CRISC Risk Response and Reporting Practice Question
An organization is implementing a third-party risk management program. Which TWO are essential components of the initial vendor risk assessment process?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security questionnaires
Security questionnaires (A) are essential because they elicit the vendor's self-reported controls, data handling practices, and security posture directly from the vendor, forming the foundational data-gathering step of an initial risk assessment. Reviewing a SOC 2 Type II report (C) is also essential because it provides independent auditor attestation that the vendor's controls operated effectively over a period (typically 6–12 months), validating the claims made in questionnaires. Contract compliance review (B) is a legal/procurement activity that occurs around contracting rather than being a core initial risk-assessment component. Quarterly vulnerability scans of vendor networks (D) are not feasible or appropriate at the initial assessment stage and typically cannot be performed against third-party infrastructure without authorization. Annual reassessment (E) is a recurring post-onboarding activity, not part of the initial vendor risk assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security questionnaires
Why this is correct
Security questionnaires elicit each vendor's controls, data handling and compliance posture before onboarding. This standardised evidence supports consistent, comparable risk tiering across the vendor population, which the initial assessment process requires to prioritise due diligence.
- ✗
Contract compliance review
Why it's wrong here
Contract compliance review verifies ongoing adherence after signing, so it belongs to continuous monitoring rather than initial assessment. It is tempting because contracts define obligations, but the initial assessment precedes the contract and examines the vendor's inherent risk and controls.
- ✓
Review of SOC 2 Type II report
Why this is correct
A SOC 2 Type II report provides independent evidence that the vendor's controls operated effectively across an audit period, not merely at a point in time. This validates the vendor's asserted security posture during initial assessment, supporting risk-based onboarding decisions.
- ✗
Quarterly vulnerability scans of vendor networks
Why it's wrong here
Quarterly vulnerability scans are continuous monitoring performed post-contract, not initial assessment. They are tempting as due diligence evidence, but the initial assessment evaluates the vendor's controls and risk posture before engagement, not periodic technical scanning of live networks.
- ✗
Annual reassessment
Why it's wrong here
Annual reassessment is a recurring monitoring activity performed after onboarding, not part of the initial assessment. It is tempting because ongoing oversight matters, but the question asks about the first evaluation before engagement, where inherent risk and due diligence are examined.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.