SY0-701 - Security Program Management and Oversight - Section 5.3

Explain the processes associated with third-party risk assessment and management.

Describe how vendor assessments and ongoing vendor monitoring reduce supply chain risk introduced by third-party relationships, and explain the role of SLAs and MOUs in formalising security expectations. Recognise why a right-to-audit clause is a critical contractual safeguard, enabling an organisation to verify vendor security posture independently rather than relying solely on self-reported attestations.

vendor assessmentsupply chain riskSLA and MOUright-to-auditvendor monitoring

Practice question for this objective

Free sampleSecurity Program Management and Oversightmedium

Which option best describes the security purpose of ongoing vendor monitoring after a third party has been onboarded?

  • ATo replace the initial due diligence assessment with a single annual penetration test commissioned by the customer against the vendor's production estate.
  • BTo satisfy the vendor's own internal audit programme by sharing the customer's findings with the vendor's board on a quarterly cadence.
  • CTo allow the customer to renegotiate commercial pricing every time a minor configuration change is observed in the vendor's published security pages.
  • DTo detect changes in the vendor's risk posture, control effectiveness, and external exposure over time so the customer can respond before issues materialise. Correct
Recognise that ongoing vendor monitoring exists to detect changes in third-party risk posture between formal assessments so the customer can act in time. A vendor's risk profile is not static. Continuous monitoring through control attestations, security ratings, breach notifications, financial health checks, and periodic questionnaires gives the customer a near-real-time view of changes that may affect the service or expose the customer to harm, allowing earlier intervention than annual reviews alone would permit.

Why A is wrong: Initial due diligence and continuous monitoring address different points in the relationship and are not substitutes. A single annual test would also create long blind windows and is rarely permitted against a vendor's production estate without specific contract terms.

Why B is wrong: Vendor monitoring is performed for the customer's risk management benefit, not to feed the vendor's internal audit programme. Sharing customer-side findings with the vendor's board is not the purpose, even though some findings will be raised with the vendor.

Why C is wrong: Commercial renegotiation is not the goal of monitoring, and using minor configuration drift as a trigger would be impractical. Candidates may pick this if they conflate monitoring with contract management, but the primary aim is risk visibility.

Why D is correct: Vendors evolve after onboarding: control owners change, infrastructure is reconfigured, and new exposures appear. Ongoing monitoring through attestation refreshes, security ratings, breach notifications, and questionnaires is designed to surface those changes so the customer can act before harm occurs.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all Security Program Management and Oversight objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.