CAS-004 Governance, Risk, and Compliance Practice Question
An organization is reviewing its supply chain risk management. Which TWO of the following are effective strategies to manage fourth-party risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include a right-to-audit clause that covers subcontractors
To manage fourth-party risk, organizations can require their vendors to flow down security requirements to subcontractors and include right-to-audit clauses that extend to subcontractors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use only vendors that are SOC 2 certified
Why it's wrong here
SOC 2 certification covers a vendor's own controls, giving no visibility into its subcontractors, so fourth-party exposure remains unassessed. It is tempting because certification signals assurance, yet it is correct only for evaluating direct vendors, not the vendors behind them.
- ✗
Reduce reliance on vendors by bringing services in-house
Why it's wrong here
In-housing removes third-party dependency but does not address the fourth parties beneath remaining suppliers, and it is often commercially impossible. It is tempting because reducing reliance genuinely lowers exposure, yet effective fourth-party risk management instead demands visibility and contractual flow-down through the prime vendor.
- ✗
Conduct penetration tests on all fourth parties directly
Why it's wrong here
Direct penetration testing of fourth parties is rarely contractually permitted and tests only a point-in-time technical posture, not ongoing dependency risk. It is tempting because testing gives concrete assurance on direct suppliers, but fourth-party risk instead demands subcontractor visibility, contractual flow-down and continuous monitoring.
- ✓
Include a right-to-audit clause that covers subcontractors
Why this is correct
Extending the right-to-audit clause to subcontractors gives the organisation contractual visibility and audit reach into fourth parties, satisfying the stem's requirement to manage risk beyond direct suppliers. Without this flow-down, subcontractor controls remain unverified, so fourth-party exposure cannot be assessed or enforced.
- ✓
Require vendors to contractually mandate security controls for their subcontractors
Why this is correct
Contractually mandating security controls for subcontractors extends governance beyond direct vendors, satisfying the requirement to manage fourth-party risk. This flows down obligations through the supply chain, ensuring subcontractors meet the same security standards. It is a recognised strategy for addressing risks originating from vendors' own suppliers.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.