Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security manager is developing a third-party risk management program. Which two of the following are considered best practices for assessing and managing vendor risk throughout the vendor lifecycle? (Choose two.)

⚠ Common exam trap

The trap here is thinking that a one-time vendor assessment or self-attestation is sufficient, when effective third-party risk management requires ongoing validation and inclusion of the entire supply chain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Performing continuous monitoring of the vendor's security posture throughout the contract term.

Best practices for third-party risk management include conducting pre-contract due diligence and performing continuous monitoring throughout the contract term. These activities ensure that risks are identified before onboarding and managed as they evolve. Relying solely on self-attestation, limiting assessment to onboarding, or excluding subcontractors are all ineffective and can lead to unmanaged risk and compliance failures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Performing continuous monitoring of the vendor's security posture throughout the contract term.

    Why this is correct

    Continuous monitoring ensures that the vendor maintains the agreed-upon security controls and promptly identifies changes that could introduce new risks. It can include periodic reassessments, security ratings, and monitoring for breaches. This is a best practice because risk is not static; a vendor's posture can change due to incidents, mergers, or control failures. Ongoing monitoring supports timely risk mitigation.

  • ✓

    Conducting a thorough pre-contract due diligence assessment of the vendor's security posture.

    Why this is correct

    Pre-contract due diligence is a best practice to ensure that the vendor meets the organization's security requirements before any data is shared or services are used. It helps identify risks early and informs contract negotiations. This assessment should cover the vendor's security policies, controls, certifications, and incident history. Without it, the organization may onboard a vendor with unacceptable risk.

  • ✗

    Relying solely on the vendor's self-attestation of compliance with industry standards.

    Why it's wrong here

    Self-attestation can be easily falsified or outdated and does not provide independent verification. Best practice requires validating the vendor's claims through audits, certifications, or third-party assessments. Relying solely on self-attestation leaves the organization exposed to undisclosed risks. It is insufficient for effective vendor risk management.

  • ✗

    Excluding the vendor's subcontractors from the risk assessment scope.

    Why it's wrong here

    Subcontractors can introduce significant risk, especially if they handle sensitive data or have access to critical systems. Best practice includes assessing the entire supply chain, including subcontractors, either directly or through the primary vendor's oversight. Excluding them creates blind spots and potential compliance violations. The organization remains accountable for data protection regardless of subcontracting.

  • ✗

    Limiting the vendor risk assessment to the initial onboarding phase only.

    Why it's wrong here

    Risk assessment should be an ongoing process, not a one-time event. Threats, vulnerabilities, and business relationships evolve, so limiting assessment to onboarding ignores new risks that emerge later. Best practice requires periodic reassessments and continuous monitoring. A static assessment can become quickly outdated and provide a false sense of security.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.