Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Shared Assessments CTPRP Practice Exam with Questions & Answers | Set: 3

Questions 21

Which of the following BEST describes the distinction between a regulation and a standard?

Options:
A.

A regulation must be adhered to by all companies subject to its requirements, but companies “can voluntarily choose to follow standards.

B.

There is no distinction, regulations and standards are the same and have equal impact

C.

Standards are always a subset of a regulation

D.

A standard must be adhered to by companies based on the industry they are in, while regulations are voluntary.

Shared Assessments CTPRP Premium Access
Questions 22

Information classification of personal information may trigger specific regulatory obligations. Which statement is the BEST response from a privacy perspective:

Options:
A.

Personally identifiable financial information includes only consumer report information

B.

Public personal information includes only web or online identifiers

C.

Personally identifiable information and personal data are similar in context, but may have different legal definitions based upon jurisdiction

D.

Personally Identifiable Information and Protected Healthcare Information require the exact same data protection safequards

Questions 23

Which statement is TRUE regarding defining vendor classification or risk tiering in a TPRM program?

Options:
A.

Vendor classification and risk tiers are based upon residual risk calculations

B.

Vendor classification and risk tiering should only be used for critical third party relationships

C.

Vendor classification and corresponding risk tiers utilize the same due diligence standards for controls evaluation based upon policy

D.

Vendor classification and risk tier is determined by calculating the inherent risk associated with outsourcing a specific product or service

Questions 24

Which statement is FALSE regarding the different types of contracts and agreements between outsourcers and service providers?

Options:
A.

Contract addendums are not sufficient for addressing third party risk obligations as each requirement must be outlined in the Master Services Agreement (MSA)

B.

Evergreen contracts are automatically renewed for each party after the maturity period, unless terminated under existing contract provisions

C.

Requests for Proposals (RFPs) for outsourced services should include mandatory requirements based on an organization's TPRM program policies, standards and procedures

D.

Statements of Work (SOWs) define operational requirements and obligations for each party

Questions 25

Which statement is TRUE regarding the tools used in TPRM risk analyses?

Options:
A.

Risk treatment plans define the due diligence standards for third party assessments

B.

Risk ratings summarize the findings in vendor remediation plans

C.

Vendor inventories provide an up-to-date record of high risk relationships across an organization

D.

Risk registers are used for logging and tracking third party risks

Questions 26

Which statement is TRUE regarding the use of questionnaires in third party risk assessments?

Options:
A.

The total number of questions included in the questionnaire assigns the risk tier

B.

Questionnaires are optional since reliance on contract terms is a sufficient control

C.

Assessment questionnaires should be configured based on the risk rating and type of service being evaluated

D.

All topic areas included in the questionnaire require validation during the assessment

Questions 27

When updating TPRM vendor classification requirements with a focus on availability, which

risk rating factors provide the greatest impact to the analysis?

Options:
A.

Type of data by classification; volume of records included in data processing

B.

Financial viability of the vendor; ability to meet performance metrics

C.

Network connectivity; remote access to applications

D.

impact on operations and end users; impact on revenue; impact on regulatory compliance

Questions 28

Which cloud deployment model is focused on the management of hardware equipment?

Options:
A.

Function as a service

B.

Platform as a service

C.

Software as a service

D.

Infrastructure as a service

Questions 29

Which statement is FALSE regarding the primary factors in determining vendor risk classification?

Options:
A.

The geographic area where the vendor is located may trigger specific regulatory obligations

B.

The importance to the outsourcer's recovery objectives may trigger a higher risk tier

C.

The type and volume of personal data processed may trigger a higher risk rating based on the criticality of the systems

D.

Network connectivity or remote access may trigger a higher vendor risk classification only for third parties that process personal information

Questions 30

If a system requires ALL of the following for accessing its data: (1) a password, (2) a

security token, and (3) a user's fingerprint, the system employs:

Options:
A.

Biometric authentication

B.

Challenge/Response authentication

C.

One-Time Password (OTP) authentication

D.

Multi-factor authentication

Exam Code: CTPRP
Certification Provider: Shared Assessments
Exam Name: Certified Third-Party Risk Professional (CTPRP)
Last Update: Jul 17, 2025
Questions: 125

Shared Assessments Free Exams

Shared Assessments Free Exams
Examstrack offers free Shared Assessments exam materials and practice tests to aid your Shared Assessments certification journey.