Certified Information Security Manager CISM · Free Practice Question Medium

Question 28

What assumption can a CISO make about a third-party service provider that has returned a security questionnaire and responded “yes” to every security question?
  • A

    The organization’s questionnaire is clearly not detailed enough.

  • B

    The person who answered the questions is not adequately familiar with the service provider’s security program.

  • C

    The CISO should suspect that the service provider is being dishonest.

  • D

    The service provider has an exemplary security program.

Reveal correct answer

Correct answer: B

Explanation

Correct Answer:

"The person who answered the questions is not adequately familiar with the service provider’s security program." is correct. When a service provider answers “yes” to every question, it is likely that the person answering the questions is either unfamiliar with their security program or answering it in haste, in the hopes it will not be scrutinized.

Incorrect Answers:

"The service provider has an exemplary security program." is incorrect because even the most exemplary security program is likely to answer “no” to at least a few questions in a questionnaire.

"The organization’s questionnaire is clearly not detailed enough." is incorrect, because although this is a plausible answer, it is not the best answer.

"The CISO should suspect that the service provider is being dishonest." is incorrect because this is a rash judgment (although it may in fact be true).

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need