SY0-701 · Question #640
Which of the following is the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations?
The correct answer is A. Attestation report. Attestation reports are pre-existing documents (like SOC 2 reports or ISO 27001 certificates) that a supplier has already prepared, making them the fastest and cheapest way to confirm compliance - no scheduling, no fieldwork, just review the document. A third-party audit (B) is…
Question
Which of the following is the fastest and most cost-effective way to confirm a third-party supplier's compliance with security obligations?
Options
- AAttestation report
- BThird-party audit
- CVulnerability assessment
- DPenetration testing
How the community answered
(32 responses)- A72% (23)
- B6% (2)
- C6% (2)
- D16% (5)
Explanation
Attestation reports are pre-existing documents (like SOC 2 reports or ISO 27001 certificates) that a supplier has already prepared, making them the fastest and cheapest way to confirm compliance - no scheduling, no fieldwork, just review the document. A third-party audit (B) is more thorough but requires hiring auditors, coordinating access, and significant time and cost. A vulnerability assessment (C) evaluates technical weaknesses in systems, not contractual or policy compliance obligations. Penetration testing (D) simulates attacks to find exploitable vulnerabilities - useful for security posture, but not for validating supplier compliance with agreed obligations.
Memory tip: Think "A = Already done" - attestations are reports the supplier already has, so you just ask for it. Any option that requires you to do active work (audit, scan, test) will cost more time and money.
Topics
Community Discussion
No community discussion yet for this question.