nerdexam
Isaca

CRISC · Question #18

A company has recently acquired a customer relationship management (CRM) application from a certified software vendor. Which of the following will BE ST help lo prevent technical vulnerabilities from

The correct answer is B. Verity me software agreement indemnifies the company from losses. When using certified vendor software, verifying the software agreement indemnifies the company from losses is a key action to manage the financial risk associated with potential technical vulnerabilities being exploited.

Submitted by chiamaka_o· Apr 18, 2026Risk Response and Reporting

Question

A company has recently acquired a customer relationship management (CRM) application from a certified software vendor. Which of the following will BE ST help lo prevent technical vulnerabilities from being exploded?

Options

  • Aimplement code reviews and Quality assurance on a regular basis
  • BVerity me software agreement indemnifies the company from losses
  • CReview the source coda and error reporting of the application
  • DUpdate the software with the latest patches and updates

How the community answered

(23 responses)
  • A
    22% (5)
  • B
    61% (14)
  • C
    4% (1)
  • D
    13% (3)

Why each option

When using certified vendor software, verifying the software agreement indemnifies the company from losses is a key action to manage the financial risk associated with potential technical vulnerabilities being exploited.

Aimplement code reviews and Quality assurance on a regular basis

Implementing code reviews and quality assurance on a regular basis is typically performed by the software vendor or for internally developed code, and is generally not feasible or appropriate for an organization acquiring COTS software from a certified vendor.

BVerity me software agreement indemnifies the company from lossesCorrect

Verifying the software agreement indemnifies the company from losses helps to prevent the financial impact of technical vulnerabilities from harming the organization. While it does not technically prevent exploitation, it serves as a critical risk transfer mechanism, ensuring that the vendor bears responsibility for damages resulting from exploitable flaws in their certified software, thereby protecting the company's financial stability.

CReview the source coda and error reporting of the application

Reviewing the source code and error reporting of the application is typically not an option for COTS software from a vendor, as source code is rarely provided, and this activity falls within the vendor's development and quality assurance processes.

DUpdate the software with the latest patches and updates

Updating the software with the latest patches and updates is a direct technical control to prevent exploitation of known vulnerabilities, but the question's chosen answer implies a focus on financial risk transfer rather than direct technical prevention.

Concept tested: Third-Party Software Risk Transfer

Topics

#Risk Transfer#Third-Party Risk Management#Contractual Risk Management#Vendor Management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice