SY0-701 Question 463
Single answer5.5 Explain types and purposes of audits and assessments.A healthcare organization is preparing to sign a contract with a cloud-based billing provider that will process protected health information (PHI). Management wants reasonable assurance that the provider's security controls are designed appropriately and are operating effectively over time, without sending the organization's own team onsite. Which assessment or audit report would BEST meet this requirement?
- A
A SOC 2 Type II report
- B
A vulnerability scan summary from the provider's internal security team
- C
A penetration test report focused on the provider's external web portal
- D
A SOC 1 Type I report
Show answer and explanation
Correct answer: A
Explanation
The key phrases in the scenario are "reasonable assurance," "operating effectively over time," and "without sending the organization's own team onsite." That points to an independent third-party attestation rather than an internal assessment artifact such as a scan or pen test. SOC 2 reports, issued under the AICPA attestation framework, are commonly used to evaluate service organizations' controls related to the Trust Services Criteria, especially security and confidentiality. Type I evaluates whether controls are suitably designed at a specific point in time, while Type II evaluates both design and operating effectiveness over a review period. By contrast, SOC 1 is intended for internal control over financial reporting, making it less appropriate for a security-focused vendor due diligence review. In practice, organizations in regulated industries such as healthcare often request a SOC 2 Type II report as part of third-party risk management, along with contractual and compliance reviews, because it provides stronger audit-based evidence than a simple vulnerability scan or penetration test.
- A. Correct.
Correct. A SOC 2 Type II report is designed to provide assurance about controls relevant to security, availability, processing integrity, confidentiality, and privacy, with Type II specifically addressing not only the suitability of control design but also operating effectiveness over a period of time. For a customer evaluating a cloud provider handling sensitive data such as PHI, this is typically the most useful independent attestation when the goal is to review ongoing security control effectiveness without conducting an onsite audit.
- B. Incorrect.
Incorrect. A vulnerability scan summary can identify technical weaknesses at a point in time, but it is not an independent audit or attestation of the provider's overall control environment. It also does not demonstrate that controls were operating effectively over a defined review period. Candidates may choose this because it sounds security-focused, but it is much narrower than a formal audit report.
- C. Incorrect.
Incorrect. A penetration test report can provide valuable insight into exploitable weaknesses, but it is limited in scope and timing. It does not replace an independent assessment of the provider's broader administrative, technical, and operational controls. Someone might choose this option because penetration testing is a strong security practice, but it does not satisfy the stated requirement for assurance that controls are both well designed and operating effectively over time.
- D. Incorrect.
Incorrect. A SOC 1 Type I report focuses on controls relevant to financial reporting, not primarily on security controls for protecting customer data. In addition, Type I addresses design at a point in time rather than operating effectiveness over a period. This could be tempting because it is a recognized audit report, but it is not the best fit for evaluating a cloud provider's security posture for PHI handling.