Courseiva
mediumMultiple Choice

CRISC Practice Question: Wants to identify risks related to third-party…

An organization wants to identify risks related to third-party vendors. Which approach best supports continuous risk identification?

⚠ Common exam trap

Many candidates choose periodic assessments (A, B, or D) because they seem thorough, but CRISC emphasizes continuous risk identification over point-in-time reviews, and automated monitoring is the only option that provides real-time, ongoing visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated monitoring of vendor security controls via a third-party risk platform

Automated monitoring via a third-party risk platform enables continuous, real-time visibility into vendor security controls, such as firewall rule changes, vulnerability scan results, and compliance posture. This approach aligns with the CRISC principle of ongoing risk identification, as it detects changes in risk exposure between formal assessment cycles without relying on periodic snapshots.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Contractual clauses requiring self-assessment

    Why it's wrong here

    Self-assessment clauses rely on vendor-reported information delivered at contract-defined intervals, so the organisation learns of emerging risks only when the vendor chooses to disclose them. It is tempting because contractual obligations are inexpensive and scalable, and they would suffice where assurance depends on vendor attestation rather than independent continuous monitoring.

  • ✗

    On-site audits every two years

    Why it's wrong here

    On-site audits every two years produce point-in-time evidence with a long gap between visits, so risks arising in the interim go unidentified. It is tempting because direct inspection yields strong assurance, and it would be correct where deep periodic verification, not continuous identification, is the objective.

  • ✓

    Automated monitoring of vendor security controls via a third-party risk platform

    Why this is correct

    Automated monitoring via a third-party risk platform provides continuous, near-real-time visibility into vendor security posture, satisfying the stem's requirement for ongoing risk identification rather than periodic assessments. Unlike manual reviews, it detects control degradation as it occurs, enabling timely risk register updates and remediation before exposures escalate.

  • ✗

    Annual vendor risk assessments

    Why it's wrong here

    Annual assessments capture vendor risk at a single point each year, leaving the remaining months unmonitored and unable to satisfy continuous identification. It is tempting because scheduled assessments provide structured, repeatable coverage, and they would be the right choice where periodic attestation, not continuous monitoring, is the requirement.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.