Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Certified Third-Party Risk Professional (CTPRP)

Last Update 9 hours ago Total Questions : 125

The Certified Third-Party Risk Professional (CTPRP) content is now fully updated, with all current exam questions added 9 hours ago. Deciding to include CTPRP practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CTPRP exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CTPRP sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Certified Third-Party Risk Professional (CTPRP) practice test comfortably within the allotted time.

Question # 21

Which of the following factors is MOST important when assessing the risk of shadow IT in organizational security?

A.

The organization maintains adequate policies and procedures that communicate required controls for security functions

B.

The organization requires security training and certification for security personnel

C.

The organization defines staffing levels to address impact of any turnover in security roles

D.

The organization ' s resources and investment are sufficient to meet security requirements

Question # 22

A visual representation of locations, users, systems and transfer of personal information between outsourcers and third parties is defined as:

A.

Configuration standard

B.

Audit log report

C.

Network diagram

D.

Data flow diagram

Question # 23

Which statement BEST describes the methods of performing due diligence during third party risk assessments?

A.

Inspecting physical and environmental security controls by conducting a facility tour

B.

Reviewing status of findings from the questionnaire and defining remediation plans

C.

interviewing subject matter experts or control owners, reviewing compliance artifacts, and validating controls

D.

Reviewing and assessing only the obligations that are specifically defined in the contract

Question # 24

Which factor is MOST important when scoping assessments of cloud-based third parties that access, process, and retain personal data?

A.

The geographic location of the vendor ' s outsourced datacenters since assessments are only required for international data transfers

B.

The identification of the type of cloud hosting deployment or service model in order to confirm responsibilities between the third party and the cloud hosting provider

C.

The definition of requirements for backup capabilities for power generation and redundancy in the resilience plan

D.

The contract terms for the configuration of the environment which may prevent conducting the assessment

Question # 25

When conducting an assessment of a third party ' s physical security controls, which of the following represents the innermost layer in a ‘Defense in Depth’ model?

A.

Public internal

B.

Restricted entry

C.

Private internal

D.

Public external

Question # 26

Data loss prevention in endpoint security is the strategy for:

A.

Assuring there are adequate data backups in the event of a disaster

B.

Preventing exfiltration of confidential information by users who access company systems

C.

Enabling high-availability to prevent data transactions from loss

D.

Preventing malware from entering secure systems used for processing confidential information

Question # 27

Which cloud deployment model is focused on the management of hardware equipment?

A.

Function as a service

B.

Platform as a service

C.

Software as a service

D.

Infrastructure as a service

Question # 28

Which statement is TRUE regarding defining vendor classification or risk tiering in a TPRM program?

A.

Vendor classification and risk tiers are based upon residual risk calculations

B.

Vendor classification and risk tiering should only be used for critical third party relationships

C.

Vendor classification and corresponding risk tiers utilize the same due diligence standards for controls evaluation based upon policy

D.

Vendor classification and risk tier is determined by calculating the inherent risk associated with outsourcing a specific product or service

Question # 29

Which of the following is NOT an example of a type of application security testing?

A.

Cookie consent scanning

B.

Interactive testing

C.

Static testing

D.

Dynamic testing

Question # 30

Information classification of personal information may trigger specific regulatory obligations. Which statement is the BEST response from a privacy perspective:

A.

Personally identifiable financial information includes only consumer report information

B.

Public personal information includes only web or online identifiers

C.

Personally identifiable information and personal data are similar in context, but may have different legal definitions based upon jurisdiction

D.

Personally Identifiable Information and Protected Healthcare Information require the exact same data protection safequards

Go to page: