Shared Assessments Certified Third-Party Risk Professional (CTPRP) CTPRP Question # 9 Topic 1 Discussion

Shared Assessments Certified Third-Party Risk Professional (CTPRP) CTPRP Question # 9 Topic 1 Discussion

CTPRP Exam Topic 1 Question 9 Discussion:
Question #: 9
Topic #: 1

When defining due diligence requirements for the set of vendors that host web applications which of the following is typically NOT part of evaluating the vendor's patch

management controls?


A.

The capability of the vendor to apply priority patching of high-risk systems


B.

Established procedures for testing of patches, service packs, and hot fixes prior to installation


C.

A documented process to gain approvals for use of open source applications


D.

The existence of a formal process for evaluation and prioritization of known vulnerabilities


Get Premium CTPRP Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.