Before any changes to the configuration of an application are made, it is recommended that the correct update set and application scope are selected. What role is required for this functionality?
AThe Vendor Administrator role is required for this functionality
BThe Data Administrator role is required for this functionality
CThe User Administrator role is required for this functionality
DThe System Administrator role is required for this functionality
What is the definition of ‘Risk Management’?
APolicies/Standards/Procedures established to ensure an organization is aligned with corporate strategy and expectations are clearly defined
BThe process of conforming to standards, policies, and remediation of audit findings
CThe elimination of vulnerable surface area in an enterprise environment
DProcess to identify, assess, and respond to risks, threats and vulnerabilities that could compromise the business
Which of the following is the main benefit of using the Vendor Portal?
AAssessments are performed via the Vendor Portal and spreadsheets
BMore efficiently communicating Assessments with a single contact
CAssessments are shared through the Vendor Portal and email
DMore efficiently completing Assessments via the Vendor Portal
Which statement best describes the role assignment of vendor contacts in Vendor Risk Management?
AWhen vendor contacts are created, they are automatically assigned the snc_internal role and the snc_external role
BWhen vendor contacts are created, they must be manually assigned the snc_external role
CWhen vendor contacts are created, they are automatically assigned the snc_internal role
DWhen vendor contacts are created, they are automatically assigned the snc_external role
What can a vendor contact do in the Vendor Portal? (Choose four.)
AUpdate answers to returned questionnaires
BCommunicate or share information with other vendors of the assessing organization
CCreate new issues and tasks for the vendor risk assessor team
DReview and respond to issues created by the assessing organization
EManage vendor contacts and task assignments within the vendor organization
FRespond to assessments sent by the assessing organization
To what type of assessment record can a vendor contact respond?
AVendor tiering assessment
BVendor risk assessment
CCustomer assessment
DExternal monitoring assessment
What are the features of Vendor Risk Issues? (Choose two.)
AGenerate audit tasks for the vendor risk team
BCan only be seen by the customer’s vendor risk team
CProvide vendor direct access to update and respond to Issues
DCan be generated on-demand or automatically due to an incorrect answer
Who is able to change the password for the vendor contact? (Choose two.)
AVendor Contract Relationship Manager
Bsys_admin
CVendor contact via the Forgot Password link
DVendor Risk Reviewer
Which GRC records can be related to an Entity? (Choose three.)
AEntity Types
BVendors
CRisks
DPolicies
EControls
A vendor is assessed and responds to a question which impacts one of the Controls applied to them. When is the Control Status updated?
AWhen the Vendor Risk Assessment State is Responses Received
BWhen the Vendor Risk Assessment State is Finalizing with Vendor or Closed
CWhen the Vendor Risk Assessment response is saved
DWhen all Questions in the Vendor Risk Assessment have a response
A Vendor Risk Manager needs to run a report displaying Critical Vendors. On which table would this person run a report?