hardMultiple Choice
CISSP Practice Question: Outsourcing its customer support operations to a…
A company is outsourcing its customer support operations to a third-party vendor. The vendor will have access to sensitive customer data. Which of the following should be the primary security requirement in the contract with the vendor?
⚠ Common exam trap
CISSP often tests the misconception that specific tactical measures (like penetration testing or background checks) are sufficient as primary security requirements, when the overarching requirement should be contractual compliance with the organization's security policies and standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vendor must comply with the company's security policies and standards.
The primary security requirement in any outsourcing contract is that the vendor must comply with the company's security policies and standards. This ensures the vendor adheres to the same security controls, procedures, and risk management practices that the company has established to protect its data. Without this overarching requirement, other specific measures like penetration testing or background checks may not align with the company's overall security posture. It also provides a contractual basis for auditing and enforcing compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor must perform annual penetration testing.
Why it's wrong here
While annual penetration testing is a valuable technical control for identifying vulnerabilities, mandating only this specific activity is insufficient for comprehensive security assurance. A robust vendor contract requires adherence to the client's entire security program, which encompasses policies, standards, and a broader range of controls, not just a single, periodic test. Relying solely on one control neglects critical aspects like continuous monitoring, incident response, and overall governance.
- ✗
The vendor must conduct background checks on all employees.
Why it's wrong here
Conducting background checks on employees is a prudent human resources security measure, but it represents only one component of a comprehensive personnel security program. While important for initial vetting, background checks do not guarantee ongoing secure behavior, compliance with specific data handling protocols, or adherence to the client's security policies. The primary contractual requirement must be for the vendor to enforce the client's security policies, which would include appropriate personnel screening alongside ongoing training, awareness, and enforcement mechanisms.
- ✗
The vendor must provide a list of all subcontractors.
Why it's wrong here
Requiring a list of all subcontractors is a critical due diligence step for understanding the full scope of the supply chain and associated third-party risks. However, merely knowing who the subcontractors are does not inherently ensure their security posture or compliance with the client's requirements. The primary contractual obligation must be that the *vendor* is responsible for ensuring *all* parties involved, including their subcontractors, adhere to the client's security policies and standards, thereby extending the security requirements throughout the service delivery chain.
- ✓
The vendor must comply with the company's security policies and standards.
Why this is correct
This is the most comprehensive and fundamental requirement for any outsourced operation, ensuring the vendor adopts the same baseline security posture, controls, and risk management philosophy as the client. By mandating compliance with the company's established security policies and standards, the contract holistically covers all aspects of data protection, access control, incident response, and regulatory adherence. This approach directly aligns the vendor's security practices with the client's expectations and risk tolerance, providing a robust framework for protecting sensitive information.
Go deeper
Related to this question
Learn chapter
Legal, Regulatory, and Compliance Issues
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
Key term
Penetration testing
Penetration testing is a simulated cyberattack on a computer system, network, or application to find security weaknesses before real attackers can exploit them.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.