Objective 5.3SY0-701

5.3 Explain the processes associated with third-party risk assessment and management

Objective 5.3 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Security Program Management and OversightEasy

In the private disclosure model for reporting vulnerabilities, who decides whether vulnerability details are ever published?

Correct.

The concept

Private disclosure is one model for handling third-party vulnerability reports and sets who controls the eventual release of details.

Why this answer

Under private disclosure, the vulnerability is reported to the organization and publication is left entirely to the organization's discretion, so many findings never become public.

  • Correct: private disclosure places publication authority with the organization, not the reporter.
  • BThe researcher only controls timing under full or coordinated disclosure, not under a pure private model.
  • CA CERT may assist with contact, but it does not hold publication authority under private disclosure.
  • DA bug bounty platform hosts the program but the organization retains the publication decision.
Read the sourceOWASP Vulnerability Disclosure Cheat Sheet
Verified against cheatsheetseries.owasp.org · 2026-07-27
vulnerability-disclosurethird-party-riskmonitoring

Now you: objective 5.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Security Program Management and OversightEasy

Which practice should an organization maintain so outside researchers have a clear channel to report discovered vulnerabilities?

Sample question 2 of 3

Security Program Management and OversightModerate

After a researcher privately reports a vulnerability, the organization threatens the researcher with legal action instead of addressing the report. Which expectation of vulnerability handling has the organization failed to meet?

Sample question 3 of 3

Security Program Management and OversightModerate

A researcher finds a vulnerability in a company's bug bounty program but also decides to test a subdomain not listed in the program's published scope. What is the most likely consequence?

That’s 3 of the full Security+ bank.

Keep going free: 10 questions per certification in bank practice, with no account.

Continue practicing

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security Program Management and Oversight