nerdexam
IIBA

CBAP · Question #496

A conservative company with rigorous risk control plans and internal audit rules has a recurrent problem with a core Business application. As a result access to this application must be restricted…

The correct answer is A. In this context what is the company's response to the vendor's request? This question has a formatting error where choice A contains question stem text rather than an answer; the substantively correct answer is that the vendor request should be denied due to the company's risk aversion and policies requiring restricted, on-site access.

Strategy Analysis

Question

A conservative company with rigorous risk control plans and internal audit rules has a recurrent problem with a core Business application. As a result access to this application must be restricted and controlled and maintenance must be on-site. However the company feels that the application must have an emergency service team. The routine maintenance of this solution is provided by an external vendor and the vendor requested 24 hours remote access to quality and production dat

Options

  • AIn this context what is the company's response to the vendor's request?
  • BDented because of the company's risk aversion
  • CAccepted, because the company has an urgent problem to solve
  • DDenied- because the vendor requested it
  • EAccepted, because immediate remote access will resolve any issue

How the community answered

(29 responses)
  • A
    76% (22)
  • B
    7% (2)
  • C
    14% (4)
  • E
    3% (1)

Why each option

This question has a formatting error where choice A contains question stem text rather than an answer; the substantively correct answer is that the vendor request should be denied due to the company's risk aversion and policies requiring restricted, on-site access.

AIn this context what is the company's response to the vendor's request?Correct

The company's documented risk posture mandates restricted access and on-site maintenance for its core application, which directly conflicts with granting a vendor 24-hour remote access to quality and production data. Denying the request is the only option consistent with the company's internal audit rules and risk governance framework, as established security policies take precedence over operational convenience.

BDented because of the company's risk aversion

Accepting the request because of an urgent problem would violate the company's established security and risk policies, since urgency does not override documented governance controls.

CAccepted, because the company has an urgent problem to solve

Denying the request solely because the vendor requested it is not a sound rationale - denial must be grounded in policy and risk governance, not the identity of the requester.

DDenied- because the vendor requested it

Accepting on the basis that remote access will resolve issues immediately ignores the company's explicit on-site maintenance requirement and its risk-averse governance posture.

EAccepted, because immediate remote access will resolve any issue

Concept tested: Risk management and vendor access governance policy alignment

Source: https://www.iiba.org/standards-and-resources/babok/

Topics

#risk aversion#organizational policies#vendor access control#solution constraints

Community Discussion

No community discussion yet for this question.

Full CBAP Practice