ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 479 - CAS-004 discussion

Report
Export

Which of the following describes how a risk assessment is performed when an organization has a critical vendor that provides multiple products?

A.
At the individual product level
Answers
A.
At the individual product level
B.
Through the selection of a random product
Answers
B.
Through the selection of a random product
C.
Using a third-party audit report
Answers
C.
Using a third-party audit report
D.
By choosing a major product
Answers
D.
By choosing a major product
Suggested answer: A

Explanation:

When conducting a risk assessment for a vendor that provides multiple products, it is important to perform the assessment at the individual product level. Each product might have different risk factors, security requirements, and vulnerabilities, so assessing each one ensures a comprehensive understanding of the risks involved. Assessing randomly or only major products could leave gaps in understanding the risks for smaller but still critical products. CASP+ emphasizes that risk assessments should be detailed and product-specific for a thorough evaluation.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (Vendor and Product Risk Assessments)

CompTIA CASP+ Study Guide: Vendor Risk Management

asked 02/10/2024
John Shelby
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first