CTPRP FREQUENTLY TESTED ACTUAL EXAM
QUESTIONS WITH CORRECT ANSWERS
Question 1.
third party
ANSWER
entities or persons that work on behalf of the organization but are not its employees, including
consultants, contingent workers, clients, business partners, service providers, subcontractors,
vendors, suppliers, affiliates and any other person or entity that accesses customer, company
confidential/proprietary data and/or systems that interact with that data
Question 2.
third party access to company data/systems
ANSWER
it presents unique risks due to the inability to directly address how they control access to those
systems and data
Question 3.
TPRM
ANSWER
a process for identifying and managing the risks created when hiring a third party to provide goods
and/or services. it's primary focus is usually on data protection/privacy and IT security controls, but
its scope depends entirely on the nature of the services provided by the third party. therefore, it may
include operational issues such as business continuity and disaster recovery, financial integrity,
regulatory compliance, the vendors own third party risk management practices
Question 4.
Requirements for third party oversight
ANSWER
- relationships between organization and vendors has become more complicated as vendors are
being viewed as business partners - risks associated with working with vendors have become
complicated as those vendors have been more popular targets for cyber attacks - regulatory
environment is more complex - vendors are targeted by criminals
Question 5.
governance model/structure to manage third party risk
ANSWER
- define clear roles and responsibility - risk management framework to focus approach - "right-size"
structure based on risk
1
,Question 6.
first line of defense
ANSWER
business who use the outsourced services. business unit managers control the vendor relationship
and may serve as primary contact for gathering assessment the business unit will accept
Question 7.
second line of defense
ANSWER
compromised of the groups within the company who provide risk oversight (risk management,
compliance, legal, etc). they establish policies, procedures, controls for managing risk and provide
oversight/guidance for the first line
Question 8.
third line of defense
ANSWER
internal/external audit provide validation for the risk and control assessments established by the
second line
Question 9.
policies
ANSWER
defined at enterprise level and include all relevant corporate functions
Question 10.
standards
ANSWER
corporate standards for risk tiers, rating, classifications and all regulatory/industry guidelines to be
followed
Question 11.
procedures
ANSWER
"what" you're supposed to do to implement the policies
2
, Question 12.
criteria for risk tiers will be used to establish
ANSWER
- contract requirements - level/type of assessment - frequency of assessment
Question 13.
third party contract
ANSWER
it defines entire relationship with vendor and establishes the rights, roles and responsibilities,
including ability to assess an require remediation form vendor
Question 14.
jwhich areas of the company should be involved
ANSWER
- business unit - it - procurement - security - legal - disaster recovery/BCP - support - call
center/shared services
Question 15.
how to ensure contract provitent with vendor risk rank
ANSWER
- validate contracts are aligned with vendor risk rank - standards for vendor ranks should be based on
corporate risk tolerance
Question 16.
criteria for contract review cycle
ANSWER
- periodic contract review should be developed based on vendor rank - review is required when there
are triggers (breach, merger, regulatory change, etc)
Question 17.
procedures to review existing contracts
ANSWER
- to ensure they comply with current standards (renewal, revisions, incident, etc) - a remediation
process to correct the contract deficiencies
3
QUESTIONS WITH CORRECT ANSWERS
Question 1.
third party
ANSWER
entities or persons that work on behalf of the organization but are not its employees, including
consultants, contingent workers, clients, business partners, service providers, subcontractors,
vendors, suppliers, affiliates and any other person or entity that accesses customer, company
confidential/proprietary data and/or systems that interact with that data
Question 2.
third party access to company data/systems
ANSWER
it presents unique risks due to the inability to directly address how they control access to those
systems and data
Question 3.
TPRM
ANSWER
a process for identifying and managing the risks created when hiring a third party to provide goods
and/or services. it's primary focus is usually on data protection/privacy and IT security controls, but
its scope depends entirely on the nature of the services provided by the third party. therefore, it may
include operational issues such as business continuity and disaster recovery, financial integrity,
regulatory compliance, the vendors own third party risk management practices
Question 4.
Requirements for third party oversight
ANSWER
- relationships between organization and vendors has become more complicated as vendors are
being viewed as business partners - risks associated with working with vendors have become
complicated as those vendors have been more popular targets for cyber attacks - regulatory
environment is more complex - vendors are targeted by criminals
Question 5.
governance model/structure to manage third party risk
ANSWER
- define clear roles and responsibility - risk management framework to focus approach - "right-size"
structure based on risk
1
,Question 6.
first line of defense
ANSWER
business who use the outsourced services. business unit managers control the vendor relationship
and may serve as primary contact for gathering assessment the business unit will accept
Question 7.
second line of defense
ANSWER
compromised of the groups within the company who provide risk oversight (risk management,
compliance, legal, etc). they establish policies, procedures, controls for managing risk and provide
oversight/guidance for the first line
Question 8.
third line of defense
ANSWER
internal/external audit provide validation for the risk and control assessments established by the
second line
Question 9.
policies
ANSWER
defined at enterprise level and include all relevant corporate functions
Question 10.
standards
ANSWER
corporate standards for risk tiers, rating, classifications and all regulatory/industry guidelines to be
followed
Question 11.
procedures
ANSWER
"what" you're supposed to do to implement the policies
2
, Question 12.
criteria for risk tiers will be used to establish
ANSWER
- contract requirements - level/type of assessment - frequency of assessment
Question 13.
third party contract
ANSWER
it defines entire relationship with vendor and establishes the rights, roles and responsibilities,
including ability to assess an require remediation form vendor
Question 14.
jwhich areas of the company should be involved
ANSWER
- business unit - it - procurement - security - legal - disaster recovery/BCP - support - call
center/shared services
Question 15.
how to ensure contract provitent with vendor risk rank
ANSWER
- validate contracts are aligned with vendor risk rank - standards for vendor ranks should be based on
corporate risk tolerance
Question 16.
criteria for contract review cycle
ANSWER
- periodic contract review should be developed based on vendor rank - review is required when there
are triggers (breach, merger, regulatory change, etc)
Question 17.
procedures to review existing contracts
ANSWER
- to ensure they comply with current standards (renewal, revisions, incident, etc) - a remediation
process to correct the contract deficiencies
3