CTPRP Exam Expected Questions and Verified Answers
(2026-2027)
Question 1.
third party
Correct Answer: entities or persons that work on behalf of the organization but
are not its employees, including consultants, contingent workers, clients,
business partners, service providers, subcontractors, vendors, suppliers,
affiliates and any other person or entity that accessess customer, company
confidential/proprietary data and/or systems that interact with that data
Question 2.
outsourcer
Correct Answer: the entity delegating a function to another entity, or is
considering doing so
Question 3.
outsourcer
Correct Answer: the entity evaluating the risk posed by obtaining services from
another entity
Question 4.
fourth party/subcontractor
Correct Answer: an entity independent of and directly performing tasks for the
assessee being evaluated
Question 5.
drivers for third party risk assessments
Correct Answer: ISO 27002, FFEIC Appendix, OOC Bulletins, FFEIC CAT Tool, PCI
Data Security Standard, NIST Cybersecurity Framework, HIPAA/HiTech, EU GDPR
Question 6.
different names for third parties
Correct Answer: Business Associate, Service Provider, Processor, Person who
provides support for the internal operations of the Web site or online service,
Third-Party Service Provider
, Question 7.
Office of the Comptroller of the Currency (OOC) lifecycle framework for third party risk
Correct Answer: Planning, Due Diligence and Third Party Selection, Contract
Negotiation, Ongoing Monitoring, Termination
Question 8.
False - You must determine the third party's ability to satisfy those requirements.
Correct Answer: T/F - You can rely on contract requirements to satisfy
regulatory requirements for third parties.
Question 9.
True - e.g., HIPAA and OFAC
Correct Answer: T/F - It is possible to be subject to regulations from different
industry sectors
Question 10.
False - in many instances state requirements may be more stringent than federal
Correct Answer: T/F - Federal regulations always supersede state regulations
Question 11.
Audits should ensure compliance with:
Correct Answer: Corporate, Legal, Regulatory, Industry requirements
Question 12.
Risk Assessment and Treatment
Correct Answer: Describes the vendor's risk assessment program, and its
maturity and operating effectiveness.
Question 13.
True
Correct Answer: T/F - A risk assessment program should be approved by
management and communicated to all appropriate constituents
(2026-2027)
Question 1.
third party
Correct Answer: entities or persons that work on behalf of the organization but
are not its employees, including consultants, contingent workers, clients,
business partners, service providers, subcontractors, vendors, suppliers,
affiliates and any other person or entity that accessess customer, company
confidential/proprietary data and/or systems that interact with that data
Question 2.
outsourcer
Correct Answer: the entity delegating a function to another entity, or is
considering doing so
Question 3.
outsourcer
Correct Answer: the entity evaluating the risk posed by obtaining services from
another entity
Question 4.
fourth party/subcontractor
Correct Answer: an entity independent of and directly performing tasks for the
assessee being evaluated
Question 5.
drivers for third party risk assessments
Correct Answer: ISO 27002, FFEIC Appendix, OOC Bulletins, FFEIC CAT Tool, PCI
Data Security Standard, NIST Cybersecurity Framework, HIPAA/HiTech, EU GDPR
Question 6.
different names for third parties
Correct Answer: Business Associate, Service Provider, Processor, Person who
provides support for the internal operations of the Web site or online service,
Third-Party Service Provider
, Question 7.
Office of the Comptroller of the Currency (OOC) lifecycle framework for third party risk
Correct Answer: Planning, Due Diligence and Third Party Selection, Contract
Negotiation, Ongoing Monitoring, Termination
Question 8.
False - You must determine the third party's ability to satisfy those requirements.
Correct Answer: T/F - You can rely on contract requirements to satisfy
regulatory requirements for third parties.
Question 9.
True - e.g., HIPAA and OFAC
Correct Answer: T/F - It is possible to be subject to regulations from different
industry sectors
Question 10.
False - in many instances state requirements may be more stringent than federal
Correct Answer: T/F - Federal regulations always supersede state regulations
Question 11.
Audits should ensure compliance with:
Correct Answer: Corporate, Legal, Regulatory, Industry requirements
Question 12.
Risk Assessment and Treatment
Correct Answer: Describes the vendor's risk assessment program, and its
maturity and operating effectiveness.
Question 13.
True
Correct Answer: T/F - A risk assessment program should be approved by
management and communicated to all appropriate constituents