Courseiva

CRISC Risk Response and Reporting Practice Question

A third-party vendor is classified as high risk due to its access to sensitive data. Which THREE activities should be part of ongoing monitoring for this vendor?

⚠ Common exam trap

Watch out — candidates often confuse pre-contract due diligence activities (like SOC 2 certification or initial questionnaires) with ongoing monitoring activities, leading candidates to select options that are valid but belong to a different phase of the vendor risk management lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Contract compliance reviews to ensure terms are met.

Option A is correct because ongoing monitoring for a high-risk vendor must include contract compliance reviews, which verify that the vendor continues to meet agreed security, privacy, and service-level terms throughout the relationship, not just at signing. Option C is correct because continuous monitoring via shared threat intelligence platforms provides real-time visibility into emerging threats, indicators of compromise, and the vendor's security posture, which is essential for a vendor with access to sensitive data. Option D is correct because annual reassessment of the vendor's security posture is a recurring due-diligence activity that re-evaluates controls, risk ratings, and changes in the vendor's environment over time. Option B is not part of ongoing monitoring because requiring SOC 2 Type II certification is a pre-contract due-diligence step performed before signing, not a continuous monitoring activity. Option E is also not ongoing monitoring because the initial onboarding security questionnaire review occurs only at the start of the relationship and does not provide continuous oversight.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Contract compliance reviews to ensure terms are met.

    Why this is correct

    Contract compliance reviews verify the vendor still meets agreed security, privacy and service terms, directly addressing the sensitive-data access that makes this vendor high risk. Reviews detect drift from contractual obligations before it becomes a reportable exposure.

  • ✗

    Requiring SOC 2 Type II certification before contract signing.

    Why it's wrong here

    SOC 2 Type II certification is a point-in-time attestation obtained during procurement, not a recurring monitoring activity, and it covers the vendor's own controls rather than the specific sensitive-data access granted here. It is tempting because it evidences control effectiveness, and would be correct when qualifying a vendor before contract signing.

  • ✓

    Continuous monitoring via shared threat intelligence platforms.

    Why this is correct

    Sharing threat intelligence gives near-real-time indicators of compromise affecting the vendor, satisfying the ongoing monitoring requirement for a high-risk third party with sensitive data access. It detects emerging threats between periodic assessments, unlike annual questionnaires or static contractual reviews, enabling prompt risk response.

  • ✓

    Annual reassessment of the vendor's security posture.

    Why this is correct

    Annual reassessment verifies the high-risk vendor's security posture remains adequate as its data access, infrastructure and threat landscape evolve. It satisfies the ongoing monitoring requirement by providing periodic independent validation, complementing continuous technical controls such as access reviews and vulnerability tracking.

  • ✗

    Initial onboarding security questionnaire review.

    Why it's wrong here

    An onboarding questionnaire is a one-off due-diligence gate performed before or at contract award, so it produces no recurring assurance once the vendor is live. It is tempting because it does establish the initial risk baseline, and would be the right artefact when first assessing or re-assessing a vendor's inherent risk.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.