CRISC Risk Response and Reporting Practice Question
An organization is designing a vendor risk assessment process for critical vendors. Which THREE of the following should be included in the initial onboarding assessment?
⚠ Common exam trap
Watch out — candidates often confuse ongoing monitoring activities (like continuous monitoring or annual reassessments) with the discrete, upfront steps required during the initial vendor onboarding assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security questionnaires
Security questionnaires (A) are a core onboarding artifact because they elicit the vendor's controls, data handling, and security posture directly from the vendor before any data or access is granted. Contract compliance review (C) is essential at onboarding to verify that the agreement contains required security, privacy, breach-notification, and data-return/retention clauses before the relationship begins. SOC 2 report review (E) is appropriate during initial assessment because it provides independent third-party attestation over the vendor's security, availability, confidentiality, or privacy controls under the Trust Services Criteria. Continuous monitoring via shared intelligence platforms (B) and annual reassessment (D) are ongoing or periodic post-onboarding activities, not initial onboarding assessment steps, so they do not belong in this phase.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security questionnaires
Why this is correct
Security questionnaires elicit the vendor's control environment, certifications and data-handling practises at onboarding, providing the baseline evidence needed to assess inherent risk before a critical vendor is engaged or granted access to systems and data.
- ✗
Continuous monitoring via shared intelligence platforms
Why it's wrong here
Continuous monitoring is an ongoing control, not an onboarding assessment activity; it belongs in steady-state vendor oversight after the contract is signed. It is tempting because shared intelligence platforms genuinely strengthen post-onboarding risk visibility, but the stem asks what to include during initial onboarding, where point-in-time due diligence on the vendor's controls is required.
- ✓
Contract compliance review
Why this is correct
Contract compliance review verifies the vendor's contractual obligations — security clauses, breach notification, data protection and service levels — are actually met, establishing the legal and control baseline required before onboarding a critical vendor into the environment.
- ✗
Annual reassessment
Why it's wrong here
Annual reassessment is an ongoing monitoring activity, not part of the initial onboarding assessment, which evaluates the vendor before engagement. It is tempting because reassessment belongs in the wider vendor risk programme, and it would be correct once the vendor is onboarded and requires periodic review.
- ✓
SOC 2 report review
Why this is correct
Reviewing the SOC 2 report provides independent assurance over the vendor's security, availability and confidentiality controls, directly satisfying the stem's requirement for a control-effectiveness assessment at onboarding. It evidences whether controls operate effectively over a period, unlike self-attested questionnaires, giving risk practitioners reliable input for critical-vendor risk decisions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.