CompTIA Security+ (SY0-701)Security Program Management and OversightHard

A retail chain wants to bring on a new inventory-management SaaS vendor. Before signing the contract, the security team requires the vendor to complete a security questionnaire, provide a recent SOC 2 report, and disclose any subcontractors who will process company data. After the contract is signed, the security team also schedules recurring quarterly reviews of the vendor's security posture for as long as the relationship continues. What does the ongoing quarterly review activity represent, in contrast to the pre-contract steps?

  1. AAn attestation of compliance, which certifies a single point in time
  2. BVendor risk monitoring, which continues throughout the vendor lifecycle
  3. CVendor due diligence, which only occurs before contract signing
  4. DA right-to-audit clause, which is a contractual term rather than an activity
Show answer & explanation

Correct answer: B. Vendor risk monitoring, which continues throughout the vendor lifecycle

Due diligence occurs before the relationship begins to evaluate whether to engage a vendor, while ongoing vendor risk monitoring continues throughout the lifecycle of the relationship to ensure the vendor's security posture remains acceptable over time. The quarterly reviews described are recurring, lifecycle-long activities, matching vendor risk monitoring rather than one-time due diligence.

Why the other options are wrong

  • A. An attestation of compliance is a point-in-time certification, not a recurring monitoring process.
  • C. Due diligence describes the pre-contract questionnaire and SOC 2 review, not the recurring activity.
  • D. A right-to-audit clause is a contract term granting the ability to audit, not the recurring review activity itself.

Vendor Risk Monitoring

The ongoing process of reassessing a third-party vendor's security posture throughout the life of the business relationship, distinct from one-time pre-contract due diligence.

  • Due diligence happens before signing; monitoring happens continuously after
  • May include periodic questionnaires, updated reports, and audits
  • Reduces risk from a vendor's security posture degrading over time

Memory trick: Due diligence before the deal, monitoring for the whole relationship.

More Security Program Management and Oversight questions