ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 500 - CAS-004 discussion

Report
Export

The primary advantage of an organization creating and maintaining a vendor risk registry is to:

A.
define the risk assessment methodology.
Answers
A.
define the risk assessment methodology.
B.
study a variety of risks and review the threat landscape.
Answers
B.
study a variety of risks and review the threat landscape.
C.
ensure that inventory of potential risk is maintained.
Answers
C.
ensure that inventory of potential risk is maintained.
D.
ensure that all assets have low residual risk.
Answers
D.
ensure that all assets have low residual risk.
Suggested answer: C

Explanation:

The primary advantage of creating and maintaining a vendor risk registry is to ensure that an inventory of potential risks is maintained. A vendor risk registry helps organizations keep track of the risks associated with third-party vendors, especially as they may introduce vulnerabilities or non-compliance issues. By maintaining this registry, the organization can continuously monitor and manage vendor-related risks in a structured way, improving its overall security posture. CASP+ emphasizes the importance of vendor risk management in an organization's broader risk management strategy.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (Vendor Risk Management)

CompTIA CASP+ Study Guide: Third-Party Risk Management and Risk Registries

asked 02/10/2024
RALPH KOH
28 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first