CTPRP LATEST EXAM TEST 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔how to identify a third party - ✔✔- who are you third party service providers?
- what services do they provide?
- what data/systems do they have access to?
✔✔program execution of vendor - ✔✔1. assessment, risk rating, and other due
diligence
2. RFPs and contracts
3. ongoing monitoring
4. remediation or termination
✔✔assessment and other due diligence - ✔✔- scope of business objectives, needs,
timelines
- initial establishment of third party SOW and contract risk
- establish relationship owner
- risk ranking criterial at SOW level
- initial supplier list
- initial risk ranking for potential third parties
✔✔contracts - ✔✔- leverage assigned risk ranking
- issue remediation/closure based on performance
- formalize oversight and monitoring
- response to any findings after onboarding is preset during contract negotiations and
acted upon when monitoring results fail short of stated expectations
- response ay include application of exit strategy
✔✔monitoring - ✔✔- periodic validation of risk ranking
- frequency based on risk and service provided
- agree on scope and type of review to be performed
- perform onsite reviews agreed upon control
- determine elements that may be subject to continuous monitoring
✔✔remediate or terminate - ✔✔- normal end of contract, cause, convince, or breach
drive
- apply pre-set remediations strategy, as need based on monitoring reports
- apply pre-set exit strategy, as need based on or end of contract life
✔✔data types - ✔✔- personally identifiable information (PII)
- protected health information (PHI)
- card holder date (CHD)/payment card industry (PCI)
- confidential/intellectual property/sensitive (CIPS)
, ✔✔personally identifiable data (PII) - ✔✔information that can be used to trace a
person's identity (name, SS, DOB, biometrics, medical/educational/financial records)
✔✔types of PII - ✔✔- basic
- sensitive
✔✔basic PII - ✔✔name, phone, address, email, IP address
✔✔sensitive PII - ✔✔SS, license, DOB
✔✔protected health information (PHI) - ✔✔health information/plan/care, medical
information
✔✔card holder data (CHD)/payment card industry (PCI) - ✔✔credit/debit card
information that can includes the primary account number, cardholder name, expiration,
service code (3 digit #)
✔✔confidential, intellectual property, sensitive data (CIPS) - ✔✔- competitive pricing
- advertising or networking
- financial information
- SEC filing data (if public)
- patents, copyrights, trademarks
- internally sensitive data
✔✔controls - ✔✔safeguards to avoid, detect, counteract, or minimize security risk to
physical property, information, computer systems, or other assets
✔✔information security policy - ✔✔a document that is approved by management and
serves as a foundation for the information security controls of an organization
✔✔critical information security responsibilities are: - ✔✔- adequate protection of data
- initiate and review the implementation of info sec
- establish, communicate, maintain policies/standards/procedures/practices for security
and handling org's data
- incident response program - monitor, assessment methods, suitable liaison
✔✔when evaluating sufficiency of vendor's security policy consider: - ✔✔- sufficiency of
security due diligence in vendor research and selection
- adequacy of contractual assurances on security responsibilities, controls and reporting
- appropriateness of non-disclosure agreements regarding organization's system and
data
✔✔assets include but not limited to: - ✔✔- hardware
- software
- data
SOLUTIONS RATED A+
✔✔how to identify a third party - ✔✔- who are you third party service providers?
- what services do they provide?
- what data/systems do they have access to?
✔✔program execution of vendor - ✔✔1. assessment, risk rating, and other due
diligence
2. RFPs and contracts
3. ongoing monitoring
4. remediation or termination
✔✔assessment and other due diligence - ✔✔- scope of business objectives, needs,
timelines
- initial establishment of third party SOW and contract risk
- establish relationship owner
- risk ranking criterial at SOW level
- initial supplier list
- initial risk ranking for potential third parties
✔✔contracts - ✔✔- leverage assigned risk ranking
- issue remediation/closure based on performance
- formalize oversight and monitoring
- response to any findings after onboarding is preset during contract negotiations and
acted upon when monitoring results fail short of stated expectations
- response ay include application of exit strategy
✔✔monitoring - ✔✔- periodic validation of risk ranking
- frequency based on risk and service provided
- agree on scope and type of review to be performed
- perform onsite reviews agreed upon control
- determine elements that may be subject to continuous monitoring
✔✔remediate or terminate - ✔✔- normal end of contract, cause, convince, or breach
drive
- apply pre-set remediations strategy, as need based on monitoring reports
- apply pre-set exit strategy, as need based on or end of contract life
✔✔data types - ✔✔- personally identifiable information (PII)
- protected health information (PHI)
- card holder date (CHD)/payment card industry (PCI)
- confidential/intellectual property/sensitive (CIPS)
, ✔✔personally identifiable data (PII) - ✔✔information that can be used to trace a
person's identity (name, SS, DOB, biometrics, medical/educational/financial records)
✔✔types of PII - ✔✔- basic
- sensitive
✔✔basic PII - ✔✔name, phone, address, email, IP address
✔✔sensitive PII - ✔✔SS, license, DOB
✔✔protected health information (PHI) - ✔✔health information/plan/care, medical
information
✔✔card holder data (CHD)/payment card industry (PCI) - ✔✔credit/debit card
information that can includes the primary account number, cardholder name, expiration,
service code (3 digit #)
✔✔confidential, intellectual property, sensitive data (CIPS) - ✔✔- competitive pricing
- advertising or networking
- financial information
- SEC filing data (if public)
- patents, copyrights, trademarks
- internally sensitive data
✔✔controls - ✔✔safeguards to avoid, detect, counteract, or minimize security risk to
physical property, information, computer systems, or other assets
✔✔information security policy - ✔✔a document that is approved by management and
serves as a foundation for the information security controls of an organization
✔✔critical information security responsibilities are: - ✔✔- adequate protection of data
- initiate and review the implementation of info sec
- establish, communicate, maintain policies/standards/procedures/practices for security
and handling org's data
- incident response program - monitor, assessment methods, suitable liaison
✔✔when evaluating sufficiency of vendor's security policy consider: - ✔✔- sufficiency of
security due diligence in vendor research and selection
- adequacy of contractual assurances on security responsibilities, controls and reporting
- appropriateness of non-disclosure agreements regarding organization's system and
data
✔✔assets include but not limited to: - ✔✔- hardware
- software
- data