CTPRP Technical Skills Development 2 — Questions and Answers
Question 1: Which framework is most commonly used to assess the cybersecurity posture of third-party vendors in the US financial sector?
- COBIT 5
- NIST Cybersecurity Framework (Correct answer)
- ISO 9001
- PMBOK
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework is widely adopted in the US financial sector to evaluate and communicate cybersecurity risk with third-party vendors.
Question 2: A vendor stores client data on servers located in a country with weak data privacy laws. What technical control best mitigates this risk?
- Contractual data residency clauses only
- End-to-end encryption with client-managed keys (Correct answer)
- Periodic on-site audits
- Requiring the vendor to purchase cyber insurance
Correct answer: End-to-end encryption with client-managed keys
End-to-end encryption with client-managed keys ensures data remains protected even if the host country's legal environment allows government access.
Question 3: In third-party risk management, what does a SOC 2 Type II report primarily assess?
- Financial statement accuracy over a point in time
- Operational effectiveness of controls over a defined period (Correct answer)
- Vendor employee background check processes
- Network penetration test results
Correct answer: Operational effectiveness of controls over a defined period
A SOC 2 Type II report evaluates whether a service organization's controls related to security, availability, and confidentiality operated effectively over a review period.
Question 4: What is the primary purpose of a vendor's System and Organization Controls (SOC) report in TPRM due diligence?
- To replace the need for a vendor questionnaire
- To provide independent assurance on internal controls (Correct answer)
- To verify vendor financial solvency
- To confirm vendor compliance with GDPR
Correct answer: To provide independent assurance on internal controls
SOC reports provide third-party auditor assurance on the design and operating effectiveness of a vendor's internal controls.
Question 5: Which technical skill is essential when reviewing a vendor's API security to prevent unauthorized data access?
- Evaluating OAuth 2.0 and token-based authentication implementations (Correct answer)
- Reviewing vendor employee training completion rates
- Assessing the vendor's disaster recovery plan narrative
- Analyzing vendor financial statements for liquidity
Correct answer: Evaluating OAuth 2.0 and token-based authentication implementations
OAuth 2.0 and proper token management are foundational API security controls that prevent unauthorized access to data shared between systems.
Question 6: A TPRM analyst is reviewing a vendor's patch management policy. What is the most critical metric to evaluate?
- Number of employees in the IT department
- Mean time to patch critical vulnerabilities (Correct answer)
- Vendor's annual revenue growth
- Number of software products the vendor sells
Correct answer: Mean time to patch critical vulnerabilities
Mean time to patch critical vulnerabilities directly measures the vendor's ability to reduce exposure windows after a CVE is published.
Question 7: When assessing a cloud service provider's data segregation practices, which technical control confirms that one client's data cannot be accessed by another?
- Shared credential vaulting
- Multi-tenant logical isolation with virtual private clouds (Correct answer)
- Single sign-on (SSO) integration
- Unified audit log retention
Correct answer: Multi-tenant logical isolation with virtual private clouds
Logical isolation using virtual private clouds or similar segmentation ensures tenant data is separated and inaccessible across the shared infrastructure.
Which framework is most commonly used to assess the cybersecurity posture of third-party vendors in the US financial sector?