exam questions

Exam IIA-CIA-Part3 All Questions

View all questions & answers for the IIA-CIA-Part3 exam

Exam IIA-CIA-Part3 topic 2 question 90 discussion

Actual exam question from IIA's IIA-CIA-Part3
Question #: 90
Topic #: 2
[All IIA-CIA-Part3 Questions]

According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization's network and data?

  • A. Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations.
  • B. Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause.
  • C. Applying administrative privileges to ensure right-to-access controls are appropriate.
  • D. Creating a standing cybersecurity committee to identify and manage risks related to data security.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Walewweeeed
Highly Voted 3 years, 6 months ago
B is correct
upvoted 6 times
...
fadsinyav
Most Recent 5 days, 15 hours ago
Selected Answer: D
dnetim yağpılıyorsa sözleşme zaten hazırlanmış olmalı, sözleşme hazırlamak ilk adım olamaz bence.
upvoted 1 times
...
KonradK
11 months ago
Selected Answer: B
It's B!
upvoted 1 times
...
Elvin
11 months, 1 week ago
Why D? Should this be B?
upvoted 2 times
...
Khets
3 years, 3 months ago
Correct answer is definitely B according to GTAG Assessing cyber security risk
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...