maps to Due diligence.
Answer C is incorrect because Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management. That concept can be valid in another scenario, but this question is testing reasonable investigation performed before making a business or risk decision; Due diligence therefore fits the requirement more directly.
Question 2
A review during a third-party risk review identifies two gaps. One requires documentation showing a vendor performs its own structured control reviews. The other requires umbrella contract establishing general legal and commercial terms for ongoing services. Which TWO options should be included in the remediation plan? Choose TWO.
- Due diligence
- Master service agreement (MSA)
- Conflict-of-interest review
- Evidence of internal audits
- Independent assessment
Correct Answers: B, D
Correct Answers
Answer B is correct because Master service agreement (MSA) means umbrella contract establishing general legal and commercial terms for ongoing services. One required function is exactly what this option provides. Independent assessment may be useful elsewhere, but it is used for security evaluation performed by an external party separate from the vendor’s management.
Answer D is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. The fixed-count item needs this function in the answer set. Independent assessment covers security evaluation performed by an external party separate from the vendor’s management, a different requirement.
Incorrect Answers
Answer A is incorrect because Due diligence means reasonable investigation performed before making a business or risk decision. Every answer slot must map to a stated requirement. The correct set is Evidence of internal audits, Master service agreement (MSA), so this option cannot replace one of those selections.
Answer C is incorrect because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The scenario calls for Evidence of internal audits, Master service agreement (MSA). Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Independent assessment means security evaluation performed by an external party separate from the vendor’s management. The required choices are Evidence of internal audits, Master service agreement (MSA). Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 3
To protect sensitive information shared with a third party, which security approach should be selected?
- Service-level agreement (SLA)
- Due diligence
- Non-disclosure agreement (NDA)
- Evidence of internal audits
Correct Answer: C
Correct Answer
Answer C is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information. The deciding point is functional fit: this option covers the stated need, while Due diligence addresses reasonable investigation performed before making a business or risk decision.
Incorrect Answers
Answer A is incorrect because Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments. This could be appropriate elsewhere, but the required function is agreement restricting unauthorized disclosure of confidential information; that makes Non-disclosure agreement (NDA) the precise choice.
Answer B is incorrect because Due diligence refers to reasonable investigation performed before making a business or risk decision. That concept can be valid in another scenario, but this question is testing agreement restricting unauthorized disclosure of confidential information; Non-disclosure agreement (NDA) therefore fits the requirement more directly.
Answer D is incorrect because Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews. The key mismatch is functional: Non-disclosure agreement (NDA) addresses agreement restricting unauthorized disclosure of confidential information, the need stated by the question.
Question 4
Which term describes ongoing review of supplier performance, control changes, incidents, and risk indicators?
- Service-level agreement (SLA)
- Memorandum of understanding (MOU)
- Vendor monitoring
- Conflict-of-interest review
Correct Answer: C
Correct Answer
Answer C is correct because Vendor monitoring means ongoing review of supplier performance, control changes, incidents, and risk indicators. This is the precise fit for the scenario. Memorandum of understanding (MOU) serves the different purpose of document describing a shared understanding or intent between parties, often less formal than a contract.
Incorrect Answers
Answer A is incorrect because Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments. The scenario instead requires ongoing review of supplier performance, control changes, incidents, and risk indicators, which is why Vendor monitoring is the better answer; this option serves the different function defined above.
Answer B is incorrect because Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract. The question is not asking for this function. It is testing ongoing review of supplier performance, control changes, incidents, and risk indicators, so Vendor monitoring is the stronger fit.
Answer D is incorrect because Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The question is not asking for this function. It is testing ongoing review of supplier performance, control changes, incidents, and risk indicators, so Vendor monitoring is the stronger fit.
Question 5
Which term describes documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities?
- Non-disclosure agreement (NDA)
- Service-level agreement (SLA)
- Security questionnaire
- Rules of engagement
Correct Answer: D
Correct Answer
Answer D is correct because Rules of engagement means documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities. The requirement maps directly to this function, whereas Non-disclosure agreement (NDA) is aimed at agreement restricting unauthorized disclosure of confidential information.
Incorrect Answers
Answer A is incorrect because Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information. The key mismatch is functional: Rules of engagement addresses documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities, the need stated by the question.
Answer B is incorrect because Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments. That concept can be valid in another scenario, but this question is testing documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities; Rules of engagement therefore fits the requirement more directly.
Answer C is incorrect because Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices. The key mismatch is functional: Rules of engagement addresses documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities, the need stated by the question.
Question 6
Which term describes documentation showing a vendor performs its own structured control reviews?
- Vendor security assessment
- Evidence of internal audits
- Rules of engagement
- Master service agreement (MSA)
Correct Answer: B
Correct Answer
Answer B is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. The requirement maps directly to this function, whereas Vendor security assessment is aimed at evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Incorrect Answers
Answer A is incorrect because Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship. That concept can be valid in another scenario, but this question is testing documentation showing a vendor performs its own structured control reviews; Evidence of internal audits therefore fits the requirement more directly.
Answer C is incorrect because Rules of engagement refers to documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities. The question is not asking for this function. It is testing documentation showing a vendor performs its own structured control reviews, so Evidence of internal audits is the stronger fit.
Answer D is incorrect because Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services. The concept is valid, but it does not match this stem. The required function is documentation showing a vendor performs its own structured control reviews, which maps to Evidence of internal audits.
Question 7
Which term describes document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement?
- Master service agreement (MSA)
- Business partners agreement (BPA)
- Evidence of internal audits
- Statement of work (SOW)
Correct Answer: D
Correct Answer
Answer D is correct because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. This matches the requirement as written. Business partners agreement (BPA) can be valid in another context, but it is used for agreement defining responsibilities and expectations between organizations working together.
Incorrect Answers
Answer A is incorrect because Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services. The scenario instead requires document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement, which is why Statement of work (SOW) is the better answer; this option serves the different function defined above.
Answer B is incorrect because Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together. The question is not asking for this function. It is testing document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement, so Statement of work (SOW) is the stronger fit.
Answer C is incorrect because Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews. The scenario instead requires document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement, which is why Statement of work (SOW) is the better answer; this option serves the different function defined above.
Question 8
Two requirements remain open in a third-party risk review: document describing a shared understanding or intent between parties, often less formal than a contract; agreement restricting unauthorized disclosure of confidential information. Which TWO options close those specific gaps? Choose TWO.
- Independent assessment
- Right-to-audit clause
- Vendor security assessment
- Non-disclosure agreement (NDA)
- Memorandum of understanding (MOU)
Correct Answers: D, E
Correct Answers
Answer D is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information. One required function is exactly what this option provides. Vendor security assessment may be useful elsewhere, but it is used for evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Answer E is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract. The fixed-count item needs this function in the answer set. Right-to-audit clause covers contract language giving a customer defined rights to review or assess a supplier’s controls, a different requirement.
Incorrect Answers
Answer A is incorrect because Independent assessment means security evaluation performed by an external party separate from the vendor’s management. The fixed-count answer set is Non-disclosure agreement (NDA), Memorandum of understanding (MOU); this option does not fill one of those named functions.
Answer B is incorrect because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls. The question requires exactly 2 selections: Non-disclosure agreement (NDA), Memorandum of understanding (MOU). This option falls outside that required set.
Answer C is incorrect because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship. The fixed-count answer set is Non-disclosure agreement (NDA), Memorandum of understanding (MOU); this option does not fill one of those named functions.
Question 9
Two requirements remain open in a third-party risk review: agreement restricting unauthorized disclosure of confidential information; documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities. Which TWO options close those specific gaps? Choose TWO.
- Due diligence
- Non-disclosure agreement (NDA)
- Supply-chain analysis
- Independent assessment
- Rules of engagement
Correct Answers: B, E
Correct Answers
Answer B is correct because Non-disclosure agreement (NDA) means agreement restricting unauthorized disclosure of confidential information. This option satisfies a specific requirement in the stem; Supply-chain analysis serves review of upstream vendors, dependencies, components, and service relationships and therefore is not interchangeable with it.
Answer E is correct because Rules of engagement means documented boundaries, permissions, timing, and constraints for testing or other sensitive third-party activities. This option satisfies a specific requirement in the stem; Independent assessment serves security evaluation performed by an external party separate from the vendor’s management and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Due diligence means reasonable investigation performed before making a business or risk decision. The fixed-count answer set is Non-disclosure agreement (NDA), Rules of engagement; this option does not fill one of those named functions.
Answer C is incorrect because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships. The fixed-count answer set is Non-disclosure agreement (NDA), Rules of engagement; this option does not fill one of those named functions. For example, Non-disclosure agreement (NDA) is required for agreement restricting unauthorized disclosure of confidential information.
Answer D is incorrect because Independent assessment means security evaluation performed by an external party separate from the vendor’s management. The fixed-count answer set is Non-disclosure agreement (NDA), Rules of engagement; this option does not fill one of those named functions.
Question 10
To evaluate whether the supplier monitors and governs its security program, which security approach should be selected?
- Business partners agreement (BPA)
- Due diligence
- Evidence of internal audits
- Conflict-of-interest review
Correct Answer: C
Correct Answer
Answer C is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. The deciding point is functional fit: this option covers the stated need, while Due diligence addresses reasonable investigation performed before making a business or risk decision.
Incorrect Answers
Answer A is incorrect because Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together. The concept is valid, but it does not match this stem. The required function is documentation showing a vendor performs its own structured control reviews, which maps to Evidence of internal audits.
Answer B is incorrect because Due diligence refers to reasonable investigation performed before making a business or risk decision. The key mismatch is functional: Evidence of internal audits addresses documentation showing a vendor performs its own structured control reviews, the need stated by the question.
Answer D is incorrect because Conflict-of-interest review refers to assessment of relationships or incentives that could compromise impartial vendor selection or oversight. This could be appropriate elsewhere, but the required function is documentation showing a vendor performs its own structured control reviews; that makes Evidence of internal audits the precise choice.
Question 11
Which term describes assessment of relationships or incentives that could compromise impartial vendor selection or oversight?
- Conflict-of-interest review
- Memorandum of understanding (MOU)
- Due diligence
- Service-level agreement (SLA)
Correct Answer: A
Correct Answer
Answer A is correct because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight. That makes it the best answer here; Service-level agreement (SLA) addresses contractual definition of measurable service performance or availability commitments, not the function requested in the stem.
Incorrect Answers
Answer B is incorrect because Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract. The concept is valid, but it does not match this stem. The required function is assessment of relationships or incentives that could compromise impartial vendor selection or oversight, which maps to Conflict-of-interest review.
Answer C is incorrect because Due diligence refers to reasonable investigation performed before making a business or risk decision. The concept is valid, but it does not match this stem. The required function is assessment of relationships or incentives that could compromise impartial vendor selection or oversight, which maps to Conflict-of-interest review.
Answer D is incorrect because Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments. The concept is valid, but it does not match this stem. The required function is assessment of relationships or incentives that could compromise impartial vendor selection or oversight, which maps to Conflict-of-interest review.
Question 12
Which term describes document describing a shared understanding or intent between parties, often less formal than a contract?
- Vendor monitoring
- Security questionnaire
- Vendor security assessment
- Memorandum of understanding (MOU)
Correct Answer: D
Correct Answer
Answer D is correct because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract. This matches the requirement as written. Vendor security assessment can be valid in another context, but it is used for evaluation of a supplier’s controls, practices, and risk before or during a business relationship.
Incorrect Answers
Answer A is incorrect because Vendor monitoring refers to ongoing review of supplier performance, control changes, incidents, and risk indicators. The question is not asking for this function. It is testing document describing a shared understanding or intent between parties, often less formal than a contract, so Memorandum of understanding (MOU) is the stronger fit.
Answer B is incorrect because Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices. The key mismatch is functional: Memorandum of understanding (MOU) addresses document describing a shared understanding or intent between parties, often less formal than a contract, the need stated by the question.
Answer C is incorrect because Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship. This could be appropriate elsewhere, but the required function is document describing a shared understanding or intent between parties, often less formal than a contract; that makes Memorandum of understanding (MOU) the precise choice.
Question 13
During a third-party risk review, three requirements must be addressed: (1) contract language giving a customer defined rights to review or assess a supplier’s controls; (2) documentation showing a vendor performs its own structured control reviews; and (3) contractual definition of measurable service performance or availability commitments. Which THREE choices best satisfy them? Choose THREE.
- Vendor monitoring
- Right-to-audit clause
- Statement of work (SOW)
- Supply-chain analysis
- Service-level agreement (SLA)
- Evidence of internal audits
Correct Answers: B, E, F
Correct Answers
Answer B is correct because Right-to-audit clause means contract language giving a customer defined rights to review or assess a supplier’s controls. The fixed-count item needs this function in the answer set. Statement of work (SOW) covers document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement, a different requirement.
Answer E is correct because Service-level agreement (SLA) means contractual definition of measurable service performance or availability commitments. This selection maps directly to one of the named needs. Vendor monitoring addresses ongoing review of supplier performance, control changes, incidents, and risk indicators, so it does not satisfy the same slot.
Answer F is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. One required function is exactly what this option provides. Supply-chain analysis may be useful elsewhere, but it is used for review of upstream vendors, dependencies, components, and service relationships.
Incorrect Answers
Answer A is incorrect because Vendor monitoring means ongoing review of supplier performance, control changes, incidents, and risk indicators. The required choices are Service-level agreement (SLA), Evidence of internal audits, Right-to-audit clause. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Answer C is incorrect because Statement of work (SOW) means document defining the specific scope, deliverables, timeline, and responsibilities for a project or engagement. The scenario calls for Service-level agreement (SLA), Evidence of internal audits, Right-to-audit clause. Selecting this option would leave one of those required functions uncovered.
Answer D is incorrect because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships. The fixed-count answer set is Service-level agreement (SLA), Evidence of internal audits, Right-to-audit clause; this option does not fill one of those named functions.
Question 14
Which term describes reasonable investigation performed before making a business or risk decision?
- Due diligence
- Business partners agreement (BPA)
- Evidence of internal audits
- Service-level agreement (SLA)
Correct Answer: A
Correct Answer
Answer A is correct because Due diligence means reasonable investigation performed before making a business or risk decision. That is the function the question is testing. Evidence of internal audits would instead be used for documentation showing a vendor performs its own structured control reviews.
Incorrect Answers
Answer B is incorrect because Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together. The question is not asking for this function. It is testing reasonable investigation performed before making a business or risk decision, so Due diligence is the stronger fit.
Answer C is incorrect because Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews. The key mismatch is functional: Due diligence addresses reasonable investigation performed before making a business or risk decision, the need stated by the question.
Answer D is incorrect because Service-level agreement (SLA) refers to contractual definition of measurable service performance or availability commitments. The question is not asking for this function. It is testing reasonable investigation performed before making a business or risk decision, so Due diligence is the stronger fit.
Question 15
To formalize security and operational obligations in a partnership, which security approach should be selected?
- Right-to-audit clause
- Business partners agreement (BPA)
- Security questionnaire
- Non-disclosure agreement (NDA)
Correct Answer: B
Correct Answer
Answer B is correct because Business partners agreement (BPA) means agreement defining responsibilities and expectations between organizations working together. That is the function the question is testing. Non-disclosure agreement (NDA) would instead be used for agreement restricting unauthorized disclosure of confidential information.
Incorrect Answers
Answer A is incorrect because Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls. That concept can be valid in another scenario, but this question is testing agreement defining responsibilities and expectations between organizations working together; Business partners agreement (BPA) therefore fits the requirement more directly.
Answer C is incorrect because Security questionnaire refers to structured set of questions used to collect information about a supplier’s controls and practices. This could be appropriate elsewhere, but the required function is agreement defining responsibilities and expectations between organizations working together; that makes Business partners agreement (BPA) the precise choice.
Answer D is incorrect because Non-disclosure agreement (NDA) refers to agreement restricting unauthorized disclosure of confidential information. This could be appropriate elsewhere, but the required function is agreement defining responsibilities and expectations between organizations working together; that makes Business partners agreement (BPA) the precise choice.
Question 16
Two requirements remain open in a third-party risk review: documentation showing a vendor performs its own structured control reviews; ongoing review of supplier performance, control changes, incidents, and risk indicators. Which TWO options close those specific gaps? Choose TWO.
- Vendor monitoring
- Vendor security assessment
- Supply-chain analysis
- Conflict-of-interest review
- Evidence of internal audits
Correct Answers: A, E
Correct Answers
Answer A is correct because Vendor monitoring means ongoing review of supplier performance, control changes, incidents, and risk indicators. One required function is exactly what this option provides. Supply-chain analysis may be useful elsewhere, but it is used for review of upstream vendors, dependencies, components, and service relationships.
Answer E is correct because Evidence of internal audits means documentation showing a vendor performs its own structured control reviews. One required function is exactly what this option provides. Supply-chain analysis may be useful elsewhere, but it is used for review of upstream vendors, dependencies, components, and service relationships. This question specifically tests the combined requirements represented by Evidence of internal audits and Vendor monitoring.
Incorrect Answers
Answer B is incorrect because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship. The fixed-count answer set is Evidence of internal audits, Vendor monitoring; this option does not fill one of those named functions.
Answer C is incorrect because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships. Every answer slot must map to a stated requirement. The correct set is Evidence of internal audits, Vendor monitoring, so this option cannot replace one of those selections.
Answer D is incorrect because Conflict-of-interest review means assessment of relationships or incentives that could compromise impartial vendor selection or oversight. The required choices are Evidence of internal audits, Vendor monitoring. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.
Question 17
To gain evidence of how well a supplier resists realistic attack, which security approach should be selected?
- Third-party penetration test evidence
- Master service agreement (MSA)
- Vendor security assessment
- Right-to-audit clause
Correct Answer: A
Correct Answer
Answer A is correct because Third-party penetration test evidence means results from authorized security testing used to understand a vendor’s technical exposure. The requirement maps directly to this function, whereas Master service agreement (MSA) is aimed at umbrella contract establishing general legal and commercial terms for ongoing services.
Incorrect Answers
Answer B is incorrect because Master service agreement (MSA) refers to umbrella contract establishing general legal and commercial terms for ongoing services. The concept is valid, but it does not match this stem. The required function is results from authorized security testing used to understand a vendor’s technical exposure, which maps to Third-party penetration test evidence.
Answer C is incorrect because Vendor security assessment refers to evaluation of a supplier’s controls, practices, and risk before or during a business relationship. This could be appropriate elsewhere, but the required function is results from authorized security testing used to understand a vendor’s technical exposure; that makes Third-party penetration test evidence the precise choice.
Answer D is incorrect because Right-to-audit clause refers to contract language giving a customer defined rights to review or assess a supplier’s controls. The question is not asking for this function. It is testing results from authorized security testing used to understand a vendor’s technical exposure, so Third-party penetration test evidence is the stronger fit.
Question 18
Two requirements remain open in a third-party risk review: evaluation of a supplier’s controls, practices, and risk before or during a business relationship; agreement defining responsibilities and expectations between organizations working together. Which TWO options close those specific gaps? Choose TWO.
- Third-party penetration test evidence
- Vendor security assessment
- Memorandum of understanding (MOU)
- Supply-chain analysis
- Business partners agreement (BPA)
Correct Answers: B, E
Correct Answers
Answer B is correct because Vendor security assessment means evaluation of a supplier’s controls, practices, and risk before or during a business relationship. This option satisfies a specific requirement in the stem; Third-party penetration test evidence serves results from authorized security testing used to understand a vendor’s technical exposure and therefore is not interchangeable with it.
Answer E is correct because Business partners agreement (BPA) means agreement defining responsibilities and expectations between organizations working together. This option satisfies a specific requirement in the stem; Third-party penetration test evidence serves results from authorized security testing used to understand a vendor’s technical exposure and therefore is not interchangeable with it.
Incorrect Answers
Answer A is incorrect because Third-party penetration test evidence means results from authorized security testing used to understand a vendor’s technical exposure. The question requires exactly 2 selections: Vendor security assessment, Business partners agreement (BPA). This option falls outside that required set.
Answer C is incorrect because Memorandum of understanding (MOU) means document describing a shared understanding or intent between parties, often less formal than a contract. The question requires exactly 2 selections: Vendor security assessment, Business partners agreement (BPA). This option falls outside that required set.
Answer D is incorrect because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships. The fixed-count answer set is Vendor security assessment, Business partners agreement (BPA); this option does not fill one of those named functions.
Question 19
To gain more objective assurance about a supplier’s controls, which security approach should be selected?
- Evidence of internal audits
- Independent assessment
- Business partners agreement (BPA)
- Third-party penetration test evidence
Correct Answer: B
Correct Answer
Answer B is correct because Independent assessment means security evaluation performed by an external party separate from the vendor’s management. That is the function the question is testing. Third-party penetration test evidence would instead be used for results from authorized security testing used to understand a vendor’s technical exposure.
Incorrect Answers
Answer A is incorrect because Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews. The concept is valid, but it does not match this stem. The required function is security evaluation performed by an external party separate from the vendor’s management, which maps to Independent assessment.
Answer C is incorrect because Business partners agreement (BPA) refers to agreement defining responsibilities and expectations between organizations working together. The question is not asking for this function. It is testing security evaluation performed by an external party separate from the vendor’s management, so Independent assessment is the stronger fit.
Answer D is incorrect because Third-party penetration test evidence refers to results from authorized security testing used to understand a vendor’s technical exposure. This could be appropriate elsewhere, but the required function is security evaluation performed by an external party separate from the vendor’s management; that makes Independent assessment the precise choice.
Question 20
Which term describes review of upstream vendors, dependencies, components, and service relationships?
- Independent assessment
- Memorandum of understanding (MOU)
- Supply-chain analysis
- Evidence of internal audits
Correct Answer: C
Correct Answer
Answer C is correct because Supply-chain analysis means review of upstream vendors, dependencies, components, and service relationships. This matches the requirement as written. Memorandum of understanding (MOU) can be valid in another context, but it is used for document describing a shared understanding or intent between parties, often less formal than a contract.
Incorrect Answers
Answer A is incorrect because Independent assessment refers to security evaluation performed by an external party separate from the vendor’s management. This could be appropriate elsewhere, but the required function is review of upstream vendors, dependencies, components, and service relationships; that makes Supply-chain analysis the precise choice.
Answer B is incorrect because Memorandum of understanding (MOU) refers to document describing a shared understanding or intent between parties, often less formal than a contract. The concept is valid, but it does not match this stem. The required function is review of upstream vendors, dependencies, components, and service relationships, which maps to Supply-chain analysis.
Answer D is incorrect because Evidence of internal audits refers to documentation showing a vendor performs its own structured control reviews. The concept is valid, but it does not match this stem. The required function is review of upstream vendors, dependencies, components, and service relationships, which maps to Supply-chain analysis.