nerdexam
CompTIA

SY0-701 · Question #640

Which of the following is the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations?

The correct answer is A. Attestation report. Attestation reports are pre-existing documents (like SOC 2 reports or ISO 27001 certificates) that a supplier has already prepared, making them the fastest and cheapest way to confirm compliance - no scheduling, no fieldwork, just review the document. A third-party audit (B) is…

Submitted by certguy· Mar 6, 2026Security program management and oversight

Question

Which of the following is the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations?

Options

  • AAttestation report
  • BThird-party audit
  • CVulnerability assessment
  • DPenetration testing

How the community answered

(32 responses)
  • A
    72% (23)
  • B
    6% (2)
  • C
    6% (2)
  • D
    16% (5)

Explanation

Attestation reports are pre-existing documents (like SOC 2 reports or ISO 27001 certificates) that a supplier has already prepared, making them the fastest and cheapest way to confirm compliance - no scheduling, no fieldwork, just review the document. A third-party audit (B) is more thorough but requires hiring auditors, coordinating access, and significant time and cost. A vulnerability assessment (C) evaluates technical weaknesses in systems, not contractual or policy compliance obligations. Penetration testing (D) simulates attacks to find exploitable vulnerabilities - useful for security posture, but not for validating supplier compliance with agreed obligations.

Memory tip: Think "A = Already done" - attestations are reports the supplier already has, so you just ask for it. Any option that requires you to do active work (audit, scan, test) will cost more time and money.

Topics

#Third-party risk management#Supplier compliance#Attestation reports#Security audits

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice