CCISO Vendor Management 5 — Questions and Answers
Question 1: A CISO is developing a vendor exit strategy. Which element is MOST critical to include to protect the organization's sensitive information?
- Vendor employee retention bonuses
- Data destruction or certified return procedures with proof of completion (Correct answer)
- Vendor's future client list
- Transfer of vendor's source code to competitors
Correct answer: Data destruction or certified return procedures with proof of completion
A vendor exit strategy must include certified data destruction or return processes with documented proof to ensure sensitive information is not retained by the departing vendor.
Question 2: Which procurement practice BEST reduces the risk of counterfeit or tampered hardware components entering the organization's supply chain?
- Purchasing hardware only from the lowest-cost suppliers
- Sourcing hardware from authorized resellers and implementing integrity verification upon receipt (Correct answer)
- Relying on vendor warranty agreements
- Using open-market procurement for cost efficiency
Correct answer: Sourcing hardware from authorized resellers and implementing integrity verification upon receipt
Procuring from authorized resellers and verifying hardware integrity upon receipt reduces the risk of counterfeit or supply chain-compromised components.
Question 3: Under the NIST Cybersecurity Framework, supply chain risk management (C-SCRM) is PRIMARILY associated with which function?
- Detect
- Respond
- Identify (Correct answer)
- Recover
Correct answer: Identify
NIST CSF places supply chain risk management under the Identify function, as it involves understanding the risk landscape of suppliers and partners.
Question 4: A CISO requires that all vendors complete a security questionnaire before contract award. This activity BEST represents which phase of vendor lifecycle management?
- Vendor termination
- Vendor onboarding and due diligence (Correct answer)
- Ongoing performance monitoring
- Contract renewal negotiation
Correct answer: Vendor onboarding and due diligence
Completing security questionnaires prior to contract award is a due diligence activity performed during the vendor onboarding phase.
Question 5: Which of the following BEST describes the purpose of a vendor scorecard in a third-party risk management program?
- To rank vendors by their pricing competitiveness
- To provide a structured, measurable assessment of vendor performance across security and operational criteria (Correct answer)
- To document the history of vendor invoices
- To compare vendor marketing materials against competitors
Correct answer: To provide a structured, measurable assessment of vendor performance across security and operational criteria
A vendor scorecard provides a structured framework to objectively measure and compare vendor performance against defined security, operational, and compliance criteria.
Question 6: A CISO is negotiating a cloud services contract. Which provision is MOST important to address data residency requirements?
- Uptime SLA guarantees
- Contractual specification of geographic regions where data may be stored and processed (Correct answer)
- Vendor's marketing content rights
- Auto-renewal clauses
Correct answer: Contractual specification of geographic regions where data may be stored and processed
Specifying permissible geographic regions for data storage and processing in the contract directly addresses data residency and regulatory compliance requirements.
Question 7: Which strategy BEST mitigates the risk of vendor personnel becoming a conduit for social engineering attacks against the organization?
- Limiting vendor contracts to fixed-price agreements
- Requiring vendor personnel to complete security awareness training aligned with organizational policies (Correct answer)
- Ensuring vendors maintain their own separate IT infrastructure
- Conducting weekly vendor invoice reviews
Correct answer: Requiring vendor personnel to complete security awareness training aligned with organizational policies
Security awareness training for vendor personnel aligned to organizational policies reduces the likelihood of vendor staff being successfully targeted or manipulated in social engineering attacks.
A CISO is developing a vendor exit strategy.
Which element is MOST critical to include to protect the organization's sensitive information?