SY0-701 - Security Program Management and Oversight (20% of the exam) - Section 5.3

Explain the processes associated with third-party risk assessment and management.

Describe how vendor assessments and ongoing vendor monitoring reduce supply chain risk introduced by third-party relationships, and explain the role of SLAs and MOUs in formalising security expectations. Recognise why a right-to-audit clause is a critical contractual safeguard, enabling an organisation to verify vendor security posture independently rather than relying solely on self-reported attestations.

vendor assessmentsupply chain riskSLA and MOUright-to-auditvendor monitoring

Practice question for this objective

Free sampleSecurity Program Management and Oversightmedium

Which option best describes the security purpose of ongoing vendor monitoring after a third party has been onboarded?

  • ATo replace the initial due diligence assessment with a single annual penetration test commissioned by the customer against the vendor's production estate.
  • BTo satisfy the vendor's own internal audit programme by sharing the customer's findings with the vendor's board on a quarterly cadence.
  • CTo allow the customer to renegotiate commercial pricing every time a minor configuration change is observed in the vendor's published security pages.
  • DTo detect changes in the vendor's risk posture, control effectiveness, and external exposure over time so the customer can respond before issues materialise. Correct
Recognise that ongoing vendor monitoring exists to detect changes in third-party risk posture between formal assessments so the customer can act in time. A vendor's risk profile is not static. Continuous monitoring through control attestations, security ratings, breach notifications, financial health checks, and periodic questionnaires gives the customer a near-real-time view of changes that may affect the service or expose the customer to harm, allowing earlier intervention than annual reviews alone would permit.

Why A is wrong: Initial due diligence and continuous monitoring address different points in the relationship and are not substitutes. A single annual test would also create long blind windows and is rarely permitted against a vendor's production estate without specific contract terms.

Why B is wrong: Vendor monitoring is performed for the customer's risk management benefit, not to feed the vendor's internal audit programme. Sharing customer-side findings with the vendor's board is not the purpose, even though some findings will be raised with the vendor.

Why C is wrong: Commercial renegotiation is not the goal of monitoring, and using minor configuration drift as a trigger would be impractical. Candidates may pick this if they conflate monitoring with contract management, but the primary aim is risk visibility.

Why D is correct: Vendors evolve after onboarding: control owners change, infrastructure is reconfigured, and new exposures appear. Ongoing monitoring through attestation refreshes, security ratings, breach notifications, and questionnaires is designed to surface those changes so the customer can act before harm occurs.

See more SY0-701 practice questions, answers explained.

Exam traps in Security Program Management and Oversight

Answers that look right on this material and are not. Each one is a distractor from a different question in the SY0-701 bank for this domain.

  • Increase the financial penalties in the logistics provider's service level agreement so that any failure to meet delivery windows triggers material credits, regardless of whether the failure originated at a sub-tier supplier.

    Why it is wrong: Larger SLA credits compensate for missed deliveries after the fact but they do nothing to reduce the chain's exposure to a sub-tier failure; the pharmacy still has empty shelves and unhappy patients while it waits for the credit to be calculated.

  • Treat the completed onboarding security questionnaire as the standing record of the vendor's posture and reuse it for the duration of the contract term.

    Why it is wrong: A questionnaire is a real onboarding tool and feels sufficient because the vendor passed it, but it captures a single point in time and is self-reported, so reusing it for years gives no assurance that controls still hold.

  • The risk that the customer's own internal change management board will reject a vendor's proposed update during a maintenance window without prior notice.

    Why it is wrong: Internal change governance is part of the customer's own control environment, not supply chain risk. The option is tempting because change rejections do affect vendor work, but supply chain risk concerns exposures inherited from upstream suppliers rather than internal approval steps.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.