Courseiva
Security Principles →hardMultiple Choice

ISC2 CC Security Principles Practice Question

An organization is evaluating a new vendor that will process customer data. The security team performs a thorough assessment of the vendor's security controls and background checks. This process best demonstrates:

⚠ Common exam trap

The trap is the classic due diligence vs. due care confusion — candidates often select due care because both sound like 'being careful,' but the exam expects you to recognize that investigation/assessment is due diligence and ongoing protection is due care.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Due diligence

Due diligence is the ongoing process of investigation, assessment, and verification — performing a thorough security assessment and background checks on a vendor before engaging them is the textbook definition of exercising due diligence. It demonstrates that the organization took reasonable steps to understand and evaluate the risks involved. Due care, by contrast, is the ongoing action of maintaining that standard once the relationship exists.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance is a decision to tolerate identified risk without further action; here the team is actively investigating controls rather than accepting exposure. It is tempting because engaging a vendor involves some residual risk, but acceptance is a formal decision, not an assessment activity.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts financial impact to another party, typically via insurance or contractual indemnity; assessing a vendor's controls does not transfer anything. It is tempting because outsourcing processing feels like offloading risk, but accountability and residual risk remain with the organisation.

  • ✗

    Due care

    Why it's wrong here

    Due care is the ongoing diligence of maintaining controls, whereas this assessment is the one-off diligence performed before engaging a vendor, which is due diligence. It is tempting because both describe careful investigation, but due care applies to continuing protection after selection.

  • ✓

    Due diligence

    Why this is correct

    Due diligence is the investigation and verification of a vendor's security controls, financial standing and background before entering a contract. The stem describes exactly that: assessing controls and performing background checks on a prospective processor. It satisfies the pre-engagement evaluation constraint, distinguishing it from ongoing monitoring or contractual enforcement.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.