mediumMultiple Choice
CRISC Practice Question: Wants to identify risks related to third-party…
An organization wants to identify risks related to third-party vendors. Which approach best supports continuous risk identification?
⚠ Common exam trap
Many candidates choose periodic assessments (A, B, or D) because they seem thorough, but CRISC emphasizes continuous risk identification over point-in-time reviews, and automated monitoring is the only option that provides real-time, ongoing visibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated monitoring of vendor security controls via a third-party risk platform
Automated monitoring via a third-party risk platform enables continuous, real-time visibility into vendor security controls, such as firewall rule changes, vulnerability scan results, and compliance posture. This approach aligns with the CRISC principle of ongoing risk identification, as it detects changes in risk exposure between formal assessment cycles without relying on periodic snapshots.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Contractual clauses requiring self-assessment
Why it's wrong here
Self-assessment clauses rely on vendor-reported information delivered at contract-defined intervals, so the organisation learns of emerging risks only when the vendor chooses to disclose them. It is tempting because contractual obligations are inexpensive and scalable, and they would suffice where assurance depends on vendor attestation rather than independent continuous monitoring.
- ✗
On-site audits every two years
Why it's wrong here
On-site audits every two years produce point-in-time evidence with a long gap between visits, so risks arising in the interim go unidentified. It is tempting because direct inspection yields strong assurance, and it would be correct where deep periodic verification, not continuous identification, is the objective.
- ✓
Automated monitoring of vendor security controls via a third-party risk platform
Why this is correct
Automated monitoring via a third-party risk platform provides continuous, near-real-time visibility into vendor security posture, satisfying the stem's requirement for ongoing risk identification rather than periodic assessments. Unlike manual reviews, it detects control degradation as it occurs, enabling timely risk register updates and remediation before exposures escalate.
- ✗
Annual vendor risk assessments
Why it's wrong here
Annual assessments capture vendor risk at a single point each year, leaving the remaining months unmonitored and unable to satisfy continuous identification. It is tempting because scheduled assessments provide structured, repeatable coverage, and they would be the right choice where periodic attestation, not continuous monitoring, is the requirement.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.