Practice vendor risk management vocabulary: security questionnaires, SOC 2 certification, ISO 27001, annual assessments, and risk tiering.
0 / 45 completed
1 / 45
Your procurement process requires 'the vendor to complete a 150-question security questionnaire.' What is the purpose of this questionnaire?
A vendor security questionnaire (VSQ) is a due diligence tool — it asks detailed questions about the vendor's security program: access controls, encryption, incident response, data handling, and certifications. The answers help assess whether the vendor meets your security standards before engagement.
2 / 45
A vendor says 'We are SOC 2 Type II certified.' What does SOC 2 Type II mean?
SOC 2 Type II is a rigorous third-party audit (by a licensed CPA firm) that evaluates a vendor's security, availability, processing integrity, confidentiality, and privacy controls over a defined period (typically 6-12 months). Type II proves controls work consistently — not just at a point in time.
3 / 45
A vendor assessment notes 'The vendor holds ISO 27001.' What does this certification demonstrate?
ISO 27001 certifies that a vendor has implemented a documented, systematic approach to managing information security risks (an ISMS). It covers risk assessment, security policies, physical and technical controls, and continuous improvement — providing assurance about the vendor's overall security posture.
4 / 45
Your vendor management policy says 'The vendor assessment is annual.' Why is annual reassessment important?
Vendor risk is dynamic — a vendor that was secure 18 months ago may have experienced a breach, changed their security team, or added new subprocessors. Annual reassessment ensures your organization maintains current risk awareness and can respond to changes in vendor posture.
5 / 45
Your vendor risk register 'rates vendors as critical/high/medium/low.' What factors typically determine a vendor's risk tier?
Vendor risk tiering considers: what data is shared (PII, financial data = higher risk), how deeply integrated the vendor is (single sign-on, production access = higher risk), what happens if the vendor fails (critical path vs. nice-to-have), and the vendor's demonstrated security posture.
6 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
7 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
8 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
9 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
10 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
11 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
12 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
13 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
14 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
15 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
16 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
17 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
18 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
19 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
20 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
21 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
22 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
23 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
24 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
25 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
26 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
27 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
28 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
29 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
30 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
31 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
32 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
33 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
34 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
35 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
36 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
37 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
38 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
39 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
40 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
41 / 45
// PR Description:
"Fix: Updated API endpoint to integrate with new payment processor, 'NovaPay'. NovaPay's SLA guarantees 99.99% uptime and includes data encryption at rest and in transit. We've conducted a preliminary risk assessment based on their SOC 2 Type II certification."
This question tests understanding of how vendor risk is communicated and assessed within a development workflow. The correct answer acknowledges that the SOC 2 Type II certification provides a foundational level of assurance, which is what the PR is referencing. Options A and B represent an overemphasis on technical details not immediately conveyed in the PR; option D suggests unnecessary escalation. It's crucial to understand certifications like SOC 2 as starting points for ongoing risk management.
42 / 45
// Slack message from a developer to their team lead:
`@teamlead Can you review this PR? We're integrating with 'DataStream Analytics' – they've provided a detailed risk assessment document outlining potential vulnerabilities related to data access controls and incident response. It mentions 'Business Associate Agreement' (BAA) requirements, and we need to ensure our compliance team has reviewed it before merging."
This question assesses understanding of the purpose of a vendor risk assessment document. A BAA (Business Associate Agreement) is a legally binding contract that outlines responsibilities regarding sensitive data – especially PII – when a third party handles it. The risk assessment goes far beyond just downtime; it examines vulnerabilities and compliance processes, which are crucial for mitigating risks associated with the integration. Incorrect options often conflate the purpose of a BAA with broader security assessments or focus solely on operational aspects.
43 / 45
PR Description:
"Update: Implemented integration with 'SecureCloud Storage'. Their documentation references 'Data Processing Addendum' (DPA) clauses related to GDPR compliance and specifies that all data transfers must utilize TLS 1.3 encryption. A preliminary risk assessment identified potential concerns regarding access logging practices."
This question tests understanding of a key component in vendor risk: compliance with data protection laws. The DPA (Data Processing Addendum) is a legally binding agreement that details the responsibilities of the processor (SecureCloud Storage) regarding personal data and ensures adherence to regulations like GDPR. Choosing this option correctly identifies the critical focus of the risk assessment – legal obligations related to data processing, not just technical vulnerabilities. Options A, C, and D misinterpret the document's content or represent unrelated security activities.
44 / 45
PR Description:
"Integration with 'CloudSync' complete. The vendor's documentation highlights their adherence to the NIST Cybersecurity Framework and includes a 'Statement of Applicability' (SoA) outlining specific controls implemented for data security. We have noted potential gaps regarding multi-factor authentication across all services, which we will address in a subsequent phase."
This question tests understanding of specialized vendor risk terminology. The 'Statement of Applicability' (SoA) is a critical document demonstrating how a vendor's security controls align with a recognized framework like NIST. Options A and C misinterpret the SoA; it's not about speed or outdated practices, but about tailored control implementation. Option D incorrectly suggests incomplete implementation – the SoA *documents* the alignment.
45 / 45
PR Description:
"Integration with 'LexiData' complete. Their vendor agreement includes a 'Service Level Agreement' (SLA) guaranteeing 99.9% uptime and specifies data residency within the EU. A preliminary risk assessment identified potential challenges related to data sovereignty requirements."
This question tests understanding of a core Vendor Risk Management vocabulary item. While an SLA does involve payment terms, its primary purpose is far broader – defining service performance metrics and establishing accountability. Misconceptions often arise from thinking it's *just* about money; it's fundamentally about guaranteeing the vendor delivers what they promised regarding availability and quality, which directly impacts your operations and risk profile. Selecting option 1 demonstrates this crucial distinction.
What does the "Vendor Risk Management Vocabulary" exercise practise?
Practice vendor risk management vocabulary: security questionnaires, SOC 2 certification, ISO 27001, annual assessments, and risk tiering.
How many questions are in this exercise?
This exercise has 45 questions, each multiple-choice with a full explanation shown after you answer.
What English level is this exercise for?
This exercise is tagged Intermediate. If the vocabulary feels difficult, browse the Compliance Security category page for an easier module to start with.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free with no account, sign-up, or paywall.
Do I get feedback if I answer incorrectly?
Yes — whichever option you choose, right or wrong, you'll immediately see an explanation clarifying the correct term and why the other options don't fit.
Can I retry this exercise?
Yes — once you finish all the questions, a "Try again" button on the results screen resets the exercise so you can practise as many times as you like.
Do I need an account to track my progress?
No account is required. Your progress bar and score for this session are tracked in the browser as you go, but nothing is saved once you leave the page.
Is "Vendor Risk Management Vocabulary" part of a larger series?
Yes — it's one exercise in the Compliance Security category on CoderSlingo. See the category page for the full list of related exercises on similar terminology.
Can I link directly to this exercise?
Yes — this exercise has its own permanent URL, so you can bookmark it or share the link directly with a colleague or study partner.
Where can I find more exercises like this one?
See the Compliance Security category page for related exercises, or browse the main Exercises hub for other IT English topics.