Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: Considering outsourcing its customer support…

A company is considering outsourcing its customer support operations to a third-party vendor. Which of the following should be the PRIMARY risk management activity before finalizing the contract?

⚠ Common exam trap

ISC2 often tests the misconception that risk transfer (insurance) or legal agreements (NDAs) are primary risk management activities, when in fact proactive assessment and due diligence must occur first to identify and treat risks before any contractual commitment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a thorough vendor risk assessment including security audits.

Before outsourcing critical operations, the primary risk management activity is to conduct a thorough vendor risk assessment, including security audits. This evaluates the vendor's security posture, compliance with standards (e.g., ISO 27001), and ability to protect sensitive customer data, directly addressing risks like data breaches or service disruptions before contractual obligations are locked in.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct a thorough vendor risk assessment including security audits.

    Why this is correct

    Conducting a thorough vendor risk assessment, including security audits, is the most critical proactive step in managing third-party risk. This process involves evaluating the vendor's security posture, controls, compliance frameworks, and operational resilience to ensure they can adequately protect the company's data and systems. Security audits, such as SOC 2 reports or independent penetration tests, provide objective evidence of their capabilities, identifying potential vulnerabilities and compliance gaps before any commitment is made. This due diligence is essential for mitigating risks and ensuring the vendor meets the organization's security requirements.

  • Negotiate a lower price to offset potential security investments.

    Why it's wrong here

    While cost is a significant factor in any business decision, negotiating a lower price does not address or mitigate the inherent security risks introduced by outsourcing to a third-party vendor. Financial adjustments cannot compensate for inadequate security controls, potential data breaches, or non-compliance with regulatory requirements. Prioritizing cost savings over robust security due diligence can lead to significantly higher financial, reputational, and operational losses in the event of a security incident, far outweighing any initial cost reduction.

  • Purchase cyber liability insurance to cover potential breaches.

    Why it's wrong here

    Purchasing cyber liability insurance is a valuable risk transfer mechanism that can help mitigate the financial impact of a data breach or cyber incident after it occurs. However, it is a reactive measure that addresses the consequences rather than a proactive control to prevent or reduce the likelihood of a breach. Relying solely on insurance without conducting proper security due diligence leaves the organization exposed to operational disruptions, reputational damage, and regulatory penalties that insurance may not fully cover, as it does not improve the vendor's security posture.

  • Require the vendor to sign a non-disclosure agreement (NDA).

    Why it's wrong here

    A Non-Disclosure Agreement (NDA) is a fundamental legal document that establishes confidentiality obligations and protects proprietary information shared with a vendor. While essential for legal recourse in case of unauthorized disclosure, an NDA primarily addresses the legal framework for information protection, not the technical or procedural security controls implemented by the vendor. It does not provide insight into the vendor's actual ability to prevent breaches, manage vulnerabilities, or adhere to security best practices, which requires a comprehensive security assessment.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.