nerdexam
CompTIA

SY0-701 · Question #629

The Chief Information Officer (CIO) asked a vendor to provide documentation detailing the specific objectives within the compliance framework that the vendor's services meet. The vendor provided a…

The correct answer is C. Attestation of compliance. Attestation of compliance is correct because it is a formal, signed declaration by the vendor affirming that their services satisfy specific requirements within a compliance framework - exactly what the signed letter plus the report represent. The signature is the key element…

Submitted by rania.sa· Mar 6, 2026Security program management and oversight

Question

The Chief Information Officer (CIO) asked a vendor to provide documentation detailing the specific objectives within the compliance framework that the vendor's services meet. The vendor provided a report and a signed letter stating that the services meet 17 of the 21 objectives. Which of the following did the vendor provide to the CIO?

Options

  • APenetration test results
  • BSelf-assessment findings
  • CAttestation of compliance
  • DThird-party audit report

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    3% (1)
  • C
    86% (25)
  • D
    3% (1)

Explanation

Attestation of compliance is correct because it is a formal, signed declaration by the vendor affirming that their services satisfy specific requirements within a compliance framework - exactly what the signed letter plus the report represent. The signature is the key element: it transforms a mere report into a legally/formally attested statement.

Why the distractors are wrong:

  • A (Penetration test results): Pen tests identify security vulnerabilities through active testing; they don't map services to compliance framework objectives.
  • B (Self-assessment findings): A self-assessment documents an internal review process but lacks the formal signed declaration - the signed letter elevates this beyond a simple self-assessment.
  • D (Third-party audit report): A third-party audit is performed by an independent external auditor, not the vendor themselves. Here, the vendor is making the claim about their own services.

Memory tip: Think "attest = assert with a signature." Whenever you see a vendor providing a signed letter vouching for their own compliance, that's attestation. If an outside auditor produced the report, it would be a third-party audit; if there's no signature formalizing the claim, it's just a self-assessment.

Topics

#Compliance#Vendor Management#Attestation#Security Documentation

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice