Courseiva
easyMultiple ChoiceObjective-mapped

CAS-004 Practice Question: A security manager is reviewing the company's…

A security manager is reviewing the company's vendor risk management program. Which of the following should be included as a mandatory step BEFORE entering into a contract with a new cloud service provider?

⚠ Common exam trap

It's easy for candidates to confuse post-contract operational activities (like incident response planning or vulnerability reporting) with pre-contract due diligence, leading them to select options that are important but not mandatory before signing a contract.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conducting a third-party security assessment

A third-party security assessment is a mandatory due diligence step before entering into a contract with a new cloud service provider. This assessment evaluates the vendor's security controls, compliance posture, and risk profile against the organization's requirements, ensuring that the vendor meets minimum security standards before any data or systems are entrusted to them. Without this pre-contract assessment, the organization would be accepting unknown risks that could lead to data breaches or compliance violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Establishing an incident response plan

    Why it's wrong here

    Incident response plan is internal, not a vendor step.

  • Performing a penetration test of the vendor's infrastructure

    Why it's wrong here

    Penetration testing typically occurs after contract or during onboarding.

  • Conducting a third-party security assessment

    Why this is correct

    Pre-contract assessment ensures vendor meets security requirements.

  • Requesting monthly vulnerability reports

    Why it's wrong here

    Monthly reports are part of ongoing monitoring, not pre-contract.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.