Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Certified Third-Party Risk Professional (CTPRP)

Last Update 9 hours ago Total Questions : 125

The Certified Third-Party Risk Professional (CTPRP) content is now fully updated, with all current exam questions added 9 hours ago. Deciding to include CTPRP practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CTPRP exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CTPRP sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Certified Third-Party Risk Professional (CTPRP) practice test comfortably within the allotted time.

Question # 11

When updating TPRM vendor classification requirements with a focus on availability, which

risk rating factors provide the greatest impact to the analysis?

A.

Type of data by classification; volume of records included in data processing

B.

Financial viability of the vendor; ability to meet performance metrics

C.

Network connectivity; remote access to applications

D.

impact on operations and end users; impact on revenue; impact on regulatory compliance

Question # 12

Which type of contract provision is MOST important in managing Fourth-Nth party risk after contract signing and on-boarding due diligence is complete?

A.

Subcontractor notice and approval

B.

Indemnification and liability

C.

Breach notification

D.

Right to audit

Question # 13

Which TPRM risk assessment component would typically NOT be maintained in a Risk Register?

A.

An assessment of the impact and likelihood the risk will occur and the possible seriousness

B.

Vendor inventory of all suppliers, vendors, and service providers prioritized by contract value

C.

An outline of proposed mitigation actions and assignment of risk owner

D.

A grading of each risk according to a risk assessment table or hierarchy

Question # 14

During the contract negotiation process for a new vendor, the vendor states they have legal obligations to retain data for tax purposes. However, your company policy requires data

return or destruction at contract termination. Which statement provides the BEST approach to address this conflict?

A.

Determine if a policy exception and approval is required, and require that data safeguarding obligations continue after termination

B.

Change the risk rating of the vendor to reflect a higher risk tier

C.

Insist the vendor adheres to the policy and contract provisions without exception

D.

Conduct an assessment of the vendor ' s data governance and records management program

Question # 15

When working with third parties, which of the following requirements does not reflect a “Zero Trust " approach to access management?

A.

Utilizing a solution that allows direct access by third parties to the organization ' s network

B.

Ensure that access is granted on a per session basis regardless of network location, user, or device

C.

Implement device monitoring, continual inspection and monitoring of logs/traffic

D.

Require that all communication is secured regardless of network location

Question # 16

The set of shared values and beliefs that govern a company’s attitude toward risk is known as:

A.

Risk tolerance

B.

Risk treatment

C.

Risk culture

D.

Risk appetite

Question # 17

Which statement is FALSE regarding the primary factors in determining vendor risk classification?

A.

The geographic area where the vendor is located may trigger specific regulatory obligations

B.

The importance to the outsourcer ' s recovery objectives may trigger a higher risk tier

C.

The type and volume of personal data processed may trigger a higher risk rating based on the criticality of the systems

D.

Network connectivity or remote access may trigger a higher vendor risk classification only for third parties that process personal information

Question # 18

Which statement is NOT a method of securing web applications?

A.

Ensure appropriate logging and review of access and events

B.

Conduct periodic penetration tests

C.

Adhere to web content accessibility guidelines

D.

Include validation checks in SDLC for cross site scripting and SOL injections

Question # 19

Which statement is TRUE regarding the use of questionnaires in third party risk assessments?

A.

The total number of questions included in the questionnaire assigns the risk tier

B.

Questionnaires are optional since reliance on contract terms is a sufficient control

C.

Assessment questionnaires should be configured based on the risk rating and type of service being evaluated

D.

All topic areas included in the questionnaire require validation during the assessment

Question # 20

Which of the following is a positive aspect of adhering to a secure SDLC?

A.

Promotes a “check the box " compliance approach

B.

A process that defines and meets both the business requirements and the security requirements

C.

A process that forces quality code repositories management

D.

Enables the process if system code is managed in different IT silos

Go to page: