ISC2 CC Security Principles Practice Question
An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:
⚠ Common exam trap
The trap is the classic due diligence vs. due care confusion — candidates often select due care because both sound like 'being careful,' but the exam expects you to recognize that investigation/assessment is due diligence and ongoing protection is due care.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Due diligence
Due diligence is the ongoing process of investigation, assessment, and verification — performing a thorough security assessment and background checks on a vendor before engaging them is the textbook definition of exercising due diligence. It demonstrates that the organization took reasonable steps to understand and evaluate the risks involved. Due care, by contrast, is the ongoing action of maintaining that standard once the relationship exists.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is a decision to tolerate identified risk without further action; here the team is actively investigating controls rather than accepting exposure. It is tempting because engaging a vendor involves some residual risk, but acceptance is a formal decision, not an assessment activity.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts financial impact to another party, typically via insurance or contractual indemnity; assessing a vendor's controls does not transfer anything. It is tempting because outsourcing processing feels like offloading risk, but accountability and residual risk remain with the organisation.
- ✗
Due care
Why it's wrong here
Due care is the ongoing diligence of maintaining controls, whereas this assessment is the one-off diligence performed before engaging a vendor, which is due diligence. It is tempting because both describe careful investigation, but due care applies to continuing protection after selection.
- ✓
Due diligence
Why this is correct
Due diligence is the investigation and verification of a vendor's security controls, financial standing and background before entering a contract. The stem describes exactly that: assessing controls and performing background checks on a prospective processor. It satisfies the pre-engagement evaluation constraint, distinguishing it from ongoing monitoring or contractual enforcement.
Go deeper
Related to this question
Key term
Due care
Due care is the legal and ethical duty of an organization to take reasonable steps to protect sensitive information and IT systems from harm.
Key term
Standard
A standard is an agreed-upon set of rules, guidelines, or specifications that ensure consistency, compatibility, and quality across IT products, services, and processes.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.