SY0-301 · Question #174
In order to maintain oversight of a third party service provider, the company is going to implement a Governance, Risk, and Compliance (GRC) system. This system is promising to provide overall…
The correct answer is A. Continuous security monitoring. When maintaining oversight of a third-party provider through a GRC system, continuous security monitoring is most important because it provides ongoing, real-time visibility into the security posture of both the organization and the third party. It detects deviations, new…
Question
In order to maintain oversight of a third party service provider, the company is going to implement a Governance, Risk, and Compliance (GRC) system. This system is promising to provide overall security posture coverage. Which of the following is the MOST important activity that should be considered?
Options
- AContinuous security monitoring
- BBaseline configuration and host hardening
- CService Level Agreement (SLA) monitoring
- DSecurity alerting and trending
How the community answered
(26 responses)- A65% (17)
- B4% (1)
- C23% (6)
- D8% (2)
Explanation
When maintaining oversight of a third-party provider through a GRC system, continuous security monitoring is most important because it provides ongoing, real-time visibility into the security posture of both the organization and the third party. It detects deviations, new vulnerabilities, and compliance gaps as they emerge rather than at point-in-time audits. SLA monitoring tracks performance metrics but not security posture. Baseline configuration and host hardening are important internal controls but don't directly address third-party oversight. Security alerting and trending are components of monitoring but are subsets of the broader continuous monitoring effort.
Topics
Community Discussion
No community discussion yet for this question.