C_ARSUM Ariba Supplier Management Practice Question
A supplier risk analyst is reviewing how SAP Ariba Supplier Management calculates a supplier's risk exposure in a supplier risk project. Which two data inputs directly contribute to the risk score calculation? (Choose two.)
⚠ Common exam trap
The trap here is treating any supplier-related metric as a risk input, when only scored indicators from external feeds and risk questionnaires drive the calculation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Third-party risk data feeds such as financial and legal filings
A supplier risk score is produced by combining external risk data feeds with the supplier's own questionnaire responses, which are weighted according to the risk project's scoring configuration. Commercial metrics such as sourcing participation, directory preference, and contract counts are not scored indicators and therefore do not influence the calculated risk exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The supplier's preferred status in the supplier directory
Why it's wrong here
Preferred status is a directory categorization indicating a buyer's preference, not a risk measurement. It does not feed risk indicators or weights in a risk project, so it has no effect on the computed risk score. Confusing it with a risk input would misstate how exposure is derived.
- ✗
The count of contract workspaces linked to the supplier
Why it's wrong here
Linked contract workspaces represent existing agreements and their terms. While useful context, the number of contracts is not a scored risk indicator in the risk project calculation and does not alter the supplier's risk score. Treating it as an input would misrepresent the scoring model.
- ✗
The number of sourcing events the supplier participated in
Why it's wrong here
Sourcing event participation reflects commercial activity, not risk exposure. It is not a defined input to the risk score calculation in a supplier risk project, so including it would not change the supplier's calculated risk. This metric belongs to sourcing analytics, not to supplier risk scoring.
- ✓
Third-party risk data feeds such as financial and legal filings
Why this is correct
Supplier risk projects in SAP Ariba Supplier Management incorporate external risk data from providers that supply financial, legal, and regulatory information. These feeds populate risk indicators that are scored and rolled into the supplier's overall risk exposure, so they directly contribute to the calculation rather than merely being displayed for reference.
- ✓
The supplier's answers to risk assessment questionnaires
Why this is correct
Risk assessment questionnaires completed by the supplier provide self-reported data on controls, compliance, and exposure areas. The answers are evaluated against scoring rules defined in the risk project, and their weighted results feed directly into the supplier's risk score alongside external data, making them a primary input to the calculation.
About these practice questions
Courseiva writes every C_ARSUM question from scratch — 250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official SAP exam blueprint
This C_ARSUM practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_ARSUM exam.