SY0-501 · Question #191
When considering a third-party cloud service provider, which of the following criteria would be the BEST to include in the security assessment process? (Select two.)
The correct answer is B. Adherence to regulatory compliance C. Data retention policies. When assessing a third-party cloud provider's security posture, regulatory compliance and data retention policies are the most directly relevant security criteria to evaluate.
Question
When considering a third-party cloud service provider, which of the following criteria would be the BEST to include in the security assessment process? (Select two.)
Options
- AUse of performance analytics
- BAdherence to regulatory compliance
- CData retention policies
- DSize of the corporation
- EBreadth of applications support
How the community answered
(52 responses)- A8% (4)
- B73% (38)
- D15% (8)
- E4% (2)
Why each option
When assessing a third-party cloud provider's security posture, regulatory compliance and data retention policies are the most directly relevant security criteria to evaluate.
Performance analytics relates to operational efficiency and uptime metrics, not security controls or risk management, making it irrelevant to a security assessment.
Adherence to regulatory compliance (e.g., GDPR, HIPAA, SOC 2, ISO 27001) ensures the provider meets legally mandated security and privacy controls, reducing legal liability and confirming baseline security standards are enforced. Non-compliance by a third-party provider can directly expose the contracting organization to regulatory penalties and breaches.
Data retention policies define how long sensitive data is stored, how it is disposed of, and who has access over time - all critical security concerns when entrusting a third party with organizational data. Inadequate retention or disposal practices can lead to data exposure, unauthorized access, or failure to meet legal obligations.
The size of a corporation does not directly correlate with its security posture or risk level; smaller providers can have strong security practices while large ones may have significant vulnerabilities.
Breadth of application support is a functional/business capability criterion, not a security assessment factor, as it measures feature range rather than security controls or risk management practices.
Concept tested: Third-party cloud provider security assessment criteria
Source: https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.