(ISC)2(ISC)2
CISSP · Question #1274
CISSP Question #1274: Real Exam Question with Answer & Explanation
Sign in or unlock CISSP to reveal the answer and full explanation for question #1274. The question stem and answer options stay visible for context.
Submitted by marco_it· Mar 5, 2026Security Assessment and Testing
Question
When conducting a third-party risk assessment of a new supplier, which of the following reports should be reviewed to confirm the operating effectiveness of the security, availability, confidentiality, and privacy trust principles?
Options
- AService Organization Control (SOC) 1, Type 2
- BService Organization Control (SOC) 2, Type 2
- CInternational Organization for Standardization (ISO) 27001
- DInternational Organization for Standardization (ISO) 27002
Unlock CISSP to see the answer
You've previewed enough free CISSP questions. Unlock CISSP for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#third-party risk assessment#SOC 2#Trust Services Criteria#vendor risk management