712-50 · Question #413
When reviewing a Solution as a Service (SaaS) provider's security health and posture, which key document should you review?
The correct answer is B. SOC-2 Report. A SOC 2 (System and Organization Controls 2) Report is the industry-standard third-party audit document that independently verifies a SaaS provider's controls around security, availability, processing integrity, confidentiality, and privacy - making it the most authoritative…
Question
When reviewing a Solution as a Service (SaaS) provider's security health and posture, which key document should you review?
Options
- ASaaS provider's website certifications and representations (certs and reps)
- BSOC-2 Report
- CMetasploit Audit Report
- DStatement from SaaS provider attesting their ability to secure your data
How the community answered
(20 responses)- A10% (2)
- B80% (16)
- C5% (1)
- D5% (1)
Explanation
A SOC 2 (System and Organization Controls 2) Report is the industry-standard third-party audit document that independently verifies a SaaS provider's controls around security, availability, processing integrity, confidentiality, and privacy - making it the most authoritative and objective source for assessing their security posture.
Why the distractors fail:
- A (certs and reps on website): Marketing claims and self-declared badges are unverified and unaudited - a provider can post any logo they want.
- C (Metasploit Audit Report): Metasploit is a penetration testing tool, not an audit framework; there is no formal "Metasploit Audit Report" standard used for vendor due diligence.
- D (provider's own attestation): A self-written statement is self-serving and carries no independent verification - it's the fox guarding the henhouse.
Memory tip: Think "SOC 2 = Someone Else Checked" - the key value is that a third-party auditor (a CPA firm) performed the assessment, so you're not relying on the vendor's word alone. On any exam question asking about vendor/SaaS security assurance, SOC 2 is almost always the answer when independent verification is the goal.
Topics
Community Discussion
No community discussion yet for this question.