hardMultiple ChoiceObjective-mapped
CISSP Practice Question: Outsourcing its customer support operations to a…
A company is outsourcing its customer support operations to a third-party vendor. The vendor will have access to sensitive customer data. Which of the following should be the primary security requirement in the contract with the vendor?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vendor must comply with the company's security policies and standards.
The primary security requirement in a contract with a third-party vendor that accesses sensitive data is to mandate compliance with the company's security policies and standards. This ensures consistent and comprehensive protection across all aspects of vendor operations, including access controls, data handling, incident response, and oversight of subcontractors. Option A (annual penetration testing) is a valuable specific security control but not the overarching requirement; it should be part of the policies with which the vendor must comply. Option B (background checks on employees) is an important personnel security measure but is typically a component of the company's security policies rather than the primary contractual requirement. Option C (providing a list of all subcontractors) is relevant for supply chain risk management, but again, the fundamental requirement is that the vendor adheres to the company's policies, which would include requirements for subcontractor disclosure and management. Therefore, policy compliance is the overarching contractual necessity that encompasses all other specific controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor must perform annual penetration testing.
Why it's wrong here
While annual penetration testing is a valuable technical control for identifying vulnerabilities, mandating only this specific activity is insufficient for comprehensive security assurance. A robust vendor contract requires adherence to the client's entire security program, which encompasses policies, standards, and a broader range of controls, not just a single, periodic test. Relying solely on one control neglects critical aspects like continuous monitoring, incident response, and overall governance.
- ✗
The vendor must conduct background checks on all employees.
Why it's wrong here
Conducting background checks on employees is a prudent human resources security measure, but it represents only one component of a comprehensive personnel security program. While important for initial vetting, background checks do not guarantee ongoing secure behavior, compliance with specific data handling protocols, or adherence to the client's security policies. The primary contractual requirement must be for the vendor to enforce the client's security policies, which would include appropriate personnel screening alongside ongoing training, awareness, and enforcement mechanisms.
- ✗
The vendor must provide a list of all subcontractors.
Why it's wrong here
Requiring a list of all subcontractors is a critical due diligence step for understanding the full scope of the supply chain and associated third-party risks. However, merely knowing who the subcontractors are does not inherently ensure their security posture or compliance with the client's requirements. The primary contractual obligation must be that the *vendor* is responsible for ensuring *all* parties involved, including their subcontractors, adhere to the client's security policies and standards, thereby extending the security requirements throughout the service delivery chain.
- ✓
The vendor must comply with the company's security policies and standards.
Why this is correct
This is the most comprehensive and fundamental requirement for any outsourced operation, ensuring the vendor adopts the same baseline security posture, controls, and risk management philosophy as the client. By mandating compliance with the company's established security policies and standards, the contract holistically covers all aspects of data protection, access control, incident response, and regulatory adherence. This approach directly aligns the vendor's security practices with the client's expectations and risk tolerance, providing a robust framework for protecting sensitive information.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.