5.3 - Third-party agreements (SLA, SOW, NDA)
Security+ SY0-701 objective 5.3 covers the agreements that govern third-party and vendor relationships. A service level agreement (SLA) promises measurable service levels, such as 99.9% uptime, with penalties if the provider misses them. A statement of work (SOW) defines exactly what services, deliverables and timelines a project will cover. A non-disclosure agreement (NDA) is signed before sharing confidential information so both parties are legally bound to protect it. You should also recognise a memorandum of understanding (MOU), a memorandum of agreement (MOA), a master service agreement (MSA), and a business partners agreement (BPA), plus interconnection security agreements. Expect scenario questions that describe what an agreement guarantees or defines - service levels, scope and deliverables, or confidentiality - and ask which specific document is being described.
Guaranteed uptime with penalties = SLA. Exact services, deliverables, timelines = SOW. Sign before sharing secrets = NDA. Non-binding intent = MOU.
Practice questions
1. Which agreement defines the measurable service levels (e.g., uptime) a vendor must meet?
- An NDA (confidentiality)
- An SLA (service levels) (correct answer)
- An AUP (acceptable use)
- A BPA (partnership terms)
An SLA sets measurable targets (uptime, response time) and penalties. NDA=confidentiality, MOU/MOA=intent, BPA=business partnership.
2. Which vendor agreement legally protects shared confidential information from disclosure?
- An SLA (service levels)
- A non-disclosure agreement (correct answer)
- An MOU (intent)
- An SOW (scope of work)
An NDA legally binds parties to keep shared information confidential. SLA=measurable service levels; MOU=non-binding intent; SOW=specific deliverables/scope.
3. Before onboarding a cloud vendor, evaluating their security posture is called:
- A business impact analysis
- Vendor/third-party risk assessment (correct answer)
- A phishing simulation
- A change-management review
Third-party (vendor) risk assessment reviews a supplier's security, compliance and practices before and during engagement — often with a right-to-audit clause.
4. Which agreement is the overarching contract setting general terms that later work orders (SOWs) fall under?
- A non-disclosure agreement
- A master service agreement (correct answer)
- A memorandum of understanding
- A service level agreement
An MSA establishes overarching terms (liability, IP, payment) for an ongoing relationship; individual SOWs then define specific projects/deliverables under it.
5. A clause letting a customer inspect a vendor's security controls during the contract is a:
- A non-compete clause
- Right-to-audit clause (correct answer)
- A force-majeure clause
- A payment-terms clause
A right-to-audit clause lets the customer assess/verify the vendor's controls and compliance during the engagement, supporting ongoing third-party risk management.
6. Two hospitals want a non-binding statement of shared intent before a formal partnership. They should sign a(n):
- A service level agreement
- A memorandum of understanding (correct answer)
- A statement of work
- A non-disclosure agreement
An MOU expresses mutual intent and general terms, typically non-binding. SLA=measurable service; SOW=specific deliverables; NDA=confidentiality obligations.