nerdexam
CompTIA

SY0-501 · Question #253

An organization is working with a cloud services provider to transition critical business applications to a hybrid cloud environment. The organization retains sensitive customer data and wants to…

The correct answer is A. Service level agreement. Organizations transitioning to a hybrid cloud with sensitive data need assurance about a provider's data protection controls. A Service Level Agreement (SLA) is the primary document where a cloud provider's commitment to security measures and data protection is contractually…

Submitted by lars.no· Mar 4, 2026Security program management and oversight

Question

An organization is working with a cloud services provider to transition critical business applications to a hybrid cloud environment. The organization retains sensitive customer data and wants to ensure the provider has sufficient administrative and logical controls in place to protect its data. In which of the following documents would this concern MOST likely be addressed?

Options

  • AService level agreement
  • BInterconnection security agreement
  • CNon-disclosure agreement
  • DBusiness process analysis

How the community answered

(61 responses)
  • A
    74% (45)
  • B
    15% (9)
  • C
    3% (2)
  • D
    8% (5)

Why each option

Organizations transitioning to a hybrid cloud with sensitive data need assurance about a provider's data protection controls. A Service Level Agreement (SLA) is the primary document where a cloud provider's commitment to security measures and data protection is contractually defined.

AService level agreementCorrect

A Service Level Agreement (SLA) is a contractual agreement between a service provider and a customer that specifies the minimum level of service expected. This includes defining the administrative and logical controls, such as security measures, data protection policies, and performance guarantees, that the provider commits to implement to safeguard customer data and ensure service integrity.

BInterconnection security agreement

An Interconnection Security Agreement (ISA) primarily focuses on the security requirements for direct technical connections between two organizations' information systems, not the overall administrative and logical controls of a cloud service offering.

CNon-disclosure agreement

A Non-disclosure Agreement (NDA) is a legal contract that obligates parties to protect confidential information from unauthorized disclosure, rather than outlining the specific administrative and logical controls for data protection within a service provider's infrastructure.

DBusiness process analysis

Business process analysis (BPA) is an internal management tool used to evaluate and improve an organization's internal processes, not a contractual document between an organization and a cloud service provider detailing security controls.

Concept tested: Role of SLAs in cloud security and data protection

Source: https://www.cisco.com/c/en/us/products/security/what-is-sla.html

Topics

#cloud security#SLA#data protection#hybrid cloud

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice