nerdexam
CompTIA

CAS-003 · Question #741

Which of the following is MOST likely to be included in a security services SLA with a third-party vendor?

The correct answer is A. The standard of quality for anti-malware engines. An SLA (Service Level Agreement) with a security services vendor defines measurable, contractual quality benchmarks for the services being delivered. For a vendor providing anti-malware services, the standard of quality for their detection engines - such as detection rate…

Risk Management

Question

Which of the following is MOST likely to be included in a security services SLA with a third-party vendor?

Options

  • AThe standard of quality for anti-malware engines
  • BParameters for applying critical patches
  • CThe validity of program productions
  • DMinimum bit strength for encryption-in-transit.

How the community answered

(67 responses)
  • A
    88% (59)
  • B
    1% (1)
  • C
    3% (2)
  • D
    7% (5)

Explanation

An SLA (Service Level Agreement) with a security services vendor defines measurable, contractual quality benchmarks for the services being delivered. For a vendor providing anti-malware services, the standard of quality for their detection engines - such as detection rate thresholds, definition update frequency, and false positive tolerances - is a core SLA metric. Patch parameters (B) are typically addressed in an operational procedures agreement or maintenance window schedule, not the SLA itself. Program production validity (C) is vague and not a standard SLA element. Minimum encryption bit strength (D) is a technical baseline requirement, more suited to a security policy or contract clause than an SLA quality metric.

Topics

#SLA#third-party risk#patch management#vendor management

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice