CISM Information Security Risk Management Practice Question
A software development company is assessing the risk of using a third-party cloud provider to host its source code repository. The security manager must determine whether the provider's security controls are sufficient. Which of the following is the MOST effective way to obtain assurance about the provider's security posture?
⚠ Common exam trap
The trap here is accepting self-reported claims or questionnaires as sufficient assurance instead of requiring independent, period-based audit evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request the provider's most recent independent audit report, such as SOC 2 Type II
Independent audit reports such as SOC 2 Type II provide validated evidence that a third-party provider's controls operated effectively over a defined period. They are prepared by a qualified auditor and cover relevant trust services criteria, giving the organization reliable assurance for risk assessment and vendor management. Self-reported materials, questionnaires, or unauthorized testing do not offer the same level of independent, ongoing verification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ask the provider to complete a security questionnaire and sign a confidentiality agreement
Why it's wrong here
A security questionnaire is a self-assessment and can be useful for initial screening, but it does not independently verify controls. Signing a confidentiality agreement protects information but does not assure security. Without independent validation or audit evidence, the organization cannot be confident that the provider's controls are effective in practice.
- ✓
Request the provider's most recent independent audit report, such as SOC 2 Type II
Why this is correct
An independent audit report, such as SOC 2 Type II, provides validated evidence that the provider's controls operated effectively over a period. It covers security, availability, and confidentiality criteria and is issued by a third-party auditor. This gives the organization reliable assurance for risk assessment and vendor management, far more than self-attestations or marketing claims.
- ✗
Review the provider's public marketing materials and security whitepapers
Why it's wrong here
Marketing materials and whitepapers are self-reported and not independently verified. They may highlight strengths but omit weaknesses or control gaps. Relying on them for assurance is insufficient because they do not provide evidence of actual control effectiveness over time. A formal audit report or direct assessment is needed to validate the provider's security posture.
- ✗
Conduct a penetration test of the provider's infrastructure without notifying them
Why it's wrong here
Unauthorized penetration testing of a third party's infrastructure is unethical and likely illegal, and it does not provide ongoing assurance. Even authorized testing only captures a point-in-time view and may not cover all relevant controls. The most effective assurance comes from independent audit reports that evaluate controls over a period.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.