Courseiva
mediumMultiple Choice

CRISC Practice Question: A retail company uses a third-party vendor for…

A retail company uses a third-party vendor for payment processing. The vendor's service level agreement (SLA) requires 99.9% uptime. Recently, there were two incidents of downtime totaling 0.2% in a month, still within the SLA. However, the company's internal risk monitoring detected a pattern of increasing minor incidents. The vendor insists the SLA is met. The risk manager must decide on monitoring and reporting. The company's board wants to understand the risk. What is the best course of action?

⚠ Common exam trap

CRISC often tests the difference between contractual compliance and risk posture — the trap is choosing 'SLA is met, so accept' when the question is really about emerging risk that the board needs visibility into.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request a root cause analysis from the vendor and monitor trend more closely, reporting to board if trend worsens.

Even though the SLA is technically met, the emerging pattern of minor incidents is a leading indicator of rising operational risk, so the risk manager should request a root cause analysis and tighten monitoring, escalating to the board only if the trend worsens. This balances contractual reality (SLA not breached) with proactive risk management (trend detection). It also gives the board meaningful, evidence-based information rather than alarmist or premature action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Request a root cause analysis from the vendor and monitor trend more closely, reporting to board if trend worsens.

    Why this is correct

    An SLA breach threshold alone cannot detect deteriorating stability; rising minor incidents signal systemic weakness that may precede a major outage. Requesting root cause analysis addresses the underlying cause, while trend monitoring provides early warning, with board escalation tied to worsening patterns rather than the SLA figure.

  • ✗

    Terminate the vendor contract.

    Why it's wrong here

    Termination discards a vendor currently meeting the 99.9% SLA, and the rising minor incidents do not yet justify that disruption to payment processing. It is tempting as a decisive response to deteriorating performance. The correct action is reporting the trend to the board and increasing monitoring, since the contractual threshold is still satisfied.

  • ✗

    Increase the SLA penalty.

    Why it's wrong here

    Penalty increases are contractual remedies applied at renewal, so they change nothing about the rising minor-incident trend the board needs reported now. It is tempting because penalties appear to hold the vendor accountable. The correct action reports the trend and strengthens continuous monitoring, since SLA compliance alone does not capture emerging operational risk.

  • ✗

    Accept the vendor's assurance as SLA is met.

    Why it's wrong here

    Relying on the vendor's assurance ignores the internal monitoring evidence of increasing minor incidents, leaving the board uninformed about a developing trend. It is tempting because the SLA threshold is formally met. The correct action escalates the pattern through risk reporting and enhanced monitoring rather than accepting contractual compliance as sufficient.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.