nerdexam
CompTIA

CAS-003 · Question #923

A line-of-business manager has deeded in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the…

The correct answer is E. Risk assessment. Before the CSO signs off on a third-party vendor relationship, a Risk Assessment must be performed. A risk assessment is the foundational step that identifies, analyzes, and evaluates all risks the vendor relationship introduces-including data security, regulatory compliance…

Risk Management

Question

A line-of-business manager has deeded in conjunction with the IT and legal departments, that outsourcing a specific function to a third-party vendor would be the best course of action for the business to increase efficiency and profit. Which of the following should the Chief Security Officer (CSO) perform before signing off on the third-party vendor?

Options

  • ASupply chain audit
  • BVulnerability assessment
  • CPenetration test
  • DApplication code review
  • ERisk assessment

How the community answered

(25 responses)
  • A
    4% (1)
  • C
    4% (1)
  • E
    92% (23)

Explanation

Before the CSO signs off on a third-party vendor relationship, a Risk Assessment must be performed. A risk assessment is the foundational step that identifies, analyzes, and evaluates all risks the vendor relationship introduces-including data security, regulatory compliance (GDPR, HIPAA, etc.), supply chain risk, operational dependencies, and the vendor's own security posture. It determines whether residual risk is acceptable given the business benefit and informs contract terms like SLAs, right-to-audit clauses, and data handling requirements. The other options may be components that feed into a risk assessment: a supply chain audit (A) is a subset activity; a vulnerability assessment (B) or penetration test (C) may be required of the vendor; an application code review (D) is relevant only if the vendor delivers software. The risk assessment is the overarching process that drives the decision.

Topics

#third-party risk#risk assessment#vendor due diligence#supply chain

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice