ISC2 CC Security Principles Practice Question
A company conducts a background check on a new vendor before signing a contract. This activity is an example of:
⚠ Common exam trap
The trap is the classic due diligence vs. due care confusion — candidates pick due care because it sounds like 'taking care,' but the pre-contract investigation is always due diligence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Due diligence
Due diligence is the investigation and verification process an organization performs before entering a relationship or contract — such as a background check on a vendor — to assess risks and make an informed decision. It is the 'before you sign' activity that informs risk acceptance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Due diligence
Why this is correct
Due diligence is the investigation and verification a company performs on a prospective vendor before contracting, assessing risks, finances, and compliance. The background check gathers evidence to inform the decision, matching the definition of due diligence rather than post-contract monitoring or contractual obligation.
- ✗
Risk avoidance
Why it's wrong here
A background check identifies and evaluates the vendor's risk; it does not eliminate the activity or exposure, so it cannot be avoidance, which requires cancelling the contract or refusing the engagement entirely. Avoidance is tempting because both are proactive pre-contract decisions, but avoidance removes the risk source rather than assessing it.
- ✗
Due care
Why it's wrong here
Due care is the ongoing standard of reasonable prudence, not the specific act of vetting a vendor before contracting. The check is due diligence: investigating and verifying facts about the counterparty. Due care is tempting because both terms describe responsible behaviour, but diligence is the investigation itself, while care is the continuing obligation.
- ✗
Risk transfer
Why it's wrong here
Transfer shifts financial impact to a third party via insurance or indemnity clauses; a background check merely gathers information and leaves the risk with the company. Transfer is tempting because vendor contracts often contain indemnities, but the check itself neither insures nor contractually reallocates any loss.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Risk acceptance
Risk acceptance is a risk management strategy where an organization acknowledges a potential risk but decides to tolerate it without taking active measures to reduce or eliminate it.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.