Courseiva

C_ARSUM Ariba Supplier Management Practice Question

When designing a modular questionnaire, what is the best practice for managing sensitive supplier compliance documentation?

⚠ Common exam trap

Candidates often confuse 'Internal-only' visibility with 'External' access, incorrectly assuming that external-facing questionnaires can hide sensitive fields from the supplier while still collecting the data through that same form.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use internal-only visibility conditions

Using internal-only attachments and visibility conditions ensures that sensitive documents are accessible only to authorized personnel. This is essential for maintaining privacy and ensuring compliance with data regulations like GDPR. By restricting visibility at the question level, organizations prevent data leakage and ensure that sensitive certificates are reviewed by appropriate legal or compliance teams while keeping the supplier-facing interface clean and focused on necessary information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store all documents in a public folder

    Why it's wrong here

    Storing compliance documentation in a public folder is a major security risk. It exposes sensitive corporate data to unauthorized users, failing to comply with standard security practices and potentially leading to compliance breaches regarding the handling of confidential supplier certification and verification documents.

  • ✓

    Use internal-only visibility conditions

    Why this is correct

    Internal-only visibility conditions allow documents to be uploaded by the requester or internal reviewer without being visible to the supplier. This maintains a clean and secure process for internal documentation, ensuring that sensitive information remains contained within the company’s internal review cycles and protected from external access.

  • ✗

    Mandate that suppliers email documents to buyers

    Why it's wrong here

    Emailing sensitive documentation is inherently unsecure and bypasses the audit trail of the Ariba platform. This approach creates data silos, increases the risk of loss, and makes it impossible for the system to track compliance progress automatically through the standard workflow-based lifecycle management process.

  • ✗

    Attach documents to the supplier master record

    Why it's wrong here

    Attaching documents directly to the master record can lead to version control issues and difficulties in tracking specific compliance renewals. Modular questionnaires are designed to handle these documents in a process-oriented manner, ensuring that they are associated with the correct review context and workflow.

About these practice questions

Courseiva writes every C_ARSUM question from scratch — 250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official SAP exam blueprint

This C_ARSUM practice question is part of Courseiva's free SAP certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C_ARSUM exam.