Winter Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

CTPRP Exam Dumps - Shared Assessments Third Party Risk Management Questions and Answers

Question # 34

Which of the following factors is MOST important when assessing the risk of shadow IT in organizational security?

Options:

A.

The organization maintains adequate policies and procedures that communicate required controls for security functions

B.

The organization requires security training and certification for security personnel

C.

The organization defines staffing levels to address impact of any turnover in security roles

D.

The organization's resources and investment are sufficient to meet security requirements

Buy Now
Question # 35

When defining due diligence requirements for the set of vendors that host web applications which of the following is typically NOT part of evaluating the vendor's patch

management controls?

Options:

A.

The capability of the vendor to apply priority patching of high-risk systems

B.

Established procedures for testing of patches, service packs, and hot fixes prior to installation

C.

A documented process to gain approvals for use of open source applications

D.

The existence of a formal process for evaluation and prioritization of known vulnerabilities

Buy Now
Question # 36

Your organization has recently acquired a set of new global third party relationships due to M&A. You must define your risk assessment process based on your due diligence

standards. Which risk factor is LEAST important in defining your requirements?

Options:

A.

The risk of increased expense to conduct vendor assessments based on client contractual requirements

B.

The risk of natural disasters and physical security risk based on geolocation

C.

The risk of increased government regulation and decreased political stability based on country risk

D.

The financial risk due to local economic factors and country infrastructure

Buy Now
Question # 37

Which activity BEST describes conducting due diligence of a lower risk vendor?

Options:

A.

Accepting a service providers self-assessment questionnaire responses

B.

Preparing reports to management regarding the status of third party risk management and remediation activities

C.

Reviewing a service provider's self-assessment questionnaire and external audit report(s)

D.

Requesting and filing a service provider's external audit report(s) for future reference

Buy Now
Question # 38

The BEST time in the SDLC process for an application service provider to perform Threat Modeling analysis is:

Options:

A.

Before the application design and development activities begin

B.

After the application vulnerability or penetration test is completed

C.

After testing and before the deployment of the final code into production

D.

Prior to the execution of a contract with each client

Buy Now
Question # 39

Which approach demonstrates GREATER maturity of physical security compliance?

Options:

A.

Leveraging periodic reporting to schedule facility inspections based on reported events

B.

Providing a checklist for self-assessment

C.

Maintaining a standardized scheduled for confirming controls to defined standards

D.

Conducting unannounced checks an an ac-hac basis

Buy Now
Question # 40

Which factor describes the concept of criticality of a service provider relationship when determining vendor classification?

Options:

A.

Criticality is limited to only the set of vendors involved in providing disaster recovery services

B.

Criticality is determined as all high risk vendors with access to personal information

C.

Criticality is assigned to the subset of vendor relationships that pose the greatest impact due to their unavailability

D.

Criticality is described as the set of vendors with remote access or network connectivity to company systems

Buy Now
Exam Code: CTPRP
Exam Name: Certified Third-Party Risk Professional (CTPRP)
Last Update: Feb 6, 2025
Questions: 125
CTPRP pdf

CTPRP PDF

$29.75  $84.99
CTPRP Engine

CTPRP Testing Engine

$33.25  $94.99
CTPRP PDF + Engine

CTPRP PDF + Testing Engine

$47.25  $134.99