Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

A critical vendor is being onboarded. The vendor risk appetite policy requires SOC 2 Type II reports for critical vendors. The vendor has provided a SOC 2 Type I report. What should the risk manager do?

⚠ Common exam trap

CRISC often tests the difference between SOC 2 Type I and Type II — candidates may think Type I is 'good enough' or that downgrading the vendor is a pragmatic solution, but the exam expects strict adherence to the stated policy and the correct escalation path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request a SOC 2 Type II report from the vendor

The vendor risk appetite policy explicitly requires SOC 2 Type II reports for critical vendors, and the vendor only provided a Type I report. The risk manager must enforce the policy as written, so the correct action is to request the Type II report from the vendor. Accepting a Type I or exempting the vendor would violate the stated policy and undermine the control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Request a SOC 2 Type II report from the vendor

    Why this is correct

    The policy mandates SOC 2 Type II, which tests control operating effectiveness over a period (typically 6–12 months), whereas Type I only attests design at a single point in time. Requesting the Type II report satisfies the critical vendor requirement directly.

  • ✗

    Downgrade the vendor to a lower tier

    Why it's wrong here

    Downgrading the tier changes the vendor's classification rather than satisfying the critical-vendor policy, and the vendor remains critical in practice. Tiering is the right action when a vendor genuinely no longer meets criticality criteria, not when evidence is merely incomplete.

  • ✗

    Exempt the vendor from the requirement

    Why it's wrong here

    Exempting the vendor bypasses the risk appetite policy without any compensating assessment, leaving the SOC 2 Type II gap unaddressed. Exemptions are appropriate for vendors outside the policy's scope, not for critical vendors whose required evidence is simply missing.

  • ✗

    Accept the Type I report as sufficient

    Why it's wrong here

    A SOC 2 Type I report attests to control design at a single point in time, whereas the policy mandates Type II, which tests operating effectiveness across a period. It is tempting because Type I is quicker to obtain and still covers the same trust services criteria, making it the right choice only when policy accepts design-only assurance.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.