Courseiva
easyMultiple Choice

CAS-004 Practice Question: A security manager is reviewing the company's…

A security manager is reviewing the company's vendor risk management program. Which of the following should be included as a mandatory step BEFORE entering into a contract with a new cloud service provider?

⚠ Common exam trap

It's easy for candidates to confuse post-contract operational activities (like incident response planning or vulnerability reporting) with pre-contract due diligence, leading them to select options that are important but not mandatory before signing a contract.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conducting a third-party security assessment

A third-party security assessment is a mandatory due diligence step before entering into a contract with a new cloud service provider. This assessment evaluates the vendor's security controls, compliance posture, and risk profile against the organization's requirements, ensuring that the vendor meets minimum security standards before any data or systems are entrusted to them. Without this pre-contract assessment, the organization would be accepting unknown risks that could lead to data breaches or compliance violations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Establishing an incident response plan

    Why it's wrong here

    An incident response plan addresses events after onboarding; the mandatory pre-contract step is assessing the provider's security controls and risk posture. It is tempting because incident response is a genuine vendor management control, but it belongs in the contract's operational terms rather than the pre-contract assessment.

  • ✗

    Performing a penetration test of the vendor's infrastructure

    Why it's wrong here

    Penetration testing a provider's infrastructure without authorisation is legally and contractually prohibited; the mandatory pre-contract step is reviewing the provider's independent audit reports and certifications. It is tempting because testing gives direct evidence, but it is only permissible once contractual authorisation exists.

  • ✓

    Conducting a third-party security assessment

    Why this is correct

    A third-party security assessment independently verifies the provider's controls, certifications and data-handling practises before contractual commitment, giving the security manager evidence to judge residual risk. This due diligence must precede signing, since contractual leverage and exit options diminish afterwards.

  • ✗

    Requesting monthly vulnerability reports

    Why it's wrong here

    Monthly vulnerability reports are an ongoing contractual assurance mechanism, not a pre-contract due diligence step; the mandatory step is assessing the provider's controls before signing. It is tempting because continuous monitoring is valuable, but it applies after the contract exists.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.