CTPRP Technical Skills Development 3 — Questions and Answers
Question 1: A vendor's penetration test report is 18 months old. What is the most appropriate TPRM action?
- Accept the report since it was conducted by a reputable firm
- Request an updated penetration test or risk-accept with compensating controls (Correct answer)
- Terminate the vendor relationship immediately
- Escalate to the board without further analysis
Correct answer: Request an updated penetration test or risk-accept with compensating controls
Penetration test results older than 12 months may not reflect current vulnerabilities; requesting updated testing or formally risk-accepting with compensating controls is the appropriate response.
Question 2: Which tool category is most useful for continuous monitoring of a third party's external attack surface?
- GRC platform workflow automation
- Cyber ratings and external threat intelligence tools (Correct answer)
- Contract lifecycle management software
- Vendor invoice reconciliation tools
Correct answer: Cyber ratings and external threat intelligence tools
Cyber ratings platforms (e.g., BitSight, SecurityScorecard) continuously scan external-facing vendor assets to provide real-time risk signals.
Question 3: What does 'data minimization' mean in the context of evaluating a vendor's data handling practices?
- Reducing the number of data centers the vendor operates
- Collecting and retaining only the data necessary for the specified purpose (Correct answer)
- Minimizing the size of files transferred to the vendor
- Limiting the vendor's number of data processing employees
Correct answer: Collecting and retaining only the data necessary for the specified purpose
Data minimization is a core privacy principle requiring organizations to limit data collection and retention to what is strictly necessary for the defined purpose.
Question 4: An organization discovers a critical CVE affecting software used by a key vendor. What is the FIRST technical step in the TPRM response?
- Issue a contract amendment
- Contact the vendor to determine if they are affected and their remediation timeline (Correct answer)
- Immediately suspend data sharing with the vendor
- Notify regulators about the vendor's vulnerability
Correct answer: Contact the vendor to determine if they are affected and their remediation timeline
The first step is confirming whether and how the vendor is impacted, enabling an informed risk decision before taking operational or contractual action.
Question 5: Which encryption standard is currently considered the minimum acceptable for protecting sensitive data in transit when transmitted by a third party?
- SSL 3.0
- TLS 1.0
- TLS 1.2 or higher (Correct answer)
- DES with 56-bit keys
Correct answer: TLS 1.2 or higher
TLS 1.2 and TLS 1.3 are the current industry-accepted minimum standards; older protocols like SSL 3.0 and TLS 1.0/1.1 have known vulnerabilities and are deprecated.
Question 6: In a TPRM context, what is the significance of a vendor's RTO (Recovery Time Objective)?
- It measures how quickly the vendor can onboard new clients
- It defines the maximum acceptable downtime after a disruption before business impact becomes critical (Correct answer)
- It tracks how rapidly the vendor responds to security questionnaires
- It quantifies the vendor's annual revenue recovery rate
Correct answer: It defines the maximum acceptable downtime after a disruption before business impact becomes critical
RTO specifies the target time within which a vendor must restore services after an incident, directly affecting the organization's own operational continuity.
Question 7: A fourth-party risk is BEST described as:
- Risk from a vendor's direct employee misconduct
- Risk arising from a vendor's own subcontractors or suppliers (Correct answer)
- Risk from the organization's internal IT team
- Risk from regulatory changes affecting your industry
Correct answer: Risk arising from a vendor's own subcontractors or suppliers
Fourth-party risk refers to the risk your organization inherits from vendors' vendors (subcontractors), which can be difficult to observe directly.
A vendor's penetration test report is 18 months old.
What is the most appropriate TPRM action?