
Certified in Risk and Information Systems Control
Domain 3Objective 2
Third-Party and Supply Chain Risk CRISC Practice Questions (Page 4)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
35questions here
7free pages
9concepts
32%of the exam
Questions 16–20
- 16
A company has outsourced its IT helpdesk to a third-party vendor. The vendor has been meeting SLA targets, but the company's internal audit recently found that the vendor's employees have access to more customer data than necessary. What should the risk practitioner do to address this risk?
Select an answer first - 17
Which of the following is an example of a financial risk associated with a third-party relationship?
Select an answer first - 18
A company is negotiating a contract with a critical vendor. The vendor has refused to include an exit clause that allows the company to terminate for convenience. The company's risk appetite is low, and it wants to ensure it can exit if the vendor's performance deteriorates. What is the BEST alternative?
Select an answer first - 19
Which contractual clause is used to mitigate vendor risk by defining performance expectations?
Select an answer first - 20
Which criterion is commonly used to assess vendor risk?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.