Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Shared Assessments CTPRP Practice Exam with Questions & Answers | Set: 4

Questions 31

Which of the following statements is FALSE regarding a virtual assessment:

Options:
A.

Virtual assessment agendas and planning should identify who should be available for interviews

B.

Virtual assessment planning should identify what documentation is available for review prior to and during the assessment

C.

Virtual assessments should be used to validate or confirm understanding of key controls, and not be used simply to review questionnaire responses

D.

Virtual assessments include using interviews with subject matter experts since controls evaluation and testing cannot be performed virtually

Shared Assessments CTPRP Premium Access
Questions 32

Which action statement BEST describes an assessor calculating residual risk?

Options:
A.

The assessor adjusts the vendor risk rating prior to reporting the findings to the business unit

B.

The assessor adjusts the vendor risk rating based on changes to the risk level after analyzing the findings and mitigating controls

C.

The business unit closes out the finding prior to the assessor submitting the final report

D.

The assessor recommends implementing continuous monitoring for the next 18 months

Questions 33

Which statement is FALSE regarding the foundational requirements of a well-defined third party risk management program?

Options:
A.

We conduct onsite or virtual assessments for all third parties

B.

We have defined senior and executive management accountabilities for oversight of our TPRM program

C.

We have established vendor risk ratings and classifications based on a tiered hierarchy

D.

We have established Management and Board-level reporting to enable risk-based decisionmaking

Questions 34

Which statement is FALSE regarding problem or issue management?

Options:
A.

Problems or issues are the root cause of an actual or potential incident

B.

Problem or issue management involves managing workarounds or known errors

C.

Problems or issues typically lead to systemic failures

D.

Problem or issue management may reduce the likelihood and impact of incidents

Questions 35

When evaluating remote access risk, which of the following is LEAST applicable to your analysis?

Options:
A.

Logging of remote access authentication attempts

B.

Limiting access by job role of business justification

C.

Monitoring device activity usage volumes

D.

Requiring application whitelisting

Questions 36

An IT change management approval process includes all of the following components EXCEPT:

Options:
A.

Application version control standards for software release updates

B.

Documented audit trail for all emergency changes

C.

Defined roles between business and IT functions

D.

Guidelines that restrict approval of changes to only authorized personnel

Questions 37

Which of the following factors is MOST important when assessing the risk of shadow IT in organizational security?

Options:
A.

The organization maintains adequate policies and procedures that communicate required controls for security functions

B.

The organization requires security training and certification for security personnel

C.

The organization defines staffing levels to address impact of any turnover in security roles

D.

The organization's resources and investment are sufficient to meet security requirements

Exam Code: CTPRP
Certification Provider: Shared Assessments
Exam Name: Certified Third-Party Risk Professional (CTPRP)
Last Update: Jul 12, 2025
Questions: 125

Shared Assessments Free Exams

Shared Assessments Free Exams
Examstrack offers free Shared Assessments exam materials and practice tests to aid your Shared Assessments certification journey.