nerdexam
(ISC)2

CCSP · Question #29

You are performing an audit of the security controls used in a cloud environment. Which of the following would best serve your purpose?

The correct answer is D. A SOC 3 report from another (external) auditor. When auditing security controls in a cloud environment, a SOC 3 report provides an external auditor's opinion on the effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy.

Submitted by skyler.x· Apr 18, 2026Cloud Platform & Infrastructure Security

Question

You are performing an audit of the security controls used in a cloud environment. Which of the following would best serve your purpose?

Options

  • AThe business impact analysis (BIA)
  • BA copy of the VM baseline configuration
  • CThe latest version of the company's financial records
  • DA SOC 3 report from another (external) auditor

How the community answered

(18 responses)
  • A
    11% (2)
  • C
    6% (1)
  • D
    83% (15)

Why each option

When auditing security controls in a cloud environment, a SOC 3 report provides an external auditor's opinion on the effectiveness of a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy.

AThe business impact analysis (BIA)

A business impact analysis (BIA) assesses the potential effects of an interruption to critical business functions, not the effectiveness of security controls in a cloud environment.

BA copy of the VM baseline configuration

A VM baseline configuration shows how a *single VM* is configured, but doesn't provide an overall assessment of the broader security controls and processes implemented across the entire cloud environment by the provider.

CThe latest version of the company's financial records

The latest version of the company's financial records is irrelevant for an audit of security controls in a cloud environment.

DA SOC 3 report from another (external) auditorCorrect

A SOC 3 report, provided by an external auditor, offers a publicly available summary of a cloud service provider's internal controls relevant to security, availability, processing integrity, confidentiality, and privacy. For an organization auditing security controls in a cloud environment, reviewing this report allows them to gain assurance about the cloud provider's control effectiveness without conducting their own exhaustive audit of the provider's infrastructure.

Concept tested: Cloud security auditing & SOC reports

Source: https://www.aicpa.org/resources/download/understanding-the-difference-between-a-soc-1-soc-2-and-soc-3-report

Topics

#Security Auditing#Cloud Security Controls#Configuration Management#Virtual Machine Security

Community Discussion

No community discussion yet for this question.

Full CCSP Practice