nerdexam
CompTIA

SY0-501 · Question #191

When considering a third-party cloud service provider, which of the following criteria would be the BEST to include in the security assessment process? (Select two.)

The correct answer is B. Adherence to regulatory compliance C. Data retention policies. When assessing a third-party cloud provider's security posture, regulatory compliance and data retention policies are the most directly relevant security criteria to evaluate.

Submitted by minji_kr· Mar 4, 2026Security program management and oversight

Question

When considering a third-party cloud service provider, which of the following criteria would be the BEST to include in the security assessment process? (Select two.)

Options

  • AUse of performance analytics
  • BAdherence to regulatory compliance
  • CData retention policies
  • DSize of the corporation
  • EBreadth of applications support

How the community answered

(52 responses)
  • A
    8% (4)
  • B
    73% (38)
  • D
    15% (8)
  • E
    4% (2)

Why each option

When assessing a third-party cloud provider's security posture, regulatory compliance and data retention policies are the most directly relevant security criteria to evaluate.

AUse of performance analytics

Performance analytics relates to operational efficiency and uptime metrics, not security controls or risk management, making it irrelevant to a security assessment.

BAdherence to regulatory complianceCorrect

Adherence to regulatory compliance (e.g., GDPR, HIPAA, SOC 2, ISO 27001) ensures the provider meets legally mandated security and privacy controls, reducing legal liability and confirming baseline security standards are enforced. Non-compliance by a third-party provider can directly expose the contracting organization to regulatory penalties and breaches.

CData retention policiesCorrect

Data retention policies define how long sensitive data is stored, how it is disposed of, and who has access over time - all critical security concerns when entrusting a third party with organizational data. Inadequate retention or disposal practices can lead to data exposure, unauthorized access, or failure to meet legal obligations.

DSize of the corporation

The size of a corporation does not directly correlate with its security posture or risk level; smaller providers can have strong security practices while large ones may have significant vulnerabilities.

EBreadth of applications support

Breadth of application support is a functional/business capability criterion, not a security assessment factor, as it measures feature range rather than security controls or risk management practices.

Concept tested: Third-party cloud provider security assessment criteria

Source: https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final

Topics

#cloud security#vendor assessment#regulatory compliance#data retention

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice