
Information Systems Security Management Professional
Domain 3Objective 2
3.2 Manage Security Risks Within the Supply Chain (e.g., Supplier, Vendor, Third-Party Risk, Contracts) ISSMP Practice Questions (Page 7)
Part of the Risk Management domain, which accounts for 20% of the ISSMP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 4–6 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
10concepts
20%of the exam
Questions 31–32
- 31
A multinational corporation is evaluating a new software vendor that will have access to its customer database. The vendor has passed initial due diligence, but the corporation wants to ensure that the vendor's security controls are actually effective before granting access. What is the BEST next step?
Select an answer first - 32
Which of the following is an example of a supply chain risk introduced by a third-party vendor?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ISSMP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “ISSMP” is a trademark of its owner, used for identification only.