Governance, Risk, Compliance and Third-Party Oversight
Security program questions test policies, standards, risk registers, risk responses, compliance obligations, vendor assessment, contracts, and shared responsibility.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Governance sets direction, accountability, decision rights, policies, and oversight for security risk.
Exam cue: Separate policy, standard, procedure, and guideline.
Concept 2
Risk management identifies, analyzes, treats, monitors, and reports risk using business context.
Exam cue: Choose avoid, transfer, mitigate, or accept based on business decision.
Concept 3
Third-party risk management evaluates vendors before and during the relationship through due diligence, contracts, monitoring, and offboarding.
Exam cue: Evaluate vendors before granting access to sensitive systems or data.
Risk pitfalls and guardrails
Accepting risk without an accountable owner.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Confusing compliance with complete security.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Skipping vendor review because a contract is already signed.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Policy
A policy states management intent and required behavior at a high level.
Standard
A standard defines mandatory details needed to comply with a policy.
Procedure
A procedure gives step-by-step instructions for performing a required task.
Guideline
A guideline gives recommended practice that may allow flexibility.
Risk Register
A risk register records risks, owners, likelihood, impact, response, and status.
Risk Acceptance
Risk acceptance is an accountable decision to tolerate residual risk.
Risk Transfer
Risk transfer shifts financial or operational impact through insurance or contracts.
Risk Mitigation
Risk mitigation reduces likelihood or impact through controls.
Vendor Due Diligence
Vendor due diligence evaluates a third party before sensitive access or reliance.
SLA
A service-level agreement defines expected service performance, responsibilities, and remedies.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
The board states that sensitive data must be protected according to business and legal requirements. What type of document is this high-level management direction?
A document requires AES-256 for a defined class of stored data and TLS 1.2 or later in transit. What type of document is it?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
