CompTIA Security+ SY0-701 (V7) Practice Question

During a third-party risk assessment your organization develops its own vendor security questionnaire. The form is tailored to the service being purchased and asks detailed questions about authentication, data protection, and incident response, but it is not explicitly mapped to any well-known framework such as NIST CSF or ISO/IEC 27001.

Which statement BEST describes the role of security frameworks in this situation?

  • Framework mapping is required only when assessing cloud service providers; it is unnecessary for other vendor types.

  • Mapping each question to a recognized framework is mandatory; without it the questionnaire cannot be considered reliable.

  • Framework mapping is helpful, but a well-tailored questionnaire that covers the vendor's relevant risk areas can still be effective without a formal cross-reference.

  • Using a framework is discouraged because it makes questionnaires too lengthy and compliance-focused.

CompTIA Security+ SY0-701 (V7)
Security Program Management and Oversight
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA Security+ Voucher with Retake
v7 / SY0-701
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot