Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

Free CTPRP Questions Attempt

Page: 8 / 9
Question 32

When defining due diligence requirements for the set of vendors that host web applications which of the following is typically NOT part of evaluating the vendor's patch

management controls?

Options:

A.

The capability of the vendor to apply priority patching of high-risk systems

B.

Established procedures for testing of patches, service packs, and hot fixes prior to installation

C.

A documented process to gain approvals for use of open source applications

D.

The existence of a formal process for evaluation and prioritization of known vulnerabilities

Question 33

Your organization has recently acquired a set of new global third party relationships due to M&A. You must define your risk assessment process based on your due diligence

standards. Which risk factor is LEAST important in defining your requirements?

Options:

A.

The risk of increased expense to conduct vendor assessments based on client contractual requirements

B.

The risk of natural disasters and physical security risk based on geolocation

C.

The risk of increased government regulation and decreased political stability based on country risk

D.

The financial risk due to local economic factors and country infrastructure

Question 34

Which activity BEST describes conducting due diligence of a lower risk vendor?

Options:

A.

Accepting a service providers self-assessment questionnaire responses

B.

Preparing reports to management regarding the status of third party risk management and remediation activities

C.

Reviewing a service provider's self-assessment questionnaire and external audit report(s)

D.

Requesting and filing a service provider's external audit report(s) for future reference

Question 35

The BEST time in the SDLC process for an application service provider to perform Threat Modeling analysis is:

Options:

A.

Before the application design and development activities begin

B.

After the application vulnerability or penetration test is completed

C.

After testing and before the deployment of the final code into production

D.

Prior to the execution of a contract with each client

Page: 8 / 9
Exam Code: CTPRP
Exam Name: Certified Third-Party Risk Professional (CTPRP)
Last Update: May 8, 2024
Questions: 125
CTPRP pdf

CTPRP PDF

$28  $80
CTPRP Engine

CTPRP Testing Engine

$33.25  $95
CTPRP PDF + Engine

CTPRP PDF + Testing Engine

$45.5  $130