Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Shared Assessments CTPRP Practice Exam with Questions & Answers

Questions 1

The set of shared values and beliefs that govern a company’s attitude toward risk is known as:

Options:
A.

Risk tolerance

B.

Risk treatment

C.

Risk culture

D.

Risk appetite

Shared Assessments CTPRP Premium Access
Questions 2

Which statement provides the BEST description of inherent risk?

Options:
A.

inherent risk is the amount of risk an organization can incur when there is an absence of controls

B.

Inherent risk is the level of risk triggered by outsourcing & product or service

C.

Inherent risk is the amount of risk an organization can accept based on their risk tolerance

D.

Inherent risk is the level of risk that exists with all of the necessary controls in place

Questions 3

Which example of a response to external environmental factors is LEAST likely to be managed directly within the BCP or IT DR plan?

Options:
A.

Protocols for social media channels and PR communication

B.

Response to a natural or man-made disruption

C.

Dependency on key employee or supplier issues

D.

Response to a large scale illness or health outbreak

Questions 4

Which of the following statements is FALSE about Data Loss Prevention Programs?

Options:
A.

DLP programs include the policy, tool configuration requirements, and processes for the identification, blocking or monitoring of data

B.

DLP programs define the consequences for non-compliance to policies

C.

DLP programs define the required policies based on default tool configuration

D.

DLP programs include acknowledgement the company can apply controls to remove any data

Questions 5

Which activity BEST describes conducting due diligence of a lower risk vendor?

Options:
A.

Accepting a service providers self-assessment questionnaire responses

B.

Preparing reports to management regarding the status of third party risk management and remediation activities

C.

Reviewing a service provider's self-assessment questionnaire and external audit report(s)

D.

Requesting and filing a service provider's external audit report(s) for future reference

Questions 6

Which capability is LEAST likely to be included in the annual testing activities for Business Continuity or Disaster Recovery plans?

Options:
A.

Plans to enable technology and business operations to be resumed at a back-up site

B.

Process to validate that specific databases can be accessed by applications at the designated location

C.

Ability for business personnel to perform their functions at an alternate work space location

D.

Require participation by third party service providers in collaboration with industry exercises

Questions 7

A visual representation of locations, users, systems and transfer of personal information between outsourcers and third parties is defined as:

Options:
A.

Configuration standard

B.

Audit log report

C.

Network diagram

D.

Data flow diagram

Questions 8

Your company has been alerted that an IT vendor began utilizing a subcontractor located in a country restricted by company policy. What is the BEST approach to handle this situation?

Options:
A.

Notify management to approve an exception and ensure that contract provisions require prior “notification and evidence of subcontractor due diligence

B.

inform the business unit and recommend that the company cease future work with the IT vendor due to company policy

C.

Update the vender inventory with the mew location information in order to schedule a reassessment

D.

Inform the business unit and ask the vendor to replace the subcontractor at their expense in “order to move the processing back to an approved country

Questions 9

Which of the following components are typically NOT part of a cloud hosting vendor assessment program?

Options:
A.

Reviewing the entity's image snapshot approval and management process

B.

Requiring security services documentation and audit attestation reports

C.

Requiring compliance evidence that provides the definition of patching responsibilities

D.

Conducting customer performed penetration tests

Questions 10

A set of principles for software development that address the top application security risks and industry web requirements is known as:

Options:
A.

Application security design standards

B.

Security testing methodology

C.

Secure code reviews

D.

Secure architecture risk analysis

Exam Code: CTPRP
Certification Provider: Shared Assessments
Exam Name: Certified Third-Party Risk Professional (CTPRP)
Last Update: Jul 15, 2025
Questions: 125

Shared Assessments Free Exams

Shared Assessments Free Exams
Examstrack offers free Shared Assessments exam materials and practice tests to aid your Shared Assessments certification journey.