100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CTPRP Exam | 99 Questions and Answers Graded A+

Rating
-
Sold
-
Pages
8
Grade
A+
Uploaded on
18-08-2025
Written in
2025/2026

entities or persons that work on behalf of the organization but are not its employees, including consultants, contingent workers, clients, business partners, service providers, subcontractors, vendors, suppliers, affiliates and any other person or entity that accessess customer, company confidential/proprietary data and/or systems that interact with that data - ANSWER -third party the entity delegating a function to another entity, or is considering doing so - ANSWER - outsourcer the entity evaluating the risk posed by obtaining services from another entity - ANSWER - outsourcer an entity independent of and directly performing tasks for the assessee being evaluated - AN

Show more Read less
Institution
CTPRP
Course
CTPRP









Whoops! We can’t load your doc right now. Try again or contact support.

Written for

Institution
CTPRP
Course
CTPRP

Document information

Uploaded on
August 18, 2025
Number of pages
8
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CTPRP Exam | 99 Questions and Answers Graded A+
entities or persons that work on behalf of the
organization but are not its employees, including
consultants, contingent workers, clients, T/F - You can rely on contract requirements to
business partners, service providers, satisfy regulatory requirements for third parties. -
subcontractors, vendors, suppliers, affiliates and ANSWER -False - You must determine the
any other person or entity that accessess third party's ability to satisfy those requirements.
customer, company confidential/proprietary data
and/or systems that interact with that data -
ANSWER -third party T/F - It is possible to be subject to regulations
from different industry sectors - ANSWER -
True - e.g., HIPAA and OFAC
the entity delegating a function to another entity,
or is considering doing so - ANSWER -
outsourcer T/F - Federal regulations always supersede state
regulations - ANSWER -False - in many
instances state requirements may be more
the entity evaluating the risk posed by obtaining stringent than federal
services from another entity - ANSWER -
outsourcer
Corporate, Legal, Regulatory, Industry
requirements - ANSWER -Audits should
an entity independent of and directly performing ensure compliance with:
tasks for the assessee being evaluated -
ANSWER -fourth party/subcontractor
Describes the vendor's risk assessment program,
and its maturity and operating effectiveness. -
ISO 27002, FFEIC Appendix, OOC Bulletins, ANSWER -Risk Assessment and Treatment
FFEIC CAT Tool, PCI Data Security Standard,
NIST Cybersecurity Framework, HIPAA/HiTech,
EU GDPR - ANSWER -drivers for third T/F - A risk assessment program should be
party risk assessments approved by management and communicated to
all appropriate constituents - ANSWER -
True
Business Associate, Service Provider,
Processor, Person who provides support for the
internal operations of the Web site or online Protected Health Information, Electronic Health
service, Third-Party Service Provider - Records, Personally Identifiable Financial
ANSWER -different names for third parties Information, Cardholder Data, Personal Data,
Personal Information, Consumer Financial
Information - ANSWER -Different names for
Planning, Due Diligence and Third Party data
Selection, Contract Negotiation, Ongoing
Monitoring, Termination - ANSWER -Office
of the Comptroller of the Currency (OOC) any information about an individual maintained by
lifecycle framework for third party risk an agency, including (1) any information that can
1/8

, CTPRP Exam | 99 Questions and Answers Graded A+
be used to distinguish or trace an individual's infrastructure is managed and operated
identity, such as name, or biometric records and exclusively for one company in order to keep a
(2) any other information that is linked or linkable consistent level of security privacy, and
to an individual, such as medical, educational, governance control. - ANSWER -private
financial and employment information - cloud
ANSWER -Personally Identifiable
Information (PII)
combination of public and private cloud
computing environments shared between them -
physical - last name, first name, phone #'s, street ANSWER -hybrid cloud
address - ANSWER -Basic PII

collaborative effort in which infrastructure is
PII used in conjunction with basic PII (i.e., SS shared between several organizations from a
card, Driver's License, DOB) - ANSWER - specific community with common concerns -
Sensitive PII ANSWER -community cloud


credit or debit card info that includes the Primary owned by a cloud vendor and is accessible to the
Account Number (PAN), which is the payment general public or a large industry group -
card number (credit or debit) that identifies the ANSWER -public cloud
issuer and the particular cardholder account -
ANSWER -Card Holder
Data(CHD)/Payment Card Industry(PCI) data - review of audit form attestation reports
- security services documentation
- image snapshot approval and mgmt process
Organization outsources the equipment used to - patching responsibility - ANSWER -
support operations, including storage, hardware, components of a cloud vendor assessment
servers and networking components. - program
ANSWER -IaaS (Infrastructure as a
Service)
assess the perimeter - ANSWER -first layer
of defense in physical and environmental security
Hardware and software infrastructure for the
development of business applications. Most
commonly used by application developers. - - video surveillance
ANSWER -PaaS (Platform as a Service) - electronic access control at essential
ingress/egress points
- correlation of the video an dcard access data
Business application delivered over the Internet - retention of video and logs for forensics -
in which users interact iwth the application ANSWER -monitoring and controls
through a web browser. - ANSWER -SaaS established for infrastructure
(Software as a Service)

process for documenting and maintaining an
2/8

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
MERCYTRISHIA Howard Community College
View profile
Follow You need to be logged in order to follow users or courses
Sold
177
Member since
1 year
Number of followers
35
Documents
10547
Last sold
5 days ago
MercyTrishia

On this page, you find all documents, package deals offered by seller MercyTrishia

3.8

37 reviews

5
16
4
7
3
10
2
0
1
4

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can immediately select a different document that better matches what you need.

Pay how you prefer, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card or EFT and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Frequently asked questions