
Certified in Risk and Information Systems Control
Domain 3Objective 2
Third-Party and Supply Chain Risk CRISC Practice Questions (Page 3)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
35questions here
7free pages
9concepts
32%of the exam
Questions 11–15
- 11
Which of the following is a key element of incident response procedures for vendor-related incidents?
Select an answer first - 12
A company has a vendor that provides critical software updates. The vendor has been consistently meeting SLAs, but the company's risk team has identified that the vendor's financial stability is declining. The vendor is the only provider of this software. What is the BEST risk response?
Select an answer first - 13
A company is contracting with a vendor for cloud storage services. The company wants to ensure that in the event of a data breach, the vendor will notify the company promptly. Which contractual clause is MOST important?
Select an answer first - 14
Which of the following is an appropriate method for assessing vendor risk?
Select an answer first - 15
What is the purpose of ongoing vendor monitoring?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.