hardMultiple ChoiceObjective-mapped
CISSP Practice Question: Considering outsourcing its customer support…
A company is considering outsourcing its customer support operations to a third-party vendor. Which of the following should be the PRIMARY risk management activity before finalizing the contract?
⚠ Common exam trap
ISC2 often tests the misconception that risk transfer (insurance) or legal agreements (NDAs) are primary risk management activities, when in fact proactive assessment and due diligence must occur first to identify and treat risks before any contractual commitment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a thorough vendor risk assessment including security audits.
Before outsourcing critical operations, the primary risk management activity is to conduct a thorough vendor risk assessment, including security audits. This evaluates the vendor's security posture, compliance with standards (e.g., ISO 27001), and ability to protect sensitive customer data, directly addressing risks like data breaches or service disruptions before contractual obligations are locked in.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a thorough vendor risk assessment including security audits.
Why this is correct
Conducting a thorough vendor risk assessment, including security audits, is the most critical proactive step in managing third-party risk. This process involves evaluating the vendor's security posture, controls, compliance frameworks, and operational resilience to ensure they can adequately protect the company's data and systems. Security audits, such as SOC 2 reports or independent penetration tests, provide objective evidence of their capabilities, identifying potential vulnerabilities and compliance gaps before any commitment is made. This due diligence is essential for mitigating risks and ensuring the vendor meets the organization's security requirements.
- ✗
Negotiate a lower price to offset potential security investments.
Why it's wrong here
While cost is a significant factor in any business decision, negotiating a lower price does not address or mitigate the inherent security risks introduced by outsourcing to a third-party vendor. Financial adjustments cannot compensate for inadequate security controls, potential data breaches, or non-compliance with regulatory requirements. Prioritizing cost savings over robust security due diligence can lead to significantly higher financial, reputational, and operational losses in the event of a security incident, far outweighing any initial cost reduction.
- ✗
Purchase cyber liability insurance to cover potential breaches.
Why it's wrong here
Purchasing cyber liability insurance is a valuable risk transfer mechanism that can help mitigate the financial impact of a data breach or cyber incident after it occurs. However, it is a reactive measure that addresses the consequences rather than a proactive control to prevent or reduce the likelihood of a breach. Relying solely on insurance without conducting proper security due diligence leaves the organization exposed to operational disruptions, reputational damage, and regulatory penalties that insurance may not fully cover, as it does not improve the vendor's security posture.
- ✗
Require the vendor to sign a non-disclosure agreement (NDA).
Why it's wrong here
A Non-Disclosure Agreement (NDA) is a fundamental legal document that establishes confidentiality obligations and protects proprietary information shared with a vendor. While essential for legal recourse in case of unauthorized disclosure, an NDA primarily addresses the legal framework for information protection, not the technical or procedural security controls implemented by the vendor. It does not provide insight into the vendor's actual ability to prevent breaches, manage vulnerabilities, or adhere to security best practices, which requires a comprehensive security assessment.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.