Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Information Systems Security Management Professional

Domain 3Objective 2

3.2 Manage Security Risks Within the Supply Chain (e.g., Supplier, Vendor, Third-Party Risk, Contracts) ISSMP Practice Questions (Page 3)

Part of the Risk Management domain, which accounts for 20% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
10concepts
20%of the exam

Questions 11–15

  1. 11expert · hard

    A company's supply chain risk review has identified that a long-standing vendor's security posture has declined significantly due to financial difficulties. The vendor provides a critical component with no readily available alternative. The company's risk appetite is low for critical components. What is the BEST course of action?

    Select an answer first
  2. 12expert · hard

    A company is planning to audit a critical vendor that provides cloud infrastructure services. The vendor has multiple data centers in different countries, and the company's audit team is based in a different region. The company wants to verify the vendor's compliance with its security requirements, but the audit must be completed within a limited budget. What is the MOST effective audit strategy?

    Select an answer first
  3. 13application · medium

    A retail company has outsourced its customer support to a third-party call center. The company wants to ensure that the call center's security posture remains acceptable over time. Which approach BEST supports continuous monitoring of this third-party risk?

    Select an answer first
  4. 14application · medium

    A manufacturing company relies on a single supplier for a critical component used in its main product. The supplier is located in a politically unstable region. The company's risk management framework requires that all risks be assessed in terms of likelihood and impact. What should the risk manager do to assess this supply chain risk?

    Select an answer first
  5. 15application · medium

    A company's contract with a software vendor requires the vendor to implement specific security controls, including encryption of data at rest and in transit. The company wants to validate that these controls are actually in place. What is the MOST effective method?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.