CRISC Risk Response and Reporting Practice Question
During a vendor risk assessment, a third-party vendor is classified as "critical" because it has access to sensitive customer data. According to the organization's risk appetite, what minimum security requirement should be mandated for this vendor?
⚠ Common exam trap
A common mix-up: candidates choose penetration test results (Option C) because they seem technically rigorous, but they fail to recognize that a point-in-time test does not provide the ongoing assurance of control effectiveness required for a critical vendor with access to sensitive customer data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SOC 2 Type II report
A SOC 2 Type II report is the minimum security requirement for a critical vendor with access to sensitive customer data because it provides an independent, audited assessment of the vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time. This aligns with the organization's risk appetite by ensuring that the vendor has demonstrated effective controls in place to protect sensitive data, rather than relying on a point-in-time test or self-reported information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SOC 2 Type II report
Why this is correct
A SOC 2 Type II report independently attests that controls over security, availability and confidentiality operated effectively across a review period, giving assurance proportionate to the critical vendor's access to sensitive customer data and satisfying the risk-appetite requirement for validated third-party control evidence.
- ✗
General liability insurance certificate
Why it's wrong here
A general liability insurance certificate transfers some financial loss but imposes no control over how the vendor safeguards sensitive customer data, so it fails the risk-appetite requirement for a critical vendor. It is tempting because insurance is a legitimate contractual safeguard, but it belongs in vendor contracts alongside, not instead of, security controls.
- ✗
Penetration test results from the vendor
Why it's wrong here
Penetration test results demonstrate exploitable vulnerabilities at a point in time, not ongoing contractual security controls. They are valuable during due diligence or periodic assurance for internet-facing systems, but they do not mandate the enforceable data-protection obligations a critical vendor handling sensitive customer data requires.
- ✗
Self-assessment questionnaire only
Why it's wrong here
A self-assessment questionnaire relies on vendor-supplied attestation, giving no independent verification of controls protecting sensitive customer data. It suits low-risk vendors where assurance costs outweigh exposure, but a critical classification demands independently validated evidence such as an audit report or certification.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.