Which option best describes the security purpose of ongoing vendor monitoring after a third party has been onboarded?
- ATo replace the initial due diligence assessment with a single annual penetration test commissioned by the customer against the vendor's production estate.
- BTo satisfy the vendor's own internal audit programme by sharing the customer's findings with the vendor's board on a quarterly cadence.
- CTo allow the customer to renegotiate commercial pricing every time a minor configuration change is observed in the vendor's published security pages.
- DTo detect changes in the vendor's risk posture, control effectiveness, and external exposure over time so the customer can respond before issues materialise. Correct
Why A is wrong: Initial due diligence and continuous monitoring address different points in the relationship and are not substitutes. A single annual test would also create long blind windows and is rarely permitted against a vendor's production estate without specific contract terms.
Why B is wrong: Vendor monitoring is performed for the customer's risk management benefit, not to feed the vendor's internal audit programme. Sharing customer-side findings with the vendor's board is not the purpose, even though some findings will be raised with the vendor.
Why C is wrong: Commercial renegotiation is not the goal of monitoring, and using minor configuration drift as a trigger would be impractical. Candidates may pick this if they conflate monitoring with contract management, but the primary aim is risk visibility.
Why D is correct: Vendors evolve after onboarding: control owners change, infrastructure is reconfigured, and new exposures appear. Ongoing monitoring through attestation refreshes, security ratings, breach notifications, and questionnaires is designed to surface those changes so the customer can act before harm occurs.