Courseiva
mediumMultiple ChoiceObjective-mapped

CRISC Practice Question: Conducting a risk assessment of a critical…

A company is conducting a risk assessment of a critical third-party service provider. Which of the following is the BEST source of information to identify risks associated with the provider's sub-processors?

⚠ Common exam trap

It's easy for candidates to choose SOC 2 Type II reports of the primary provider (Option C) thinking they cover all downstream risks, but they typically exclude sub-processor controls unless specifically scoped.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The provider's documented vendor risk management program and audit reports of sub-processors

The provider's documented vendor risk management program and audit reports of sub-processors are the best source because they directly detail the controls, security posture, and compliance status of the sub-processors. This information is specific to the sub-processors' operations, unlike general reports or contracts that may not cover their unique risks. It enables the company to assess third-party and fourth-party risks as part of a comprehensive IT risk identification process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The provider's documented vendor risk management program and audit reports of sub-processors

    Why this is correct

    This directly addresses sub-processor risk identification.

  • Service level agreements in the contract

    Why it's wrong here

    SLA terms focus on performance, not sub-processor risk management.

  • SOC 2 Type II reports of the primary provider

    Why it's wrong here

    SOC reports may or may not include sub-processors; not guaranteed.

  • Public announcements of data breaches involving the provider

    Why it's wrong here

    Reactive and may not cover sub-processors.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.