Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Shared Assessments CTPRP Practice Exam with Questions & Answers | Set: 2

Questions 11

Which TPRM risk assessment component would typically NOT be maintained in a Risk Register?

Options:
A.

An assessment of the impact and likelihood the risk will occur and the possible seriousness

B.

Vendor inventory of all suppliers, vendors, and service providers prioritized by contract value

C.

An outline of proposed mitigation actions and assignment of risk owner

D.

A grading of each risk according to a risk assessment table or hierarchy

Shared Assessments CTPRP Premium Access
Questions 12

An IT asset management program should include all of the following components EXCEPT:

Options:
A.

Maintaining inventories of systems, connections, and software applications

B.

Defining application security standards for internally developed applications

C.

Tracking and monitoring availability of vendor updates and any timelines for end of support

D.

Identifying and tracking adherence to IT asset end-of-life policy

Questions 13

Which of the following BEST reflects the risk of a ‘shadow IT" function?

Options:
A.

“Shadow IT" functions often fail to detect unauthorized use of information assets

B.

“Shadow IT" functions often lack governance and security oversight

C.

inability to prevent "shadow IT’ functions from using unauthorized software solutions

D.

Failure to implement strong security controls because IT is executed remotely

Questions 14

Which statement is NOT an example of the purpose of internal communications and information sharing using TPRM performance metrics?

Options:
A.

To communicate the status of findings identified in vendor assessments and escalate issues es needed

B.

To communicate the status of policy compliance with TPRM onboarding, periodic assessment and off-boarding requirements

C.

To document the agreed upon corrective action plan between external parties based on the severity of findings

D.

To develop and provide periodic reporting to management based on TPRM results

Questions 15

Which statement is FALSE regarding the methods of measuring third party risk?

Options:
A.

Risk can be measured both qualitatively and quantitatively

B.

Risk can be quantified by calculating the severity of impact and likelihood of occurrence

C.

Assessing risk impact requires an analysis of prior events, frequency of occurrence, and external trends to analyze and predict the potential of a particular event happening

D.

Risk likelihood or probability is a critical element in quantifying inherent or residual risk

Questions 16

Which cloud deployment model is primarily used for load balancing?

Options:
A.

Public Cloud

B.

Community Cloud

C.

Hybrid Cloud

D.

Private Cloud

Questions 17

Which of the following is NOT a key component of TPRM requirements in the software development life cycle (SDLC)?

Options:
A.

Maintenance of artifacts that provide proof that SOLC gates are executed

B.

Process for data destruction and disposal

C.

Software security testing

D.

Process for fixing security defects

Questions 18

Which of the following is typically NOT included within the scape of an organization's network access policy?

Options:
A.

Firewall settings

B.

Unauthorized device detection

C.

Website privacy consent banners

D.

Remote access

Questions 19

For services with system-to-system access, which change management requirement

MOST effectively reduces the risk of business disruption to the outsourcer?

Options:
A.

Approval of the change by the information security department

B.

Documenting sufficient time for quality assurance testing

C.

Communicating the change to customers prior ta deployment to enable external acceptance testing

D.

Documenting and legging change approvals

Questions 20

Select the risk type that is defined as: “A third party may not be able to meet its obligations due to inadequate systems or processes”.

Options:
A.

Reliability risk

B.

Performance risk

C.

Competency risk

D.

Availability risk

Exam Code: CTPRP
Certification Provider: Shared Assessments
Exam Name: Certified Third-Party Risk Professional (CTPRP)
Last Update: Jul 15, 2025
Questions: 125

Shared Assessments Free Exams

Shared Assessments Free Exams
Examstrack offers free Shared Assessments exam materials and practice tests to aid your Shared Assessments certification journey.