SY0-701 Question 464
Single answer5.5 Explain types and purposes of audits and assessments.A healthcare company is preparing to sign a contract with a cloud-based billing vendor that will process protected health information (PHI). Before approving the vendor, the security manager wants an assessment that provides independent evidence of the vendor's control effectiveness over a period of time, rather than a point-in-time review. Which document would best satisfy this requirement?
- A
A penetration test report performed against the vendor's external applications
- B
A SOC 2 Type II report issued by an independent auditor
- C
A self-assessment questionnaire completed by the vendor's compliance team
- D
A vulnerability scan summary generated from the vendor's internal network
Show answer and explanation
Correct answer: B
Explanation
The key phrase in the scenario is 'independent evidence of the vendor's control effectiveness over a period of time.' That points to a SOC 2 Type II report, which is specifically designed to provide third-party assurance regarding the operating effectiveness of controls during a defined audit window. By contrast, a SOC 2 Type I report would only address the suitability of control design at a specific point in time. Penetration tests and vulnerability scans are valuable security assessments, but they are narrower in scope and do not replace an independent audit or attestation for vendor risk management. Self-assessments are commonly used in procurement and third-party questionnaires, but they lack independent verification. For practical Security+ purposes, this question distinguishes between audit and assessment artifacts and emphasizes the purpose of independent third-party reporting in supplier and compliance reviews. Relevant industry references include the AICPA SOC 2 attestation framework and common third-party risk management practices used in regulated environments such as healthcare.
- A. Incorrect.
A penetration test report can provide useful technical findings about exploitable weaknesses, but it does not serve as a broad audit of security control effectiveness over time. It is focused on attack paths and discovered vulnerabilities, not sustained operational control assurance across security, availability, or related trust criteria.
- B. Correct.
A SOC 2 Type II report is correct because it is an independent attestation report that evaluates the design and operating effectiveness of controls over a defined review period. This makes it well suited for vendor due diligence when an organization needs evidence that controls were not just documented at one moment, but actually operated effectively over time.
- C. Incorrect.
A self-assessment questionnaire is less reliable because it is completed by the vendor rather than independently validated by an external auditor. It may be useful as an initial screening tool, but it does not provide the same level of assurance as a formal third-party audit or attestation report.
- D. Incorrect.
A vulnerability scan summary identifies technical weaknesses present at the time of scanning, but it does not provide comprehensive assurance about the vendor's control environment or whether controls operated effectively over an extended period. It is an assessment activity, not the specific audit evidence requested in the scenario.