Courseiva

CISM Information Security Programme Practice Question

Which THREE of the following are key activities in a third-party risk management (TPRM) program?

⚠ Common exam trap

CISM often tests whether candidates confuse vendor management with granting access or performing HR-style checks, when the core activities are assessment, contractual controls, and ongoing monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ongoing monitoring of vendor security posture

Option A (Ongoing monitoring of vendor security posture) is correct because TPRM requires continuous oversight of a vendor's security controls, compliance status, and threat exposure after onboarding, using methods such as periodic reassessments, security ratings services, and audit reviews. Option C (Negotiating contract security requirements) is correct because TPRM includes embedding security, privacy, data-handling, breach-notification, and right-to-audit clauses into vendor contracts to establish enforceable obligations and risk allocation. Option D (Onboarding risk assessment for new vendors) is correct because TPRM begins with due diligence before engagement, evaluating the vendor's security posture, data access, criticality, and compliance against organizational risk tolerance. Option B (Providing vendor with access to internal network) is not a TPRM activity; it is an operational access decision that should be minimized and controlled, not a core program function. Option E (Performing background checks on vendor employees) is not a TPRM program activity; personnel screening is typically the vendor's responsibility under contract, and TPRM focuses on organizational vendor risk rather than individual employee vetting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ongoing monitoring of vendor security posture

    Why this is correct

    Ongoing monitoring tracks vendor security posture after onboarding, catching new breaches, expired certifications or degraded controls that initial due diligence missed. This satisfies TPRM's requirement for continuous oversight across the vendor relationship lifecycle, not just at selection.

  • ✗

    Providing vendor with access to internal network

    Why it's wrong here

    Granting network access is an operational onboarding action performed after risk assessment and contractual controls are agreed, not a TPRM activity itself. It is tempting because third parties frequently need connectivity to deliver services, which would make it relevant to access provisioning rather than to risk management.

  • ✓

    Negotiating contract security requirements

    Why this is correct

    Negotiating contract security requirements embeds breach notification, audit rights, data handling and liability terms into the vendor agreement. This gives the organisation enforceable remedies and visibility, satisfying TPRM's need to translate assessed risk into binding obligations before the relationship begins.

  • ✓

    Onboarding risk assessment for new vendors

    Why this is correct

    Onboarding risk assessment evaluates a new vendor's security controls, data access and criticality before any contract or data sharing occurs. This satisfies TPRM's requirement to identify inherent risk at the earliest point, enabling proportionate due diligence and appropriate contractual safeguards.

  • ✗

    Performing background checks on vendor employees

    Why it's wrong here

    Background checks on vendor staff are the vendor's own employment responsibility, discharged through contractual clauses and assurance reporting, not an activity the customer performs. It is tempting because screening reduces insider risk, and would be correct if the question concerned due diligence over the vendor's security programme.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.