CTPRP COMPREHENSIVE EXAM 2026/2027 QUESTIONS
AND SOLUTIONS RATED A+
✔✔connectivity types - ✔✔-point to point connection
-multipoint connection
-wireless
-remote terminal technology (RDP, Citrix, etc.)
✔✔third party risk management - ✔✔process for identifying and managing the risks
created when hiring a third party to provide goods and/or services
✔✔first line of defense - ✔✔lines of business who utilize the outsourced services and
has ownership of the risks the busienss unit will accept
✔✔second line of defense - ✔✔groups within the company who provide risk oversight
(risk management, compliance, legal, etc.)
✔✔third line of defense - ✔✔independent assurance providers - internal/external audit
✔✔third party risk register - ✔✔an inventory of the risk involved in outsourcing a specific
service/activity, provides a sum of all the risks associated iwth all third parties across
the org
✔✔comprehensive set of policies, standards and procedures - ✔✔foundation for every
effective third party risk management program
✔✔policies should be: - ✔✔-defined at an enterprise level
-include all relevant corporate functions
✔✔standards - ✔✔what you execute, how you take action, to enforce policies
✔✔procedures - ✔✔what you are to do to implement your policies (implementation
guidelines)
✔✔Vendor due diligence requirements are based on: - ✔✔-regulatory requirements
-corporate requirements for IT security and data privacy
-applicable industry standards
-best practices
✔✔contract - ✔✔defines the entire relationship with your vendor and establishes the
rights, roles and responsibilites
✔✔normal termination - ✔✔business relationship no longer necessary or appropriate
, ✔✔cause termination - ✔✔irreparable violation of contract terms
✔✔convenience termination - ✔✔one of you has a better arrangement/opportunity
✔✔regulatory/supervisory termination - ✔✔no explanation required
✔✔third party identification - ✔✔-who are your third party service providers
-what services do they provide
-what data/systems do they have access to
✔✔risk assessment - ✔✔-high-level overview of technology controls, info security
policies and procedures to identify areas of opportunity and risk
-identifies if there are any gaps with the controls in place
✔✔risk audit - ✔✔-a review and test of everything identified in the assessment scope
-tests the effectiveness of implemented controls
✔✔TPRM program should integrate with: - ✔✔-sourcing
-procurement
-legal
-risk
-compliance
✔✔Board level metrics - ✔✔-focus on strategic and other significant risks
-30-35 metrics
-changes are rare and exceptional
✔✔Executive management level metrics - ✔✔-focus on business and operational risks
-60-80 metrics
-changes are infrequent
✔✔Business segment level metrics - ✔✔-focus on business and operational risks
-number of metrics depends on business-specific requirements
-changes driven by risk/return opportunities
✔✔purpose of a risk assessment - ✔✔to identify the inherent and residual risk that
exists by doing business with the third party and identify if there are any gaps in the
controls
✔✔inherent risk - ✔✔amount of risk an organization can incur when there's an absence
or failing of controls
✔✔residual risk - ✔✔level of risk that exists with all of the necessary controls in place
AND SOLUTIONS RATED A+
✔✔connectivity types - ✔✔-point to point connection
-multipoint connection
-wireless
-remote terminal technology (RDP, Citrix, etc.)
✔✔third party risk management - ✔✔process for identifying and managing the risks
created when hiring a third party to provide goods and/or services
✔✔first line of defense - ✔✔lines of business who utilize the outsourced services and
has ownership of the risks the busienss unit will accept
✔✔second line of defense - ✔✔groups within the company who provide risk oversight
(risk management, compliance, legal, etc.)
✔✔third line of defense - ✔✔independent assurance providers - internal/external audit
✔✔third party risk register - ✔✔an inventory of the risk involved in outsourcing a specific
service/activity, provides a sum of all the risks associated iwth all third parties across
the org
✔✔comprehensive set of policies, standards and procedures - ✔✔foundation for every
effective third party risk management program
✔✔policies should be: - ✔✔-defined at an enterprise level
-include all relevant corporate functions
✔✔standards - ✔✔what you execute, how you take action, to enforce policies
✔✔procedures - ✔✔what you are to do to implement your policies (implementation
guidelines)
✔✔Vendor due diligence requirements are based on: - ✔✔-regulatory requirements
-corporate requirements for IT security and data privacy
-applicable industry standards
-best practices
✔✔contract - ✔✔defines the entire relationship with your vendor and establishes the
rights, roles and responsibilites
✔✔normal termination - ✔✔business relationship no longer necessary or appropriate
, ✔✔cause termination - ✔✔irreparable violation of contract terms
✔✔convenience termination - ✔✔one of you has a better arrangement/opportunity
✔✔regulatory/supervisory termination - ✔✔no explanation required
✔✔third party identification - ✔✔-who are your third party service providers
-what services do they provide
-what data/systems do they have access to
✔✔risk assessment - ✔✔-high-level overview of technology controls, info security
policies and procedures to identify areas of opportunity and risk
-identifies if there are any gaps with the controls in place
✔✔risk audit - ✔✔-a review and test of everything identified in the assessment scope
-tests the effectiveness of implemented controls
✔✔TPRM program should integrate with: - ✔✔-sourcing
-procurement
-legal
-risk
-compliance
✔✔Board level metrics - ✔✔-focus on strategic and other significant risks
-30-35 metrics
-changes are rare and exceptional
✔✔Executive management level metrics - ✔✔-focus on business and operational risks
-60-80 metrics
-changes are infrequent
✔✔Business segment level metrics - ✔✔-focus on business and operational risks
-number of metrics depends on business-specific requirements
-changes driven by risk/return opportunities
✔✔purpose of a risk assessment - ✔✔to identify the inherent and residual risk that
exists by doing business with the third party and identify if there are any gaps in the
controls
✔✔inherent risk - ✔✔amount of risk an organization can incur when there's an absence
or failing of controls
✔✔residual risk - ✔✔level of risk that exists with all of the necessary controls in place