Courseiva
Risk Response and ReportinghardMultiple SelectObjective-mapped

CRISC Risk Response and Reporting Practice Question

A third-party vendor is classified as high risk due to its access to sensitive data. Which THREE activities should be part of ongoing monitoring for this vendor?

⚠ Common exam trap

Watch out — candidates often confuse pre-contract due diligence activities (like SOC 2 certification or initial questionnaires) with ongoing monitoring activities, leading candidates to select options that are valid but belong to a different phase of the vendor risk management lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Contract compliance reviews to ensure terms are met.

Contract compliance reviews are a fundamental ongoing monitoring activity for high-risk vendors. They ensure the vendor continues to adhere to agreed-upon security controls, data handling procedures, and service-level agreements (SLAs) throughout the relationship, not just at onboarding. This is a continuous verification process, distinct from one-time checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Contract compliance reviews to ensure terms are met.

    Why this is correct

    Contract compliance is part of ongoing oversight.

  • Requiring SOC 2 Type II certification before contract signing.

    Why it's wrong here

    This is a minimum requirement for critical/high vendors, not an ongoing monitoring activity.

  • Continuous monitoring via shared threat intelligence platforms.

    Why this is correct

    Continuous monitoring helps detect emerging risks.

  • Annual reassessment of the vendor's security posture.

    Why this is correct

    Annual reassessment is a standard ongoing monitoring activity for high-risk vendors.

  • Initial onboarding security questionnaire review.

    Why it's wrong here

    Initial review is not ongoing; it is part of onboarding.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.