Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CTPRP Exam Dumps - Certified Third-Party Risk Professional (CTPRP)

Go to page:
Question # 33

Which statement is FALSE regarding the methods of measuring third party risk?

A.

Risk can be measured both qualitatively and quantitatively

B.

Risk can be quantified by calculating the severity of impact and likelihood of occurrence

C.

Assessing risk impact requires an analysis of prior events, frequency of occurrence, and external trends to analyze and predict the potential of a particular event happening

D.

Risk likelihood or probability is a critical element in quantifying inherent or residual risk

Full Access
Question # 34

Which statement provides the BEST example of the purpose of scoping in third party assessments?

A.

Scoping is used to reduce the number of questions the vendor has to complete based on vendor “classification

B.

Scoping is the process an outsourcer uses to configure a third party assessment based on the risk the vendor presents to the organization

C.

Scoping is an assessment technique only used for high risk or critical vendors that require on-site assessments

D.

Scoping is used primarily to limit the inclusion of supply chain vendors in third party assessments

Full Access
Question # 35

Which statement is NOT an accurate reflection of an organizations requirements within an enterprise information security policy?

A.

Security policies should define the organizational structure and accountabilities for oversight

B.

Security policies should have an effective date and date of last review by management

C.

Security policies should be changed on an annual basis due to technology changes

D.

Security policies should be organized based upon an accepted control framework

Full Access
Question # 36

Which of the following components is NOT typically included in external continuous monitoring solutions?

A.

Status updates on localized events based on geolocation

B.

Alerts on legal and regulatory actions involving the vendor

C.

Metrics that track SLAs for performance management

D.

Reports that identify changes in vendor financial viability

Full Access
Question # 37

For services with system-to-system access, which change management requirement

MOST effectively reduces the risk of business disruption to the outsourcer?

A.

Approval of the change by the information security department

B.

Documenting sufficient time for quality assurance testing

C.

Communicating the change to customers prior ta deployment to enable external acceptance testing

D.

Documenting and legging change approvals

Full Access
Go to page: