5.3 Explain the processes associated with third-party risk assessment and management
Objective 5.3 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
In the private disclosure model for reporting vulnerabilities, who decides whether vulnerability details are ever published?
The concept
Private disclosure is one model for handling third-party vulnerability reports and sets who controls the eventual release of details.
Why this answer
Under private disclosure, the vulnerability is reported to the organization and publication is left entirely to the organization's discretion, so many findings never become public.
- Correct: private disclosure places publication authority with the organization, not the reporter.
- BThe researcher only controls timing under full or coordinated disclosure, not under a pure private model.
- CA CERT may assist with contact, but it does not hold publication authority under private disclosure.
- DA bug bounty platform hosts the program but the organization retains the publication decision.
Now you: objective 5.3 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
Which practice should an organization maintain so outside researchers have a clear channel to report discovered vulnerabilities?
Sample question 2 of 3
After a researcher privately reports a vulnerability, the organization threatens the researcher with legal action instead of addressing the report. Which expectation of vulnerability handling has the organization failed to meet?
Sample question 3 of 3
A researcher finds a vulnerability in a company's bug bounty program but also decides to test a subdomain not listed in the program's published scope. What is the most likely consequence?
That’s 3 of the full Security+ bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practicingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.