5.3 - Third-party agreements (SLA, SOW, NDA)

Security+ SY0-701 objective 5.3 covers the agreements that govern third-party and vendor relationships. A service level agreement (SLA) promises measurable service levels, such as 99.9% uptime, with penalties if the provider misses them. A statement of work (SOW) defines exactly what services, deliverables and timelines a project will cover. A non-disclosure agreement (NDA) is signed before sharing confidential information so both parties are legally bound to protect it. You should also recognise a memorandum of understanding (MOU), a memorandum of agreement (MOA), a master service agreement (MSA), and a business partners agreement (BPA), plus interconnection security agreements. Expect scenario questions that describe what an agreement guarantees or defines - service levels, scope and deliverables, or confidentiality - and ask which specific document is being described.

Memory hook
Guaranteed uptime with penalties = SLA. Exact services, deliverables, timelines = SOW. Sign before sharing secrets = NDA. Non-binding intent = MOU.

Practice questions

1. Which agreement defines the measurable service levels (e.g., uptime) a vendor must meet?

  • An NDA (confidentiality)
  • An SLA (service levels) (correct answer)
  • An AUP (acceptable use)
  • A BPA (partnership terms)

An SLA sets measurable targets (uptime, response time) and penalties. NDA=confidentiality, MOU/MOA=intent, BPA=business partnership.

2. Which vendor agreement legally protects shared confidential information from disclosure?

  • An SLA (service levels)
  • A non-disclosure agreement (correct answer)
  • An MOU (intent)
  • An SOW (scope of work)

An NDA legally binds parties to keep shared information confidential. SLA=measurable service levels; MOU=non-binding intent; SOW=specific deliverables/scope.

3. Before onboarding a cloud vendor, evaluating their security posture is called:

  • A business impact analysis
  • Vendor/third-party risk assessment (correct answer)
  • A phishing simulation
  • A change-management review

Third-party (vendor) risk assessment reviews a supplier's security, compliance and practices before and during engagement — often with a right-to-audit clause.

4. Which agreement is the overarching contract setting general terms that later work orders (SOWs) fall under?

  • A non-disclosure agreement
  • A master service agreement (correct answer)
  • A memorandum of understanding
  • A service level agreement

An MSA establishes overarching terms (liability, IP, payment) for an ongoing relationship; individual SOWs then define specific projects/deliverables under it.

5. A clause letting a customer inspect a vendor's security controls during the contract is a:

  • A non-compete clause
  • Right-to-audit clause (correct answer)
  • A force-majeure clause
  • A payment-terms clause

A right-to-audit clause lets the customer assess/verify the vendor's controls and compliance during the engagement, supporting ongoing third-party risk management.

6. Two hospitals want a non-binding statement of shared intent before a formal partnership. They should sign a(n):

  • A service level agreement
  • A memorandum of understanding (correct answer)
  • A statement of work
  • A non-disclosure agreement

An MOU expresses mutual intent and general terms, typically non-binding. SLA=measurable service; SOW=specific deliverables; NDA=confidentiality obligations.

Related objectives