What is the primary purpose of conducting due diligence before engaging a third-party vendor?

CISM Domain 2: Daily Questions 17.06.2025

Quiz
•
Information Technology (IT)
•
Professional Development
•
Easy

Nivedita Newar
Used 3+ times
FREE Resource
8 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A. To negotiate better pricing
B. To assess the vendor’s marketing strategy
C.To evaluate the vendor’s risk profile
D.To ensure the vendor has a large customer base
Answer explanation
A. Incorrect – Pricing is important but not the primary focus of due diligence.
B. Incorrect – Marketing strategy is not relevant to risk evaluation.
C. ✅ Correct – Due diligence helps assess the vendor’s financial, operational, and security risks.
D. Incorrect – A large customer base does not guarantee low risk.
2.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of the following is the most effective control to ensure ongoing compliance of a third-party vendor?
A. One-time risk assessment
B. Annual contract renewal
C. Continuous monitoring
D. Vendor self-attestation
Answer explanation
A. Incorrect – A one-time assessment does not account for changes over time.
B. Incorrect – Contract renewal alone does not verify compliance.
C. ✅ Correct – Continuous monitoring provides real-time insights into vendor compliance.
D. Incorrect – Self-attestation may be biased or inaccurate.
3.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of the following is the best indicator of elevated third-party risk?
A. Vendor has ISO 27001 certification
B. Vendor has experienced multiple data breaches
C. Vendor has a large IT team
D. Vendor uses cloud services
Answer explanation
A. Incorrect – Certification is a positive indicator, not a risk.
B. ✅ Correct – Multiple breaches suggest poor security posture.
C. Incorrect – Team size does not directly indicate risk.
D. Incorrect – Cloud usage is common and not inherently risky.
4.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
What is the primary reason to include termination clauses in third-party contracts?
A. To reduce service costs
B. To allow exit in case of non-compliance
C. To extend contract duration
D. To avoid legal obligations
Answer explanation
A. Incorrect – Cost reduction is not the main purpose.
B. ✅ Correct – Termination clauses provide a legal exit if the vendor fails to meet obligations.
C. Incorrect – These clauses are not for extending contracts.
D. Incorrect – Legal obligations cannot be avoided through termination clauses.
5.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of the following is the most appropriate time to perform a third-party risk assessment?
A. After a security incident
B. During contract renewal only
C. Before onboarding the vendor
D. When the vendor requests it
Answer explanation
A. Incorrect – Waiting until after an incident is reactive, not proactive.
B. Incorrect – Risk assessments should not be limited to renewals.
C. ✅ Correct – Assessing risk before onboarding helps prevent issues.
D. Incorrect – Risk assessments should be initiated by the organization, not the vendor.
6.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
An organization outsources its data processing to a third-party vendor located in a different legal jurisdiction. What is the most critical risk the organization must address in this scenario?
A. The vendor’s marketing practices
B. The vendor’s employee turnover rate
C. Cross-border data transfer compliance
D. The vendor’s use of open-source software
Answer explanation
A. Incorrect – Marketing practices are not directly relevant to data processing risk.
B. Incorrect – While turnover can affect operations, it’s not the most critical issue here.
C. ✅ Correct – Cross-border data transfer must comply with data protection laws (e.g., GDPR, HIPAA), which vary by jurisdiction.
D. Incorrect – Use of open-source software may pose risks, but legal compliance is more critical in this context.
7.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
Which of the following best demonstrates effective governance over third-party risk in a large enterprise?
A. Delegating all third-party oversight to the procurement department
B. Requiring vendors to sign NDAs before contract execution
C. Establishing a cross-functional third-party risk committee
D. Performing vendor assessments only during onboarding
Answer explanation
A. Incorrect – Sole reliance on procurement lacks the necessary risk and compliance oversight.
B. Incorrect – NDAs are important but do not constitute governance.
C. ✅ Correct – A cross-functional committee ensures comprehensive oversight, including legal, IT, risk, and business units.
D. Incorrect – Ongoing assessments are necessary; onboarding alone is insufficient.
8.
MULTIPLE CHOICE QUESTION
30 sec • 1 pt
A third-party vendor provides critical infrastructure services to your organization. The vendor has passed all initial risk assessments, but your organization lacks visibility into their subcontractors. What is the most appropriate risk mitigation strategy?
A. Require the vendor to provide a list of subcontractors and their risk profiles
B. Accept the risk due to the vendor’s initial assessment results
C. Terminate the contract and bring the service in-house
D. Increase the frequency of internal audits within your organization
Answer explanation
A. ✅ Correct – Gaining visibility into subcontractors helps assess downstream risks and ensures comprehensive oversight.
B. Incorrect – Accepting the risk without understanding subcontractor exposure is irresponsible.
C. Incorrect – Termination is extreme and may not be feasible or cost-effective.
D. Incorrect – Internal audits do not address third-party or subcontractor risks directly.
Similar Resources on Quizizz
10 questions
S.Present

Quiz
•
Professional Development
10 questions
Project Management Bespoke Lesson 1

Quiz
•
Professional Development
10 questions
[March] Download (+) Assessment

Quiz
•
Professional Development
8 questions
CISM Domain 2 - Daily Questions - 19.06.2025

Quiz
•
Professional Development
12 questions
Tosca Quiz1

Quiz
•
Professional Development
12 questions
Vendor Back Office

Quiz
•
Professional Development
12 questions
On-Call Management Procedure Quiz

Quiz
•
Professional Development
11 questions
Phishing Awareness Quiz

Quiz
•
Professional Development
Popular Resources on Quizizz
15 questions
Multiplication Facts

Quiz
•
4th Grade
20 questions
Math Review - Grade 6

Quiz
•
6th Grade
20 questions
math review

Quiz
•
4th Grade
5 questions
capitalization in sentences

Quiz
•
5th - 8th Grade
10 questions
Juneteenth History and Significance

Interactive video
•
5th - 8th Grade
15 questions
Adding and Subtracting Fractions

Quiz
•
5th Grade
10 questions
R2H Day One Internship Expectation Review Guidelines

Quiz
•
Professional Development
12 questions
Dividing Fractions

Quiz
•
6th Grade