CTPRP Evaluation Details 3 — Questions and Answers
Question 1: A financial institution is evaluating a SaaS vendor that processes payment card data. Which framework should guide the evaluation's control requirements?
- ISO 9001
- PCI DSS (Correct answer)
- NIST SP 800-171
- COBIT 2019
Correct answer: PCI DSS
PCI DSS establishes specific security requirements for entities that process, store, or transmit payment card data.
Question 2: When performing a financial health evaluation of a critical vendor, which indicator is MOST concerning for long-term viability?
- Revenue grew 5% year-over-year
- The vendor carries more debt than equity and has negative cash flow from operations (Correct answer)
- The vendor recently completed a Series B funding round
- The vendor's gross margin declined by 2% compared to prior year
Correct answer: The vendor carries more debt than equity and has negative cash flow from operations
Negative operating cash flow combined with high leverage signals potential insolvency risk that could disrupt service continuity.
Question 3: Which of the following BEST describes the purpose of a right-to-audit clause in a third-party contract?
- It allows the vendor to audit the client's security controls
- It grants the organization the contractual right to inspect the vendor's facilities and records (Correct answer)
- It replaces the need for the vendor to obtain third-party certifications
- It limits the scope of regulatory examinations to contracted services only
Correct answer: It grants the organization the contractual right to inspect the vendor's facilities and records
A right-to-audit clause gives the organization contractual authority to verify vendor controls through direct inspection when needed.
Question 4: During evaluation, a vendor reports its RTO for critical systems is 4 hours but cannot produce a recent business continuity test report. What should the evaluator conclude?
- The RTO claim is valid because it is in writing
- The RTO is unverified and the evaluator should treat it as a gap (Correct answer)
- The vendor should be immediately terminated
- RTOs only apply to data recovery, not system availability
Correct answer: The RTO is unverified and the evaluator should treat it as a gap
An untested RTO is an aspirational target, not validated capability; the evaluator must treat this as a gap requiring remediation evidence.
Question 5: A vendor provides a penetration test report conducted by its internal security team. Why might an evaluator give this less weight than an external pen test?
- Internal teams lack the technical skills to perform penetration testing
- Internal testers may have conflicts of interest that limit objectivity and scope (Correct answer)
- Internal pen tests are prohibited under most regulatory frameworks
- Penetration testing is only valid when performed by government-certified testers
Correct answer: Internal testers may have conflicts of interest that limit objectivity and scope
Internal testers may unconsciously limit scope or soften findings to protect internal relationships, reducing the independence and credibility of the assessment.
Question 6: Which scenario represents a concentration risk finding in a third-party evaluation program?
- A vendor has offices in three different time zones
- Sixty percent of critical business processes rely on a single cloud provider (Correct answer)
- A vendor offers both SaaS and on-premise deployment options
- The organization uses a different vendor for each business unit
Correct answer: Sixty percent of critical business processes rely on a single cloud provider
Over-reliance on a single provider for the majority of critical processes creates systemic exposure if that provider experiences a disruption.
Question 7: When should an organization conduct an out-of-cycle evaluation of an existing vendor?
- Only when the annual review schedule comes due
- When a material change occurs, such as a vendor breach, merger, or service scope expansion (Correct answer)
- When the vendor requests a re-evaluation to improve its score
- Only if directed by an external auditor or regulator
Correct answer: When a material change occurs, such as a vendor breach, merger, or service scope expansion
Material changes to a vendor's risk profile — including incidents, ownership changes, or expanded access — trigger the need for an immediate reassessment.
A financial institution is evaluating a SaaS vendor that processes payment card data.
Which framework should guide the evaluation's control requirements?