
CompTIASecurity+
Domain 5Objective 3
Third-Party Risk SY0-701 Practice Questions (Page 5)
Part of the Security program management and oversight domain, which accounts for 20% of the SY0-701 exam. CompTIA does not publish an official question count, but from its 90-minute exam (~35–60 total, ~7–12 in this domain), expect 1–2 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
6concepts
20%of the exam
Questions 21–25
- 21
An organization has contracted with a cloud storage vendor to host sensitive customer data. The contract includes a requirement for the vendor to undergo an annual SOC 2 Type II audit. Which of the following is the MOST effective way for the organization to monitor the vendor's ongoing compliance?
Select an answer first - 22
Which topic should be covered in a vendor security questionnaire?
Select an answer first - 23
What is the purpose of rules of engagement in vendor interactions?
Select an answer first - 24
A government agency is selecting a cloud provider to host non-classified but sensitive data. The agency requires that the provider comply with FedRAMP. Two providers meet the FedRAMP requirement, but Provider A has a higher authorization level (e.g., FedRAMP High) while Provider B has a lower level (e.g., FedRAMP Moderate). Which of the following is the MOST important consideration in the selection?
Select an answer first - 25
A company has hired a third-party security firm to conduct a penetration test on its web application. The company wants to ensure the test does not disrupt production services. Which of the following should be defined in the rules of engagement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “SY0-701” is a trademark of its owner, used for identification only.