712-50 exam dumps

712-50 practice question 55 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 55

Single answerUnderstand the compliance auditing and certification programs

A global SaaS company is preparing to enter several enterprise markets where prospective customers routinely ask for independent assurance over security controls. The organization already maps many of its controls to ISO/IEC 27001, but the sales team wants a report that can be shared under NDA with customers to reduce repetitive security questionnaires. The CEO asks the CISO which compliance auditing or certification approach would best satisfy this need while providing assurance over the operating effectiveness of controls over a period of time. Which option should the CISO recommend?

  1. A

    Pursue a SOC 2 Type II examination because it provides an independent attestation on the design and operating effectiveness of controls over a defined review period and is commonly shared with customers under NDA

  2. B

    Pursue ISO/IEC 27001 certification only, because certification automatically includes a detailed customer-facing report on the operating effectiveness of all security controls over the prior 12 months

  3. C

    Request a PCI DSS Attestation of Compliance, because it is the broadest cross-industry assurance report for enterprise customers regardless of whether the company processes payment cards

  4. D

    Perform an internal audit against the NIST Cybersecurity Framework, because an internally issued assessment provides the same level of third-party assurance as an external attestation report

Show answer and explanation

Correct answer: A

Explanation

The key decision point is matching the business objective to the right assurance mechanism. The scenario asks for a report that can be shared with customers under NDA, reduces repetitive questionnaires, and demonstrates operating effectiveness of controls over time. SOC 2 Type II is the strongest fit because it is an independent attestation report covering controls over a review period, typically aligned to the AICPA Trust Services Criteria. By contrast, SOC 2 Type I addresses design at a point in time, not operating effectiveness over time. ISO/IEC 27001 certification is highly valuable for demonstrating that an ISMS has been implemented and certified by an accredited body, but it is not the same as a detailed customer assurance report on control operation across a period. PCI DSS is sector-specific, focused on payment card environments, and should not be treated as a general-purpose assurance program. NIST CSF is a framework for managing and improving cybersecurity posture, not a certification program that inherently yields third-party customer assurance. Best practice for a CISO is to align assurance activities with stakeholder needs: use certification programs like ISO/IEC 27001 for formal management-system recognition, use attestation reports like SOC 2 Type II for customer assurance on control effectiveness, and use internal audits/framework assessments such as NIST CSF for governance, benchmarking, and improvement planning. Relevant references include the AICPA guidance for SOC 2 and ISO/IEC 27001 requirements for ISMS certification.

  • A. Correct.

    Correct. A SOC 2 Type II report is specifically designed to provide independent assurance from a licensed CPA firm regarding the suitability of design and operating effectiveness of controls relevant to the Trust Services Criteria over a defined period, not just at a point in time. In practice, many SaaS and cloud providers use SOC 2 Type II reports to respond to customer due diligence requests and reduce repetitive questionnaires. These reports are commonly shared with customers and prospects under NDA because they contain sensitive control information.

  • B. Incorrect.

    Incorrect. ISO/IEC 27001 certification is valuable and widely recognized, but it is a management system certification for an Information Security Management System (ISMS), not a customer-oriented attestation report equivalent to SOC 2 Type II. Certification demonstrates that the organization has established and maintains an ISMS that conforms to the standard, but it does not automatically provide a detailed report to customers on the operating effectiveness of controls over the prior 12 months. Candidates often choose this option because ISO 27001 is globally respected, but it does not directly satisfy the stated need as well as SOC 2 Type II.

  • C. Incorrect.

    Incorrect. PCI DSS applies to entities that store, process, or transmit payment card data, or that can affect the security of the cardholder data environment. It is not a general-purpose assurance mechanism for all enterprise customers. If the company is not in scope for payment card processing, pursuing PCI DSS solely for broad customer assurance would be misaligned and costly. This distractor reflects the misconception that any well-known compliance framework can serve as a universal trust report.

  • D. Incorrect.

    Incorrect. An internal audit against the NIST Cybersecurity Framework may be useful for internal governance, maturity assessment, and gap analysis, but it does not provide the same level of independent third-party assurance as an external attestation or certification. Enterprise customers typically distinguish between self-assessments/internal audits and independent reports issued by accredited or licensed external assessors. This option is plausible because NIST CSF is a respected framework, but it does not meet the requirement for independent assurance to customers.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam