easyMultiple ChoiceObjective-mapped
CAS-004 Practice Question: A security manager is reviewing the company's…
A security manager is reviewing the company's vendor risk management program. Which of the following should be included as a mandatory step BEFORE entering into a contract with a new cloud service provider?
⚠ Common exam trap
It's easy for candidates to confuse post-contract operational activities (like incident response planning or vulnerability reporting) with pre-contract due diligence, leading them to select options that are important but not mandatory before signing a contract.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting a third-party security assessment
A third-party security assessment is a mandatory due diligence step before entering into a contract with a new cloud service provider. This assessment evaluates the vendor's security controls, compliance posture, and risk profile against the organization's requirements, ensuring that the vendor meets minimum security standards before any data or systems are entrusted to them. Without this pre-contract assessment, the organization would be accepting unknown risks that could lead to data breaches or compliance violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Establishing an incident response plan
Why it's wrong here
Incident response plan is internal, not a vendor step.
- ✗
Performing a penetration test of the vendor's infrastructure
Why it's wrong here
Penetration testing typically occurs after contract or during onboarding.
- ✓
Conducting a third-party security assessment
Why this is correct
Pre-contract assessment ensures vendor meets security requirements.
- ✗
Requesting monthly vulnerability reports
Why it's wrong here
Monthly reports are part of ongoing monitoring, not pre-contract.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.