The primary advantage of creating and maintaining a vendor risk registry is to ensure that an inventory of potential risks is maintained. A vendor risk registry helps organizations keep track of the risks associated with third-party vendors, especially as they may introduce vulnerabilities or non-compliance issues. By maintaining this registry, the organization can continuously monitor and manage vendor-related risks in a structured way, improving its overall security posture. CASP+ emphasizes the importance of vendor risk management in an organization's broader risk management strategy. Reference: CASP+ CAS-004 Exam Objectives: Domain 1.0 - Risk Management (Vendor Risk Management) CompTIA CASP+ Study Guide: Third-Party Risk Management and Risk Registries