ISC2 CC Security Principles Practice Question
A security analyst is evaluating a new vendor for cloud services. The analyst reviews the vendor's security certifications, conducts background checks, and visits the data center. This process is an example of:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Due diligence
Due diligence involves investigating and verifying before making a decision, such as vendor risk assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Due care
Why it's wrong here
Due care is the ongoing obligation to act responsibly, not the specific evidence-gathering activity described. It would describe maintaining controls over time. The stem's certifications review, background checks and site visit constitute due diligence before signing.
- ✗
Governance
Why it's wrong here
Governance is the overarching framework of policies, roles and oversight directing security decisions; it is not the act of vetting one vendor. It would be correct when defining who approves vendors or setting policy. The stem describes pre-contract due diligence.
- ✓
Due diligence
Why this is correct
Due diligence is the investigation and verification of a vendor's controls before contracting, covering certification review, background checks and site visits. These activities assess the vendor's actual security posture, satisfying the evaluation described in the scenario.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is formally acknowledging a residual risk and proceeding without further controls; the analyst is gathering evidence, not accepting anything. It would be correct after mitigation options are exhausted and management signs off on the remaining exposure.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Due diligence
Due diligence is the process of systematically reviewing and verifying information, policies, and procedures to identify and manage risks before making a decision or taking an action in an IT or security context.
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.