
Certified in Risk and Information Systems Control
Domain 3Objective 2
Third-Party and Supply Chain Risk CRISC Practice Questions (Page 7)
Part of the Domain 3: Risk Response and Reporting domain, which accounts for 32% of the CRISC exam.
35questions here
7free pages
9concepts
32%of the exam
Questions 31–35
- 31
A company is assessing a vendor that will provide marketing services and will have access to customer email addresses. The vendor is a small firm with limited security resources. What is the MOST appropriate assessment method?
Select an answer first - 32
A company's payment processing vendor has experienced a data breach that may have exposed customer credit card information. The vendor has notified the company. What should the risk practitioner do FIRST?
Select an answer first - 33
A company has a vendor that provides critical infrastructure services. The vendor has been experiencing financial difficulties, which could impact service delivery. What should the risk practitioner do to monitor this risk?
Select an answer first - 34
What is the purpose of vendor due diligence?
Select an answer first - 35
A company is contracting with a cloud provider to host a critical application. The provider has a history of minor service disruptions. The company wants to ensure that if the provider fails to meet performance targets, the company can recover costs and potentially exit the contract. Which contractual clause is MOST important to include?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CRISC
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CRISC” is a trademark of its owner, used for identification only.