nerdexam
Isaca

CGEIT · Question #477

When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?

The correct answer is B. Third-party audit report. When selecting a cloud provider, a third-party audit report offers the most comprehensive information on the current status and effectiveness of the provider's controls.

Submitted by yuriko_h· Apr 18, 2026Governance of Enterprise IT

Question

When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?

Options

  • AGlobally recognized certification
  • BThird-party audit report
  • CControl self-assessment (CSA)
  • DMaturity assessment

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    72% (26)
  • C
    3% (1)
  • D
    17% (6)

Why each option

When selecting a cloud provider, a third-party audit report offers the most comprehensive information on the current status and effectiveness of the provider's controls.

AGlobally recognized certification

A globally recognized certification indicates compliance with a standard but does not provide the granular, detailed information on control implementation and effectiveness found in the full audit report.

BThird-party audit reportCorrect

Third-party audit reports, such as SOC 2 or ISO 27001 audit reports, provide an independent and objective evaluation by external auditors of the design and operational effectiveness of a cloud provider's security and other relevant controls, offering detailed assurance.

CControl self-assessment (CSA)

A Control Self-Assessment (CSA) is an internal review by the provider, which lacks the objectivity and independent validation of an external third-party audit.

DMaturity assessment

A maturity assessment evaluates the sophistication of processes over time but does not offer specific, point-in-time evidence of the effectiveness of individual controls.

Concept tested: Cloud provider due diligence, third-party assurance reports

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2

Topics

#Cloud Security#Third-party Assurance#Vendor Due Diligence#Control Effectiveness

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice