nerdexam
CompTIA

CAS-003 · Question #864

A line-of-business manager has decided, in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the…

The correct answer is E. Risk assessment. Before approving a third-party vendor arrangement, the CSO's primary responsibility is to understand the risk the relationship introduces to the organization. A risk assessment identifies, evaluates, and prioritizes risks across security, compliance, operational continuity, and…

Risk Management

Question

A line-of-business manager has decided, in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the business to increase efficiency and profit. Which of the following should the Chief Security Officer (CSO) perform before signing off on the third-party vendor?

Options

  • ASupply chain audit
  • BVulnerability assessment
  • CPenetration test
  • DApplication code review
  • ERisk assessment

How the community answered

(31 responses)
  • B
    3% (1)
  • C
    6% (2)
  • D
    3% (1)
  • E
    87% (27)

Explanation

Before approving a third-party vendor arrangement, the CSO's primary responsibility is to understand the risk the relationship introduces to the organization. A risk assessment identifies, evaluates, and prioritizes risks across security, compliance, operational continuity, and data protection dimensions specific to that vendor. A supply chain audit (A) is narrower and focuses on the vendor's own supply chain integrity. A vulnerability assessment (B) or penetration test (C) are technical evaluations of systems, not vendor risk. An application code review (D) examines software quality but doesn't address the broader security posture or contractual/compliance risks of the relationship. The risk assessment provides the comprehensive view needed before sign-off.

Topics

#third-party risk#vendor management#risk assessment#supply chain

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice