wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CompTIA Security+ (SYO-701) Obj 5

Total questions: 24

Worksheet time: 12mins

Name
Class
Date
1.
Which of the following BEST represents a primary goal when seeking evidence of internal audits from a third-party vendor?
a)
Assessment of external threat landscape to reduce security vulnerabilities.
b)
Verification of compliance with internal security standards.
c)
Determination of the vendor's profit margins.
d)
Review of the vendor's client list.
2.
Which agreement type outlines the specific services to be provided by the vendor, along with associated timelines and costs?
a)
MSA
b)
MOA
c)
SOW
d)
SLA
3.
Kelly Innovations LLC is in the process of selecting a new vendor for their cloud storage solutions. As part of the selection process, the IT manager, Jamario, reviews the potential vendor's past financial stability, customer reviews, and history of cybersecurity incidents. Which aspect of the vendor selection process is Jamario emphasizing?
a)
Service-level agreement
b)
Due diligence
c)
Non-disclosure agreement
d)
Supply chain analysis
4.
Dion Training is considering a collaboration with a new IT service vendor. To ensure compliance and adherence to industry standards, Dion Training wishes to see verifiable evaluations of the vendor's security controls and practices. Which of the following would provide Dion Training with insights into the vendor's own internal evaluations of their security measures?
a)
External penetration test reports
b)
Customer testimonials
c)
Evidence of internal audits
d)
Regulatory compliance certificates
5.
What part of a BPA for mission essential functions provides a detailed, step-by-step description of the procedural tasks performed?
a)
Hardware
b)
Outputs
c)
Process flow
d)
Inputs
6.
Which type of agreement defines the terms of a partnership between two organizations and how they will collaborate on specific projects or initiatives?
a)
SLA
b)
BPA
c)
MSA
d)
MOU
7.
An organization hires a third-party vendor to handle its data storage needs. To ensure data confidentiality and establish clear expectations around responsibilities, they sign a document that outlines security controls, availability requirements, and confidentiality clauses. Which type of agreement is this document?
a)
Business Partnership Agreement (BPA)
b)
Memorandum of Understanding (MOU)
c)
Data Use Agreement (DUA)
d)
Service Level Agreement (SLA)
8.
An organization hires a third-party vendor to handle its data storage needs. To ensure data confidentiality and establish clear expectations around responsibilities, they sign a document that outlines security controls, availability requirements, and confidentiality clauses. Which type of agreement is this document?
a)
Business Partnership Agreement (BPA)
b)
Memorandum of Understanding (MOU)
c)
Data Use Agreement (DUA)
d)
Service Level Agreement (SLA)
9.
Abdul has suggested that his company perform a supply chain analysis of all of the company's vendors. This will be expensive and time consuming. Why is it important that the company conduct a supply chain analysis despite the costs?
a)
To evaluate the vendor's financial stability so the supply chain won't be broken due to a bankruptcy or closing.
b)
To identify potential security risks associated with the vendor's supply chain.
c)
To determine the vendor's customer satisfaction ratings so that only the best suppliers are chosen.
d)
To assess the vendor's compliance with legal regulations, so the company will remain in compliance.
10.
What type of assessment should you do to evaluate the security measures and vulnerabilities of a company that offers goods or services?
a)
Statement of Work
b)
Vendor monitoring
c)
Vendor assessment
d)
Vendor selection
11.
Which of the following involves an authorized testing of the security of a third-party by actively engaging the third-party's system?
a)
Penetration testing
b)
Vendor monitoring
c)
Supply chain analysis
d)
Vendor assessment
12.
Which of the following types of conflict of interest may occur when a vendor has a possibility of earning commissions that could influence their recommendations during vendor assessments?
a)
Insider information
b)
Competitive relationships
c)
Personal relationships
d)
Financial interests
13.
Globex Corporation is looking to enter into a long-term business relationship with a vendor to provide IT services. They want to establish the general terms and conditions that will apply to future agreements with the vendor. Which type of agreement do they want to set up?
a)
SOW
b)
MSA
c)
SLA
d)
MOU
14.
Which of the following aspects is NOT typically addressed in a Business Partnership Agreement (BPA) between two collaborating entities?
a)
Responsibilities for software updates
b)
Profit-sharing arrangements
c)
Exit strategies
d)
Ownership of intellectual property
15.
What is the purpose of a security analyst doing due diligence in the vendor selection process?
a)
To ensure that the chosen vendor is the best choice among the list of possible vendors
b)
To ensure that the vendor's practices align with the organization's requirements
c)
To assess the vendor's ability to provide the goods or services when they have promised
d)
To compare multiple vendors' suppliers to ensure they are all diligent in analyzing their own supply chains.
16.
Trent has been put in charge of checking his company's vendors to ensure they are complying with the security levels that are contained in the contracts. He evaluates their security on a regular basis to ensure continued compliance. Which of the following is now part of Trent's duties?
a)
Vendor monitoring
b)
Compliance Reporting
c)
Vendor assessment
d)
Vendor selection
17.

In the context of privacy compliance, which of the following describes the role of a data controller?

a)

The entity responsible for determining why data is processed.

b)

The organization that handles data retention and storage.

c)

The external auditor responsible for privacy compliance checks.

d)

The individual whose data is being processed.

18.

A cloud service provider recently underwent an audit to confirm their compliance with international data security standards. The final report provided by the auditors served as an attestation of the provider's security measures. What does this attestation signify to the cloud service provider's clients?

a)

It certifies that the provider's services are the most cost-effective in the market.

b)

It acknowledges the provider's marketing strategies are effective.

c)

It guarantees that the security controls are impenetrable and all data is securely held.

d)

It assures that the provider's security controls comply with established standards.

19.

What is the primary purpose of internal compliance reporting?

a)

To prove to third party auditors that a company is complying with its internal processes

b)

To report compliance status to the public

c)

To provide compliance updates to the organization's management

d)

To request additional information from agencies that are in charge of compliance

20.

Horizon Security, a cybersecurity training company, experienced a data breach due to a vendor's negligence. This breach led to a significant loss of sensitive customer information. Which type of consequence is Horizon MOST likely to face immediately?

a)

Loss of license

b)

Fines

c)

Reputational damage

d)

Sanctions

21.

A financial services company is required to submit regular documentation demonstrating adherence to regulatory security standards. This documentation includes audit results, risk assessments, and evidence of data protection measures. What is this process called?

a)

Configuration Management

b)

Risk Management

c)

Compliance Reporting

d)

Incident Response

22.

In the context of compliance monitoring, which of the following does "due diligence/care" refer to?

a)

Automated compliance checks.

b)

Taking steps to meet legal and other requirements.

c)

Conducting internal audits on a regular basis.

d)

Reviewing third-party vendor agreements.

23.

Which of the following terms refer to situations in which specific laws and regulations set by a country's government dictate how the personal data of its citizens should be collected, stored, and processed?

a)

General Data Protection Regulation (GDPR)

b)

National legal implications

c)

Data encryption

d)

Consent management

24.

Which of the following is a monetary penalty imposed as a result of non-compliance with regulations or violations of certain rules or agreements?

a)

Deductible

b)

Fine

c)

Fee

d)

Sanction