Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified in Risk and Information Systems Control

Domain 3Objective 2

Third-Party and Supply Chain Risk CRISC Practice Questions (Page 5)

Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.

35questions here
7free pages
9concepts
32%of the exam

Questions 21–25

  1. 21expert · hard

    A company's supply chain includes multiple tiers of suppliers, some of which are not directly contracted. A risk assessment reveals that a second-tier supplier has poor labor practices, which could lead to reputational damage. The company has limited ability to influence this supplier. What is the BEST course of action?

    Select an answer first
  2. 22foundation · easy

    What is the primary purpose of a vendor risk management framework?

    Select an answer first
  3. 23foundation · easy

    Which of the following is a component of vendor due diligence?

    Select an answer first
  4. 24foundation · easy

    What is the primary objective of vendor termination and exit management?

    Select an answer first
  5. 25application · medium

    A financial services firm is evaluating a new vendor that will process customer loan applications, including sensitive personal data. The vendor is a startup with limited operating history but strong technical references. The firm's risk appetite allows for moderate risk if mitigated. What should the risk practitioner do FIRST?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.