C. Obtain independent control reports from high-risk vendors.
When evaluating the control environment of third-party vendors, independent control reports (such as SOC 2 Type II or ISO 27001 certifications) provide the most comprehensive and reliable insight. These reports are conducted by third-party auditors and assess the effectiveness of a vendor's internal controls over a specific period. Obtaining these independent reports, especially from high-risk vendors, an organization can better evaluate the vendor's control environment without solely relying on the vendor's own assertions or internal documents.
I would of went with B. Not sure how A would provide more valuable insight into the control environment than B.
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.CRISC Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Raj1510
Highly Voted 2 years, 5 months agoStefan07
Highly Voted 3 years, 2 months ago01010100
Most Recent 9 months, 2 weeks agoCbtL
1 year, 3 months agojohn_boogieman
1 year, 4 months agoMusMus
2 years, 6 months agoJosh93
3 years, 2 months ago