nerdexam
CompTIA

CAS-005 · Question #370

Which of the following describes how a risk assessment is performed when an organization has a critical vendor that provides multiple products?

The correct answer is A. At the individual product level. A risk assessment should be performed at the individual product level when an organization has a critical vendor providing multiple products. This approach ensures that each product is evaluated for its specific risks, vulnerabilities, and impact on the organization. By…

Submitted by kwame.gh· Mar 6, 2026Governance, Risk, and Compliance

Question

Which of the following describes how a risk assessment is performed when an organization has a critical vendor that provides multiple products?

Options

  • AAt the individual product level
  • BThrough the selection of a random product
  • CUsing a third-party audit report
  • DBy choosing a major product

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    7% (2)
  • C
    4% (1)
  • D
    4% (1)

Explanation

A risk assessment should be performed at the individual product level when an organization has a critical vendor providing multiple products. This approach ensures that each product is evaluated for its specific risks, vulnerabilities, and impact on the organization. By assessing each product separately, the organization can identify and prioritize the risks associated with each product rather than making assumptions based on a single product or a general overview.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice