nerdexam
EC-Council

712-50 · Question #413

When reviewing a Solution as a Service (SaaS) provider's security health and posture, which key document should you review?

The correct answer is B. SOC-2 Report. A SOC 2 (System and Organization Controls 2) Report is the industry-standard third-party audit document that independently verifies a SaaS provider's controls around security, availability, processing integrity, confidentiality, and privacy - making it the most authoritative…

Strategic Planning, Finance, Procurement, and Vendor Management

Question

When reviewing a Solution as a Service (SaaS) provider's security health and posture, which key document should you review?

Options

  • ASaaS provider's website certifications and representations (certs and reps)
  • BSOC-2 Report
  • CMetasploit Audit Report
  • DStatement from SaaS provider attesting their ability to secure your data

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    80% (16)
  • C
    5% (1)
  • D
    5% (1)

Explanation

A SOC 2 (System and Organization Controls 2) Report is the industry-standard third-party audit document that independently verifies a SaaS provider's controls around security, availability, processing integrity, confidentiality, and privacy - making it the most authoritative and objective source for assessing their security posture.

Why the distractors fail:

  • A (certs and reps on website): Marketing claims and self-declared badges are unverified and unaudited - a provider can post any logo they want.
  • C (Metasploit Audit Report): Metasploit is a penetration testing tool, not an audit framework; there is no formal "Metasploit Audit Report" standard used for vendor due diligence.
  • D (provider's own attestation): A self-written statement is self-serving and carries no independent verification - it's the fox guarding the henhouse.

Memory tip: Think "SOC 2 = Someone Else Checked" - the key value is that a third-party auditor (a CPA firm) performed the assessment, so you're not relying on the vendor's word alone. On any exam question asking about vendor/SaaS security assurance, SOC 2 is almost always the answer when independent verification is the goal.

Topics

#SOC-2 audit reports#SaaS vendor assessment#Security due diligence#Compliance frameworks

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice