CTPRP (Certified Third-Party Risk Professional) Exam — Questions and Answers
Question 1: What role does critical analysis play in understanding theory?
- Critical analysis complicates simple ideas unnecessarily
- It is only needed for academic papers
- It enables deeper comprehension and the ability to evaluate and apply concepts (Correct answer)
- Analysis should be avoided to prevent overthinking
Correct answer: It enables deeper comprehension and the ability to evaluate and apply concepts
Critical analysis develops deeper understanding, enabling practitioners to evaluate, adapt, and apply theoretical concepts effectively.
Question 2: What is the importance of proper labeling in data visualizations?
- Labels make charts look cluttered
- Labels provide context and prevent misinterpretation of the data (Correct answer)
- Only the chart title matters
- Labels are optional decorations
Correct answer: Labels provide context and prevent misinterpretation of the data
Clear labeling including titles, axis labels, units, and legends ensures viewers interpret the visualization correctly.
Question 3: What is 'continuous monitoring' in the context of third-party risk management?
- Conducting a new full assessment every week
- Reviewing vendor press releases monthly
- Monitoring only vendors with SOC 2 reports
- Ongoing surveillance of vendor risk indicators between formal assessment cycles (Correct answer)
Correct answer: Ongoing surveillance of vendor risk indicators between formal assessment cycles
Continuous monitoring uses automated tools, threat intelligence feeds, and periodic check-ins to detect changes in vendor risk posture between scheduled formal assessments.
Question 4: In a TPRM context, what is the significance of a vendor's RTO (Recovery Time Objective)?
- It measures how quickly the vendor can onboard new clients
- It quantifies the vendor's annual revenue recovery rate
- It defines the maximum acceptable downtime after a disruption before business impact becomes critical (Correct answer)
- It tracks how rapidly the vendor responds to security questionnaires
Correct answer: It defines the maximum acceptable downtime after a disruption before business impact becomes critical
RTO specifies the target time within which a vendor must restore services after an incident, directly affecting the organization's own operational continuity.
Question 5: What is the relationship between theory and practice?
- Theory informs practice, and practice tests and refines theory (Correct answer)
- They are completely separate domains
- Practice is always more important than theory
- Theory always takes priority over practical experience
Correct answer: Theory informs practice, and practice tests and refines theory
Theory and practice have a reciprocal relationship: theory guides practice, and practical experience validates and improves theory.
Question 6: When a vendor relationship is classified as 'high inherent risk,' what additional step is TYPICALLY required before contract execution?
- A social media background check on vendor executives
- Senior leadership or board-level approval of the risk acceptance decision (Correct answer)
- A preference survey from end users of the vendor's service
- A verbal agreement from the procurement team
Correct answer: Senior leadership or board-level approval of the risk acceptance decision
High inherent risk engagements typically require escalation to senior leadership or the board to ensure informed decision-making at the appropriate governance level.
Question 7: When a business unit 'inherits' responsibility for a vendor previously managed by another team, which step is MOST critical from a TPRM perspective?
- Issuing a press release announcing the new internal ownership structure
- Renegotiating the vendor's pricing to reflect the new business unit's budget
- Immediately terminating the vendor to start fresh with a new procurement process
- Verifying the vendor's current risk assessment is up to date and transferring formal risk ownership (Correct answer)
Correct answer: Verifying the vendor's current risk assessment is up to date and transferring formal risk ownership
When vendor relationship ownership transfers, the TPRM program must ensure that risk ownership — and accountability for monitoring and remediation — formally transfers as well. The incoming team must confirm the vendor's risk documentation is current and that they understand any open issues. Without this handoff, vendors can fall into monitoring gaps.
Question 8: What does 'vendor offboarding' in a TPRM program primarily ensure?
- That the vendor is added to a preferred vendor list for future use
- That the vendor's invoices are paid in full before separation
- That access is revoked and data is returned or destroyed when a vendor relationship ends (Correct answer)
- That the vendor receives a positive reference letter
Correct answer: That access is revoked and data is returned or destroyed when a vendor relationship ends
Vendor offboarding ensures that all system access is terminated, data obligations are fulfilled (returned or securely destroyed), and residual risks are managed when a vendor relationship concludes.
Question 9: What distinguishes 'due diligence' from 'due care' in the context of third-party risk management?
- Due diligence is ongoing; due care is a one-time assessment at onboarding
- Due diligence applies to vendors; due care applies only to internal staff
- Due care involves legal review; due diligence involves financial review only
- Due diligence is the investigative process of assessing risk; due care is the ongoing effort to maintain appropriate standards (Correct answer)
Correct answer: Due diligence is the investigative process of assessing risk; due care is the ongoing effort to maintain appropriate standards
Due diligence refers to the upfront investigation to understand a vendor's risk profile, while due care is the continuous responsibility to act prudently in managing those risks over time.
Question 10: A vendor's business continuity plan (BCP) indicates a Recovery Time Objective (RTO) of 72 hours for a critical service. The organization's internal RTO for the same service is 4 hours. What action should the TPRM practitioner take?
- Document the gap and revisit it annually
- Escalate the misalignment as a gap and require the vendor to improve their RTO or find an alternative (Correct answer)
- Lower the organization's internal RTO to match the vendor
- Accept the vendor's RTO as industry standard
Correct answer: Escalate the misalignment as a gap and require the vendor to improve their RTO or find an alternative
A vendor RTO that exceeds the organization's own recovery requirements creates an unacceptable continuity gap that must be resolved before or during contracting.
Question 11: How should fundamental concepts be prioritized in learning?
- Fundamentals are only for beginners
- Master basics before advancing to complex topics (Correct answer)
- Learn everything simultaneously
- Skip basics and focus on advanced material
Correct answer: Master basics before advancing to complex topics
Strong fundamentals provide the foundation upon which all advanced knowledge and skills are built.
Question 12: How do interdisciplinary connections enhance understanding of fundamentals?
- Interdisciplinary study is only for advanced learners
- Mixing disciplines creates confusion
- They reveal patterns and principles that transcend individual disciplines (Correct answer)
- Each discipline should be studied in complete isolation
Correct answer: They reveal patterns and principles that transcend individual disciplines
Cross-disciplinary connections reveal universal principles and enrich understanding through multiple perspectives.
Question 13: What is the main advantage of using a standardized performance assessment framework across all vendors?
- It guarantees vendors will meet all SLAs
- It eliminates the need for vendor contracts
- It reduces the number of vendors an organization needs
- It enables consistent comparison and benchmarking across the vendor portfolio (Correct answer)
Correct answer: It enables consistent comparison and benchmarking across the vendor portfolio
Standardization allows risk teams to compare vendor performance on the same dimensions, enabling portfolio-level risk insights.
Question 14: Which historical pattern has been most consistently observed in organizations that experience major third-party-related incidents?
- Most incidents originate from vendors in low-risk tiers who were under-assessed (Correct answer)
- All major incidents could have been prevented through better contract language alone
- Incidents typically involve new vendors in relationships less than six months old
- Incidents disproportionately involve vendors whose risk assessments were overridden by business stakeholders
Correct answer: Most incidents originate from vendors in low-risk tiers who were under-assessed
Post-incident analysis consistently reveals that compromised vendors were often tiered as low-risk and therefore received minimal scrutiny, highlighting how risk tiering methodologies frequently misclassify vendors based on apparent criticality rather than actual risk exposure.
Question 15: Which element of a vendor contract directly defines the performance standards the vendor must meet?
- Non-Disclosure Agreement (NDA)
- Master Service Agreement (MSA)
- Service-Level Agreement (SLA) (Correct answer)
- Statement of Work (SOW)
Correct answer: Service-Level Agreement (SLA)
An SLA specifies measurable performance metrics such as uptime, response time, and resolution times that the vendor is contractually obligated to maintain.
Question 16: A vendor provides a shared service to 500 clients. Which risk scenario is unique to this multi-tenant architecture?
- The vendor may run out of office space
- The vendor's customer service response times may be slower
- A breach at one client environment could potentially expose data from other clients (Correct answer)
- The vendor may not offer volume discounts
Correct answer: A breach at one client environment could potentially expose data from other clients
Multi-tenant environments introduce the risk that misconfigurations or breaches could create lateral movement opportunities affecting multiple client environments.
Question 17: Which of the following is an example of a KEY control in a vendor management policy related to data privacy compliance?
- Mandating that vendors execute a Data Processing Agreement (DPA) before handling personal data (Correct answer)
- Limiting vendor invoice submission to a specific portal
- Requiring vendors to submit quarterly sales forecasts
- Requiring vendors to use the organization's preferred font in reports
Correct answer: Mandating that vendors execute a Data Processing Agreement (DPA) before handling personal data
A DPA establishes legally binding privacy obligations consistent with regulations like GDPR and CCPA before personal data is shared with a vendor.
Question 18: What is the key purpose of a right-to-audit clause in a vendor contract?
- To allow the client organization to audit the vendor's controls and compliance (Correct answer)
- To authorize government regulators to inspect vendor facilities on behalf of the client
- To give the vendor the right to audit the client's financials
- To permit third-party auditors to review the client's own employees
Correct answer: To allow the client organization to audit the vendor's controls and compliance
A right-to-audit clause contractually reserves the client's ability to conduct or commission audits of the vendor's controls, ensuring ongoing accountability beyond self-attestation.
Question 19: In vendor governance, what does 'escalation path' refer to?
- The defined process for raising unresolved vendor issues to higher authority (Correct answer)
- The vendor's internal promotion structure
- The vendor's plan to grow its business with your organization
- The contract renewal negotiation process
Correct answer: The defined process for raising unresolved vendor issues to higher authority
An escalation path defines the steps and authorities involved when vendor performance issues, control failures, or contractual disputes cannot be resolved at the operational level.
Question 20: A CTPRP holder is asked to sign off on a third-party risk assessment completed by a junior analyst they supervised. What is their ethical obligation?
- Add a disclaimer noting they did not complete the work personally
- Refuse to sign any work they did not personally complete
- Sign without review if they trust the analyst
- Review the work to ensure quality and accuracy before attesting to it (Correct answer)
Correct answer: Review the work to ensure quality and accuracy before attesting to it
Supervising professionals bear responsibility for the quality of work they endorse and must review it adequately before signing.
Question 21: What is the primary risk of relying solely on a vendor's ISO 27001 certification as evidence of adequate information security controls?
- Certification expires daily
- Certification confirms a management system exists but does not verify specific control effectiveness (Correct answer)
- ISO 27001 is not internationally recognized
- ISO 27001 only applies to data centers
Correct answer: Certification confirms a management system exists but does not verify specific control effectiveness
ISO 27001 certification confirms the existence of an ISMS framework but does not guarantee that specific controls relevant to your organization are operating effectively.
Question 22: Which statement about CTPRP renewal fees is most accurate?
- Renewal fees are only assessed if the holder fails to meet CPE requirements on time
- A renewal fee is typically required in addition to completing CPE requirements (Correct answer)
- Renewal is free for all credential holders as part of the initial exam fee
- Renewal fees are waived for holders employed by Shared Assessments member organizations
Correct answer: A renewal fee is typically required in addition to completing CPE requirements
CTPRP renewal requires both the completion of CPE credits and payment of a renewal fee to the certifying body.
Question 23: Under GDPR, when a US company uses a European vendor to process EU personal data, the US company is classified as the:
- Data controller responsible for determining processing purposes (Correct answer)
- Joint controller sharing equal liability with the vendor
- Data subject with rights to erasure
- Data processor with full liability
Correct answer: Data controller responsible for determining processing purposes
Under GDPR, the entity that determines the purposes and means of processing personal data is the data controller, which retains ultimate responsibility for compliance.
Question 24: A CTPRP holder takes a TPRM-focused graduate-level university course. How many CPE credits would this most likely generate?
- None, as academic courses do not qualify for CPE credit
- Credits only if the course leads to a degree completion
- Credits proportional to the course hours, such as one CPE per contact hour or credit hour (Correct answer)
- A flat rate of five credits regardless of course length
Correct answer: Credits proportional to the course hours, such as one CPE per contact hour or credit hour
Formal academic coursework in a relevant field typically generates CPE credits on a proportional basis, such as one CPE credit per contact or credit hour.
Question 25: What is a 'right to audit' clause in a vendor contract primarily intended to accomplish?
- Allow the vendor to audit the organization's financial statements
- Grant the organization the right to inspect the vendor's controls and compliance directly (Correct answer)
- Enable the organization to audit competitor pricing through the vendor
- Require the vendor to provide annual financial audits to regulators
Correct answer: Grant the organization the right to inspect the vendor's controls and compliance directly
A right to audit clause contractually allows the organization (or its representatives) to directly assess the vendor's processes, controls, and compliance with agreed standards.
Question 26: A risk team uses brainstorming sessions with diverse stakeholders to identify overlooked vendor risk scenarios. The primary benefit of stakeholder diversity in this context is:
- Cross-functional brainstorming always produces lower risk scores
- It distributes accountability for the final risk rating
- Different functional perspectives surface risk scenarios that siloed teams would not generate alone (Correct answer)
- It satisfies regulatory diversity requirements
Correct answer: Different functional perspectives surface risk scenarios that siloed teams would not generate alone
Diverse perspectives from legal, IT, operations, and finance reveal blind spots that any single team's frame of reference would miss.
Question 27: Which element is MOST critical when conducting vendor due diligence for a cloud service provider handling regulated data?
- The vendor's SOC 2 Type II report and data residency controls (Correct answer)
- The vendor's physical office locations
- The number of years the vendor has been in business
- The vendor's marketing materials and client testimonials
Correct answer: The vendor's SOC 2 Type II report and data residency controls
A SOC 2 Type II report provides evidence of operational effectiveness of security controls over time, while data residency controls confirm compliance with data sovereignty regulations.
Question 28: When regulators examine a financial institution's third-party risk management program, which deficiency is MOST likely to result in a Matters Requiring Attention (MRA)?
- Minor delays in vendor invoice processing
- Lack of a documented exit strategy for critical vendor relationships (Correct answer)
- Reviewing vendor contracts on a three-year rather than annual cycle
- Using standardized rather than customized vendor questionnaires
Correct answer: Lack of a documented exit strategy for critical vendor relationships
Regulators specifically look for documented exit strategies for critical vendors, as the absence of a transition plan represents a material gap that could leave the institution unable to maintain services if a vendor fails.
Question 29: When should an organization conduct an out-of-cycle evaluation of an existing vendor?
- When the vendor requests a re-evaluation to improve its score
- Only when the annual review schedule comes due
- Only if directed by an external auditor or regulator
- When a material change occurs, such as a vendor breach, merger, or service scope expansion (Correct answer)
Correct answer: When a material change occurs, such as a vendor breach, merger, or service scope expansion
Material changes to a vendor's risk profile — including incidents, ownership changes, or expanded access — trigger the need for an immediate reassessment.
Question 30: Which of the following is a key difference between CTPRP initial certification requirements and renewal requirements?
- Initial certification and renewal have identical requirements with no meaningful distinction
- Initial certification requires passing a proctored exam, while renewal is based on ongoing CPE and a renewal fee (Correct answer)
- Initial certification requires a fee, while renewal is always free
- Renewal requires retaking the exam every two years, while initial certification does not require an exam
Correct answer: Initial certification requires passing a proctored exam, while renewal is based on ongoing CPE and a renewal fee
The initial CTPRP credential requires passing a proctored exam to demonstrate baseline competency, while renewal is maintained through ongoing CPE and periodic fees rather than re-examination.
Question 31: A regulator requests documentation of how the organization communicates third-party risk to its board. Which document would best satisfy this request?
- Internal staff email threads about vendor issues
- Vendor contract amendments and SLA reports
- Raw vendor assessment questionnaire responses
- Board risk reporting templates showing risk metrics, escalation thresholds, and governance minutes (Correct answer)
Correct answer: Board risk reporting templates showing risk metrics, escalation thresholds, and governance minutes
Regulators expect evidence of structured board-level risk reporting including defined metrics, thresholds, and documented governance discussions.
Question 32: In TPRM history, what cultural shift occurred when organizations began treating vendor risk as a continuous lifecycle rather than a point-in-time assessment?
- The shift from annual audits to real-time monitoring (Correct answer)
- The introduction of cloud-first procurement policies
- The adoption of agile project management
- The move from transactional to relationship-based vendor governance
Correct answer: The shift from annual audits to real-time monitoring
The evolution from periodic snapshot assessments to continuous monitoring represented a foundational cultural shift, driven by high-profile breaches showing that risk profiles change rapidly between assessment cycles.
Question 33: Which scenario best demonstrates a CTPRP-aligned competency in practice?
- Designing a marketing campaign for a new product launch
- Performing forensic accounting on internal financial records
- Conducting a risk-tiered assessment of a critical cloud vendor (Correct answer)
- Negotiating employee salary benchmarks
Correct answer: Conducting a risk-tiered assessment of a critical cloud vendor
Risk-tiering and assessing critical vendors are core CTPRP competencies under the third-party risk lifecycle.
Question 34: What distinguishes a 'critical' vendor from a 'strategic' vendor in TPRM classification?
- Critical vendors are domestic; strategic vendors are international
- Strategic vendors have higher spend; critical vendors have lower contract value
- Critical vendors are essential to operations or compliance; strategic vendors align with long-term business goals (Correct answer)
- Critical vendors provide unique services; strategic vendors are interchangeable
Correct answer: Critical vendors are essential to operations or compliance; strategic vendors align with long-term business goals
Critical vendors are those whose failure would significantly disrupt operations or violate regulatory requirements, while strategic vendors are valued for long-term business alignment.
Question 35: What is the purpose of a vendor risk register?
- To document identified risks, their likelihood, impact, and treatment for each vendor (Correct answer)
- To list all vendors alphabetically for procurement records
- To track vendor invoice payment status
- To record vendor employee headcount over time
Correct answer: To document identified risks, their likelihood, impact, and treatment for each vendor
A vendor risk register is a structured record that captures the risks associated with each vendor, their risk ratings, and the actions taken to treat or monitor those risks.
Question 36: Which of the following BEST demonstrates mature evaluation documentation practices?
- Delegating documentation entirely to the vendor being evaluated
- Storing completed questionnaires in email inboxes organized by vendor
- Maintaining a centralized risk register with timestamped findings, evidence artifacts, and remediation tracking (Correct answer)
- Retaining only the final risk rating without supporting evidence
Correct answer: Maintaining a centralized risk register with timestamped findings, evidence artifacts, and remediation tracking
A centralized, timestamped risk register with evidence links supports audit defensibility, trend analysis, and regulatory examination readiness.
Question 37: Which encryption standard is currently considered the minimum acceptable for protecting sensitive data in transit when transmitted by a third party?
- TLS 1.2 or higher (Correct answer)
- DES with 56-bit keys
- SSL 3.0
- TLS 1.0
Correct answer: TLS 1.2 or higher
TLS 1.2 and TLS 1.3 are the current industry-accepted minimum standards; older protocols like SSL 3.0 and TLS 1.0/1.1 have known vulnerabilities and are deprecated.
Question 38: A vendor states its Recovery Time Objective (RTO) is 4 hours. What does this mean?
- The vendor will notify you of an outage within 4 hours
- The vendor promises to back up data every 4 hours
- The vendor's contract penalty period begins after 4 hours of downtime
- The vendor commits to restoring services within 4 hours of a declared disaster (Correct answer)
Correct answer: The vendor commits to restoring services within 4 hours of a declared disaster
RTO is the maximum acceptable time between a service disruption and the restoration of normal operations. A 4-hour RTO means the vendor commits to having services back up within 4 hours of invoking their disaster recovery plan. It differs from RPO (Recovery Point Objective), which addresses how much data loss is acceptable.
Question 39: Which committee or group within an organization typically has oversight responsibility for the enterprise third-party risk management program?
- Risk Committee or Third-Party Risk Oversight Committee (Correct answer)
- Marketing leadership team
- Individual business unit procurement staff only
- IT Help Desk team
Correct answer: Risk Committee or Third-Party Risk Oversight Committee
A dedicated Risk Committee or Third-Party Risk Oversight Committee provides executive-level governance, ensuring TPRM is aligned with enterprise risk appetite and regulatory expectations.
Question 40: Which of the following topics is most closely aligned with the CTPRP curriculum?
- Machine learning algorithm development
- Real estate appraisal methodology
- Equity derivatives trading strategies
- Third-party onboarding and due diligence lifecycle (Correct answer)
Correct answer: Third-party onboarding and due diligence lifecycle
Third-party onboarding and due diligence are core components of the CTPRP body of knowledge.
Question 41: What distinguishes the CTPRP from the CTPRA (Certified Third Party Risk Assessor) credential?
- CTPRP is entry-level; CTPRA is advanced
- CTPRP is for IT professionals only; CTPRA is for all industries
- CTPRP focuses on program management; CTPRA focuses on hands-on assessment execution (Correct answer)
- CTPRP requires a law degree; CTPRA does not
Correct answer: CTPRP focuses on program management; CTPRA focuses on hands-on assessment execution
CTPRP is oriented toward managing the overall third-party risk program, while CTPRA focuses on conducting individual assessments.
Question 42: What is calibration in the context of technical standards?
- Comparing measurements to a known standard to ensure accuracy (Correct answer)
- Balancing project budgets
- Training new employees on procedures
- Adjusting schedules to meet deadlines
Correct answer: Comparing measurements to a known standard to ensure accuracy
Calibration ensures measuring instruments provide accurate readings by comparing them against reference standards.
Question 43: What is the primary purpose of quality specifications in technical work?
- To increase project costs unnecessarily
- To define acceptable performance criteria and tolerances (Correct answer)
- To create employment for inspectors
- To slow down production timelines
Correct answer: To define acceptable performance criteria and tolerances
Quality specifications establish clear criteria for acceptable work, including performance requirements and allowable tolerances.
Question 44: A CTPRP holder leaves their employer and starts a consulting firm. Which action regarding the credential is most appropriate?
- The credential remains valid and may be used independently of employer affiliation (Correct answer)
- Continue displaying CTPRP only if the new firm does third-party risk work
- Surrender the credential until re-employed by a larger organization
- Re-apply for the credential under the new business entity
Correct answer: The credential remains valid and may be used independently of employer affiliation
The CTPRP credential belongs to the individual, not their employer, and remains valid as long as maintenance requirements are met.
Question 45: When evaluating a fourth-party (subcontractor of a vendor), the MOST appropriate first step is to:
- Conduct a direct on-site audit of the fourth party
- Review the vendor's own third-party risk program and subcontractor inventory (Correct answer)
- Require the fourth party to complete your standard due diligence questionnaire
- Exclude fourth parties unless they are explicitly named in the contract
Correct answer: Review the vendor's own third-party risk program and subcontractor inventory
Reviewing the vendor's own TPRM program and subcontractor inventory establishes concentration risk visibility before deciding if direct engagement is warranted.
Question 46: When a vendor experiences a data breach, which action should the contracting organization take FIRST according to best-practice vendor governance?
- Issue a public statement distancing from the vendor
- Transfer all vendor functions to an internal team
- Invoke contractual breach notification requirements and assess exposure (Correct answer)
- Immediately terminate the vendor contract
Correct answer: Invoke contractual breach notification requirements and assess exposure
The immediate priority is to invoke contractual breach notification provisions to understand the scope of exposure and coordinate the incident response according to established procedures.
Question 47: What is the primary risk management objective of requiring vendors to carry cyber liability insurance?
- To guarantee the vendor will never have a data breach
- To reduce the need for any contractual data protection clauses
- To transfer a portion of financial risk from a vendor-caused breach to the vendor's insurer (Correct answer)
- To satisfy ISO 27001 certification requirements
Correct answer: To transfer a portion of financial risk from a vendor-caused breach to the vendor's insurer
Requiring cyber liability insurance ensures that if a vendor causes a data breach, there is an insurance mechanism to cover associated financial losses, partially transferring that risk away from your organization.
Question 48: Which scenario represents the MOST significant vendor governance failure?
- A vendor accesses production systems beyond agreed scope without authorization (Correct answer)
- A vendor transitions account managers without advance notice
- A vendor submits an annual compliance certification two weeks late
- A vendor requests a contract amendment to adjust service pricing
Correct answer: A vendor accesses production systems beyond agreed scope without authorization
Unauthorized access to production systems beyond the agreed scope represents a critical security and compliance failure that could trigger regulatory violations and data breach liability.
Question 49: During a vendor evaluation, the assessor identifies a finding rated 'critical.' What is the APPROPRIATE immediate action?
- Downgrade the finding to avoid damaging the vendor relationship
- Escalate the finding immediately to internal risk owners and require the vendor to provide a remediation timeline (Correct answer)
- Publish the finding publicly to inform other organizations
- Wait until the full report is complete before notifying stakeholders
Correct answer: Escalate the finding immediately to internal risk owners and require the vendor to provide a remediation timeline
Critical findings require immediate escalation so that risk owners can make informed decisions about the vendor relationship while remediation is pursued.
Question 50: What is the primary purpose of an inherent risk assessment in the vendor evaluation lifecycle?
- To calculate the financial cost of a vendor failure event
- To determine the risk level before controls are applied, establishing a baseline for evaluation depth (Correct answer)
- To benchmark the vendor against industry peers
- To measure the effectiveness of the vendor's existing controls
Correct answer: To determine the risk level before controls are applied, establishing a baseline for evaluation depth
Inherent risk assessment captures the raw risk exposure before controls, which determines the appropriate depth and rigor of the subsequent control evaluation.
Question 51: Which NIST publication provides a catalog of security and privacy controls used to assess and authorize federal information systems including those operated by contractors?
- NIST SP 800-171
- NIST SP 800-53 (Correct answer)
- NIST SP 800-30
- NIST SP 800-37
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a comprehensive catalog of security and privacy controls applicable to federal systems and contractor environments under FedRAMP.
Question 52: What role does the CTPRP credential play in demonstrating compliance with regulatory expectations for third-party risk management programs?
- It grants FDIC insurance premium discounts for certified organizations
- It provides legal immunity from regulatory penalties related to vendor incidents
- It replaces all regulatory examination requirements for the certified firm
- It signals to regulators that staff managing vendor risk are credentialed professionals (Correct answer)
Correct answer: It signals to regulators that staff managing vendor risk are credentialed professionals
Regulators increasingly view certifications like CTPRP as evidence that organizations invest in qualified TPRM professionals.
Question 53: What is the primary purpose of inherent risk scoring during vendor due diligence?
- To assess the vendor's marketing capabilities
- To prioritize vendors by potential risk before controls are considered (Correct answer)
- To calculate the vendor's annual contract value
- To determine the vendor's credit rating
Correct answer: To prioritize vendors by potential risk before controls are considered
Inherent risk scoring evaluates the risk a third party poses based on the nature of the engagement, independent of any controls the vendor may have in place.
Question 54: An organization discovers a critical CVE affecting software used by a key vendor. What is the FIRST technical step in the TPRM response?
- Issue a contract amendment
- Notify regulators about the vendor's vulnerability
- Immediately suspend data sharing with the vendor
- Contact the vendor to determine if they are affected and their remediation timeline (Correct answer)
Correct answer: Contact the vendor to determine if they are affected and their remediation timeline
The first step is confirming whether and how the vendor is impacted, enabling an informed risk decision before taking operational or contractual action.
Question 55: A company's marketing team wants to list the CTPRP credential of one employee in an advertisement without naming the individual. Is this acceptable?
- No, credentials may never be used in commercial advertising
- Yes, it promotes the credential and benefits the profession
- Yes, as long as the employee has given written consent
- No, the credential must be attributed to the specific named individual (Correct answer)
Correct answer: No, the credential must be attributed to the specific named individual
Credentials are personal designations tied to named individuals; using them anonymously in marketing misrepresents their scope and attribution.
Question 56: Which of the following BEST describes 'concentration risk' in third-party risk management?
- Over-reliance on a limited number of vendors for critical functions, creating systemic vulnerability (Correct answer)
- The financial cost of maintaining multiple vendor contracts simultaneously
- The risk that a single vendor error causes a minor service disruption
- Regulatory penalties for using international vendors
Correct answer: Over-reliance on a limited number of vendors for critical functions, creating systemic vulnerability
Concentration risk refers to the systemic vulnerability created when an organization over-relies on a single or few vendors for critical functions, meaning one failure affects multiple operations.
Question 57: Under FFIEC guidance, what must banks document as part of ongoing third-party relationship management?
- The vendor's employee benefits packages
- The vendor's office lease agreements
- The vendor's quarterly advertising spend
- Performance reviews, risk reassessments, and any material changes to the vendor relationship (Correct answer)
Correct answer: Performance reviews, risk reassessments, and any material changes to the vendor relationship
FFIEC guidance requires banks to document ongoing vendor performance, periodic risk reassessments, and any changes that could affect the risk profile of the third-party relationship.
Question 58: In the cultural context of TPRM, what does 'vendor risk fatigue' describe?
- Risk teams becoming desensitized to low-severity vendor findings over time
- Vendors refusing to complete risk assessment questionnaires due to their volume and repetitiveness (Correct answer)
- Regulatory bodies reducing enforcement frequency
- Organizations abandoning TPRM programs due to cost
Correct answer: Vendors refusing to complete risk assessment questionnaires due to their volume and repetitiveness
Vendor risk fatigue describes the phenomenon where vendors become overwhelmed by the volume of similar but non-standardized questionnaires from multiple clients, leading to reduced quality and completeness of responses.
Question 59: Which type of CPE activity is most aligned with CTPRP renewal standards?
- An IT infrastructure bootcamp with no risk management component
- A workshop on SIG questionnaire updates and third-party assessment practices (Correct answer)
- A general project management certification course
- A leadership seminar focused on executive communications
Correct answer: A workshop on SIG questionnaire updates and third-party assessment practices
CPE activities directly related to third-party risk assessment tools and practices, such as SIG questionnaire updates, are most relevant to CTPRP renewal.
Question 60: What is the primary reason CTPRP holders must attest to the accuracy of their CPE records at renewal?
- To trigger an automatic full audit of all CPE activities claimed
- To satisfy a legal requirement mandated by the U.S. Securities and Exchange Commission
- To waive liability for any errors made by the certifying body during processing
- To affirm professional responsibility and ethical accountability for the accuracy of renewal submissions (Correct answer)
Correct answer: To affirm professional responsibility and ethical accountability for the accuracy of renewal submissions
The attestation requirement reinforces the ethical obligation of credential holders to accurately represent their continuing education activities.
Question 61: What is a significant outcome of hiring CPTRP-certified professionals?
- Improves office management workflows.
- Reduces third-party risks and enhances compliance. (Correct answer)
- Streamlines project timelines.
- Increases organizational profit margins.
Correct answer: Reduces third-party risks and enhances compliance.
CTPRP-certified professionals are specifically trained to identify, assess, and mitigate the diverse risks associated with third-party engagements. Their expertise ensures that organizations can proactively address potential vulnerabilities, comply with regulatory mandates, and protect their assets and reputation. This directly translates to a more secure and compliant operational environment.
Question 62: Which of the following BEST describes 'residual risk' in the context of third-party risk management?
- The risk transferred to the vendor via contract
- The total risk before any controls are applied
- The risk identified during the offboarding process
- The risk remaining after controls and mitigations have been implemented (Correct answer)
Correct answer: The risk remaining after controls and mitigations have been implemented
Residual risk is what remains after the organization has applied controls, contractual protections, and other mitigating measures.
Question 63: Which ethical obligation does a CTPRP professional have when advising a client whose third-party risk practices conflict with industry standards?
- Adopt the client's practices to preserve the business relationship
- Remain silent to avoid creating conflict
- Immediately report the client to regulatory authorities
- Advise the client of the risks and recommend alignment with best practices (Correct answer)
Correct answer: Advise the client of the risks and recommend alignment with best practices
CTPRP professionals are ethically obligated to provide honest, competent advice that serves the client's best interests including risk exposure.
Question 64: A TPRM analyst applies 'pre-mortem' thinking to a new critical vendor onboarding. This technique requires the analyst to:
- Imagine the engagement has already failed and work backward to identify what caused it (Correct answer)
- Review past vendor failures before approving any new vendor
- Ask the vendor to explain previous client losses
- Conduct a post-engagement review before contract execution
Correct answer: Imagine the engagement has already failed and work backward to identify what caused it
Pre-mortem thinking primes analysts to spot failure pathways by hypothetically treating future failure as already having occurred.
Question 65: During inherent risk tiering, which combination of factors most commonly elevates a vendor to 'Critical' tier?
- High data sensitivity, deep system integration, and no viable substitutes (Correct answer)
- Low data sensitivity and moderate access to internal systems
- Moderate revenue dependency and a long contract term
- Geographic distance and time-zone differences
Correct answer: High data sensitivity, deep system integration, and no viable substitutes
Critical tier designation typically results from the convergence of sensitive data exposure, deep technical integration, and concentration risk from lack of substitutes.
Question 66: How can CPTRP certification enhance a professional's career?
- Provides negotiation skills for contracts.
- Simplifies vendor marketing strategies.
- Improves financial budgeting for vendors.
- Enhances credibility and career opportunities. (Correct answer)
Correct answer: Enhances credibility and career opportunities.
Earning CTPRP certification validates a professional's expertise in a specialized and critical field. This recognized credential significantly boosts their credibility within the industry, demonstrating a commitment to best practices and a high level of skill. Consequently, it opens doors to advanced roles, promotions, and broader career opportunities in third-party risk management.
Question 67: What is the significance of PCI DSS compliance for a vendor handling payment card data?
- It indicates the vendor has no prior data breaches
- It confirms the vendor meets security standards required to store, process, or transmit cardholder data (Correct answer)
- It certifies the vendor as a preferred payment processor by Visa and Mastercard
- It exempts the vendor from SOC 2 audit requirements
Correct answer: It confirms the vendor meets security standards required to store, process, or transmit cardholder data
PCI DSS compliance demonstrates that the vendor has implemented the required controls to protect cardholder data, reducing the payment-related risk to organizations that share card data with them.
Question 68: What is the key risk of relying solely on vendor-completed security questionnaires (VSQs) without supplementary evidence?
- Responses are self-reported and may not accurately reflect actual control implementation (Correct answer)
- VSQs cannot be integrated into GRC platforms
- VSQs are too expensive for small vendors to complete
- VSQs violate data privacy regulations in most US states
Correct answer: Responses are self-reported and may not accurately reflect actual control implementation
VSQs rely on vendor self-attestation and may be aspirational or inaccurate; supplementary evidence such as audit reports, certifications, or on-site assessments is needed to validate claims.
Question 69: What is the main purpose of an exit strategy or exit plan for a critical vendor?
- To plan the vendor's retirement from the industry
- To prepare the vendor for an acquisition by your organization
- To document the vendor's succession of account managers
- To ensure business continuity if the vendor fails, exits the market, or the contract is terminated (Correct answer)
Correct answer: To ensure business continuity if the vendor fails, exits the market, or the contract is terminated
An exit strategy for a critical vendor details how the organization will transition services to maintain continuity if the vendor relationship ends abruptly or is terminated for cause.
Question 70: Which industry benefits most from CPTRP-certified professionals?
- Financial services (Correct answer)
- Automotive repair services
- Hospitality management
- Fashion and retail
Correct answer: Financial services
The financial services industry is heavily regulated and relies extensively on third-party vendors for various critical functions, from IT to data processing. This sector faces significant regulatory scrutiny and high stakes regarding data security and compliance, making robust third-party risk management, and thus CTPRP-certified professionals, exceptionally valuable.
Question 71: Which of the following best describes the ethical obligation of a CTPRP holder regarding the currency of their knowledge?
- Ethical obligations apply only to holders employed at financial institutions
- Holders have a professional duty to stay current with evolving third-party risk standards and practices (Correct answer)
- Ethics requirements are separate from and unrelated to CPE or renewal requirements
- Credential holders are only obligated to know the material covered on the original exam
Correct answer: Holders have a professional duty to stay current with evolving third-party risk standards and practices
The CTPRP code of professional conduct requires holders to proactively maintain current knowledge, which is reinforced by the CPE renewal structure.
Question 72: In the context of TPRM, 'inherent risk' is BEST defined as:
- The residual risk remaining after all controls are applied
- The risk exposure before any mitigating controls are considered (Correct answer)
- The financial cost of managing vendor relationships
- Regulatory penalties already assessed against a vendor
Correct answer: The risk exposure before any mitigating controls are considered
Inherent risk represents the level of risk that exists in a vendor relationship based on factors like data access, criticality, and geography before any controls or mitigations are applied.
Question 73: Which key area is evaluated in the CPTRP practical assessment?
- Implementing risk mitigation strategies (Correct answer)
- Developing marketing plans
- Designing financial models
- Drafting vendor contracts
Correct answer: Implementing risk mitigation strategies
The CTPRP practical assessment evaluates a candidate's ability to apply theoretical knowledge to real-world scenarios. A key aspect of third-party risk management is not just identifying risks, but also effectively putting in place plans and actions to reduce their impact or likelihood. Therefore, demonstrating the practical implementation of risk mitigation strategies is crucial for this assessment.
Question 74: What role does active listening play in a vendor risk assessment interview?
- It slows down the assessment process without adding value
- It allows the assessor to detect inconsistencies, clarify ambiguous answers, and uncover undisclosed risks (Correct answer)
- It is unnecessary since questionnaires capture all required information
- It shifts control of the interview to the vendor
Correct answer: It allows the assessor to detect inconsistencies, clarify ambiguous answers, and uncover undisclosed risks
Active listening during interviews enables assessors to probe deeper, identify inconsistencies, and surface risks not captured by standard questionnaires.
Question 75: In third-party risk management, what does 'inherent risk' represent?
- Risk transferred to the vendor via contract
- Risk before any controls or mitigations are considered (Correct answer)
- Risk remaining after controls are applied
- Risk identified during onboarding assessments
Correct answer: Risk before any controls or mitigations are considered
Inherent risk is the level of risk that exists in the absence of any controls, representing the raw exposure from engaging a third party.
Question 76: A vendor's SOC 2 Type II report covers a 6-month period ending 9 months ago. What is the primary concern for a risk evaluator?
- The coverage period is too short for meaningful assurance
- The report is stale and may not reflect current controls (Correct answer)
- The report uses Trust Service Criteria rather than COSO
- SOC 2 Type II reports are not acceptable for third-party risk
Correct answer: The report is stale and may not reflect current controls
A report that is 9 months old may not capture control changes made since the coverage period, creating a gap in assurance.
Question 77: A TPRM analyst is reviewing a vendor's patch management policy. What is the most critical metric to evaluate?
- Mean time to patch critical vulnerabilities (Correct answer)
- Number of software products the vendor sells
- Vendor's annual revenue growth
- Number of employees in the IT department
Correct answer: Mean time to patch critical vulnerabilities
Mean time to patch critical vulnerabilities directly measures the vendor's ability to reduce exposure windows after a CVE is published.
Question 78: What is the primary focus of the CPTRP certification exam?
- Risk mitigation strategies for vendors (Correct answer)
- Financial management of third parties
- Contract negotiation skills
- Team management techniques
Correct answer: Risk mitigation strategies for vendors
The CTPRP certification is designed to equip professionals with the knowledge and skills to manage risks introduced by third-party vendors. A central aspect of this is developing and implementing effective strategies to reduce, transfer, accept, or avoid these identified risks. This focus ensures that certified individuals can actively protect their organizations from potential harm stemming from vendor relationships.
Question 79: Which organization administers the CTPRP certification examination?
- ISACA
- IAPP
- Shared Assessments (Correct answer)
- RIMS
Correct answer: Shared Assessments
The CTPRP is administered by Shared Assessments, the leading organization focused on third-party risk management.
Question 80: Under GDPR, which role does a vendor typically hold when processing personal data on behalf of a US-based company serving EU residents?
- Data Custodian
- Data Controller
- Data Subject
- Data Processor (Correct answer)
Correct answer: Data Processor
Under GDPR, a vendor processing personal data solely under the instructions of a client organization is classified as a Data Processor, with specific obligations under Article 28.
Question 81: What is the primary purpose of a risk appetite statement in the context of TPRM?
- To define the maximum financial loss acceptable from vendor failures
- To outline contractual obligations vendors must meet
- To document regulatory requirements for third-party oversight
- To establish thresholds guiding which third-party risks are acceptable or require mitigation (Correct answer)
Correct answer: To establish thresholds guiding which third-party risks are acceptable or require mitigation
A risk appetite statement sets organizational boundaries for tolerable risk levels, guiding decisions on whether to accept, mitigate, transfer, or avoid third-party risks.
Question 82: What is a key requirement for third-party risk professionals under CPTRP certification?
- Software development expertise
- Risk assessment methodologies (Correct answer)
- Budget management skills
- Sales and negotiation techniques
Correct answer: Risk assessment methodologies
The CTPRP certification focuses on managing risks associated with third-party relationships. Therefore, a core competency for certified professionals is the ability to effectively identify, analyze, and evaluate these risks using established methodologies. This ensures a systematic approach to understanding potential threats and vulnerabilities introduced by third parties.
Question 83: A TPRM analyst is evaluating a SaaS vendor's data retention and deletion practices. Which contractual provision is MOST important to include?
- Vendor's commitment to annual price stability
- Guaranteed 99.9% uptime SLA
- Verifiable data deletion upon contract termination with certification of destruction (Correct answer)
- Priority support escalation path for production incidents
Correct answer: Verifiable data deletion upon contract termination with certification of destruction
Certified data deletion upon contract termination ensures the organization's data is not retained or misused after the vendor relationship ends.
Question 84: When interpreting ambiguous vendor audit findings, what approach best supports sound risk decisions?
- Accept all findings at face value without context
- Apply professional judgment combined with industry benchmarks and additional inquiry (Correct answer)
- Dismiss ambiguous findings as irrelevant to risk posture
- Escalate every ambiguous finding to senior leadership immediately
Correct answer: Apply professional judgment combined with industry benchmarks and additional inquiry
Professional judgment paired with industry benchmarks and targeted follow-up questions transforms ambiguous data into actionable risk intelligence.
Question 85: The historical development of TPRM in government contracting was significantly shaped by which legislation requiring federal agencies to manage contractor risk?
- The Government Accountability Act of 1996
- The Freedom of Information Act (FOIA)
- The Federal Acquisition Regulation (FAR) and its cybersecurity provisions (Correct answer)
- The Administrative Procedure Act (APA)
Correct answer: The Federal Acquisition Regulation (FAR) and its cybersecurity provisions
The Federal Acquisition Regulation established requirements for federal agencies to assess contractor capabilities and manage risks in government contracting relationships, providing an early formal TPRM framework for the public sector.
Question 86: What is the primary goal of vendor tiering in a TPRM program?
- To group vendors by industry sector for benchmarking purposes
- To prioritize oversight resources based on the level of risk each vendor poses (Correct answer)
- To classify vendors by geographic location for compliance mapping
- To rank vendors by annual spend for procurement negotiations
Correct answer: To prioritize oversight resources based on the level of risk each vendor poses
Vendor tiering allocates risk management resources proportionally, applying the most rigorous oversight to high-risk vendors and lighter-touch processes to low-risk ones.
Question 87: Which body provides the CTPRP certification and sets the professional standards for third-party risk professionals in the US?
- Shared Assessments (Correct answer)
- ISACA
- CompTIA
- ISC2
Correct answer: Shared Assessments
Shared Assessments is the organization that administers the CTPRP certification and develops the tools and standards used by third-party risk professionals globally.
Question 88: Which statement most accurately reflects the ethical obligations of a CTPRP holder when a conflict of interest arises in a vendor assessment?
- Proceed with the assessment and disclose the conflict afterward
- Keep the conflict confidential to avoid embarrassing the vendor
- Delegate the work without disclosing the conflict to management
- Disclose the conflict of interest and recuse from the assessment if necessary (Correct answer)
Correct answer: Disclose the conflict of interest and recuse from the assessment if necessary
CTPRP holders must proactively disclose conflicts of interest and recuse themselves from affected assessments to maintain integrity.
Question 89: What is the best characterization of the CTPRP's standing in the third-party risk management industry?
- A widely recognized benchmark credential for TPRM professionals (Correct answer)
- An entry-level certification for recent college graduates only
- A government-issued license required by federal law
- A rarely recognized credential with limited industry adoption
Correct answer: A widely recognized benchmark credential for TPRM professionals
The CTPRP is widely regarded as the benchmark professional credential in the third-party risk management field.
Question 90: What is the CTPRP credential's recertification cycle period?
- 1 year
- 2 years
- 5 years
- 3 years (Correct answer)
Correct answer: 3 years
The CTPRP credential requires recertification every three years, during which holders must accumulate the required continuing education hours.
Question 91: The Financial Stability Board (FSB) publication 'Regulatory and Supervisory Issues Relating to Outsourcing and Third-Party Relationships' (2023) emphasizes which emerging risk topic?
- Elimination of offshore outsourcing for regulated firms
- Concentration risk from reliance on a small number of critical third-party providers (Correct answer)
- Mandatory real-time data sharing between financial institutions
- Standardized global pricing for cloud services
Correct answer: Concentration risk from reliance on a small number of critical third-party providers
The 2023 FSB paper highlights systemic concentration risk as a key concern when many regulated firms rely on the same small set of critical service providers such as cloud hyperscalers.
Question 92: Which organization administers the CTPRP credential and oversees its renewal requirements?
- ISACA
- RIMS
- Shared Assessments (Correct answer)
- GARP
Correct answer: Shared Assessments
The Shared Assessments Program administers the CTPRP certification and sets its maintenance requirements.
Question 93: In the context of CTPRP credential maintenance, what counts as a 'reporting period' for CPE hours?
- A single 90-day quarter
- A two-year biennial period
- An annual calendar or certification year cycle (Correct answer)
- A 5-year rolling window
Correct answer: An annual calendar or certification year cycle
CTPRP CPE requirements are tracked on an annual basis aligned to the certification year.
Question 94: A fourth-party risk is BEST described as:
- Risk arising from a vendor's own subcontractors or suppliers (Correct answer)
- Risk from a vendor's direct employee misconduct
- Risk from regulatory changes affecting your industry
- Risk from the organization's internal IT team
Correct answer: Risk arising from a vendor's own subcontractors or suppliers
Fourth-party risk refers to the risk your organization inherits from vendors' vendors (subcontractors), which can be difficult to observe directly.
Question 95: Which method helps risk professionals reframe a third-party risk problem to uncover non-obvious solutions?
- Limiting analysis to historical precedent only
- Delegating interpretation entirely to the vendor
- Anchoring to the first risk score received
- Root cause analysis combined with 'what-if' scenario exploration (Correct answer)
Correct answer: Root cause analysis combined with 'what-if' scenario exploration
Root cause analysis paired with scenario exploration surfaces underlying drivers and alternative mitigation paths.
Question 96: Why is continuous monitoring crucial in third-party risk management?
- To reduce dependency on third parties.
- To streamline third-party onboarding processes.
- To comply with financial regulations only.
- To identify emerging risks promptly. (Correct answer)
Correct answer: To identify emerging risks promptly.
Third-party relationships are dynamic, and new risks can arise due to changes in the vendor's operations, market conditions, or regulatory landscape. Continuous monitoring allows organizations to detect these emerging risks in real-time, enabling proactive mitigation strategies. This ongoing vigilance is crucial for maintaining a strong and resilient third-party risk management program.
Question 97: Which of the following activities would NOT typically qualify as an acceptable CPE source for CTPRP renewal?
- Completing a vendor risk assessment at work
- Watching a personal finance documentary unrelated to risk (Correct answer)
- Reading a TPRM-focused industry whitepaper
- Attending a third-party risk management webinar
Correct answer: Watching a personal finance documentary unrelated to risk
CPE activities must be relevant to third-party risk management or a related professional domain to count toward renewal.
Question 98: Under the OCC's guidance on third-party risk, which phase requires the most rigorous documentation of risk assessments and due diligence?
- Ongoing monitoring and reporting
- Termination and exit planning
- Planning and due diligence before engagement (Correct answer)
- Contract negotiation and execution
Correct answer: Planning and due diligence before engagement
OCC guidance emphasizes that the planning phase—before entering a relationship—requires thorough due diligence and risk assessments documented to demonstrate sound decision-making.
Question 99: Which type of third-party relationship typically poses the GREATEST concentration risk?
- A vendor providing non-critical administrative services to one department
- A vendor shared with competitors in the same industry
- A vendor operating in a foreign jurisdiction with different regulations
- A single vendor supporting multiple critical business functions across the organization (Correct answer)
Correct answer: A single vendor supporting multiple critical business functions across the organization
Concentration risk is highest when a single vendor supports multiple critical functions, meaning vendor failure could simultaneously disrupt numerous key operations.
Question 100: Which document formally defines the responsibilities, expectations, and performance metrics agreed upon between an organization and its third party?
- Master Service Agreement (MSA)
- Non-Disclosure Agreement (NDA)
- Service Level Agreement (SLA) (Correct answer)
- Statement of Work (SOW)
Correct answer: Service Level Agreement (SLA)
An SLA specifically captures measurable performance targets and accountability provisions between the organization and the third party.
CTPRP (Certified Third-Party Risk Professional) Exam
The CTPRP exam is administered by the Shared Assessments Program and is designed for professionals involved in third-party risk management and vendor governance. The exam covers third-party risk assessment, due diligence, regulatory compliance, vendor governance, and professional standards. Candidates must demonstrate knowledge of industry frameworks including SIG, CAIQ, and ISO 27001. The exam consists of approximately 100 questions with a passing score of 70%.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds