Courseiva
easyMultiple Choice

CRISC Practice Question: A company uses a third-party SaaS application for…

A company uses a third-party SaaS application for payroll processing. What is the most important activity to identify IT risks associated with this service?

⚠ Common exam trap

Watch out — candidates often confuse risk identification activities (like vendor assessments) with risk mitigation controls (like MFA) or contractual reviews (like SLAs), leading them to select a control or document review instead of the foundational assessment needed to uncover risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conducting a vendor risk assessment

A vendor risk assessment is the most important activity because it systematically evaluates the third-party SaaS provider's security controls, compliance posture, and operational resilience before and during service use. For a payroll SaaS, this includes reviewing data protection measures for sensitive employee PII, understanding the provider's SOC 2 Type II report, and assessing their incident response capabilities. Without this assessment, the organization cannot identify inherent risks like unauthorized data access, service downtime, or regulatory non-compliance specific to the third-party environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conducting a vendor risk assessment

    Why this is correct

    Conducting a vendor risk assessment directly addresses the third-party SaaS constraint by evaluating the provider's security controls, data handling, subcontractors and compliance posture. It identifies risks the organisation inherits but cannot inspect, such as multi-tenant isolation, breach notification and service continuity, satisfying the stem's requirement to identify IT risks associated with the payroll service.

  • ✗

    Performing penetration testing on the SaaS application

    Why it's wrong here

    Penetration testing the SaaS application is normally prohibited without the provider's authorisation and tests technical vulnerabilities, not the full spectrum of third-party risk such as data residency, subprocessors or exit. It is tempting because testing identifies weaknesses, but it cannot assess contractual and operational exposure.

  • ✗

    Reviewing the service-level agreement (SLA)

    Why it's wrong here

    An SLA documents committed service levels and remedies; it does not itself identify the risks arising from the arrangement, such as data protection, provider viability or compliance. It is tempting because the SLA is a key artefact to examine, but reviewing it is one input to a broader third-party risk assessment, not the identification activity itself.

  • ✗

    Implementing multi-factor authentication (MFA)

    Why it's wrong here

    MFA is a control that mitigates access risk after identification; it does not surface the risks inherent in outsourcing payroll to a third party. It is tempting because authentication weaknesses are a real SaaS concern, but risk identification here requires assessing the provider's controls and contractual obligations, not implementing a safeguard.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.