SY0-701 Question 475
Single answerIndependent third-party auditA healthcare startup is preparing to sign a contract with a large enterprise customer that requires proof the startup's security controls were evaluated by an impartial outside party. The startup's security manager already performs quarterly internal reviews and vulnerability scans, but the customer specifically asks for evidence that the control assessment was conducted independently and can be shared with external stakeholders. Which of the following would BEST meet the customer's requirement?
- A
Have the internal audit team issue a memo stating the environment passed its annual review
- B
Provide a self-assessment questionnaire completed by the startup's security manager
- C
Engage a licensed CPA firm to perform a SOC 2 audit and provide the resulting report
- D
Run another authenticated vulnerability scan and export the scanner results
Show answer and explanation
Correct answer: C
Explanation
The key phrase in the scenario is that the customer wants proof of an independent third-party assessment that can be shared with external stakeholders. Internal audits, self-assessments, and scanner results are all useful, but they do not provide the same assurance as a formal audit or attestation conducted by an external party. A SOC 2 report is a common real-world way for service organizations to demonstrate this kind of independent review. Under AICPA guidance, SOC 2 examinations are performed by independent CPAs against the Trust Services Criteria, making them suitable for vendor assurance scenarios. From a Security+ perspective, the distinction being tested is between internal validation activities and an independent third-party audit, which provides stronger evidence of objectivity, credibility, and due diligence.
- A. Incorrect.
This is incorrect because an internal audit team is part of the organization and is not considered an independent third party from the customer's perspective. Internal reviews are useful for governance and continuous improvement, but they do not provide the same level of external assurance as an audit performed by an outside assessor.
- B. Incorrect.
This is incorrect because a self-assessment is completed by the organization itself and therefore does not satisfy a requirement for an impartial, independent third-party evaluation. Customers may use questionnaires during vendor due diligence, but a self-attested response is weaker evidence than an independently issued audit report.
- C. Correct.
This is correct because a SOC 2 examination is performed by an independent CPA firm and is specifically designed to provide external stakeholders with assurance about the design and, depending on the type of report, operating effectiveness of controls relevant to security and other trust services criteria. This aligns well with a customer's request for evidence that can be shared externally and that was produced by an impartial outside party.
- D. Incorrect.
This is incorrect because a vulnerability scan is only one technical assessment activity and does not by itself constitute a broad independent third-party audit of security controls. Scanner output may help support an audit, but it does not replace an externally performed attestation or audit report.