nerdexam
(ISC)2

CISSP · Question #875

Which of the following reports provides the BEST attestation of detailed controls when evaluating an Identity as a Service (IDaaS) solution?

The correct answer is B. Service Organization Control (SOC) 2. When evaluating an Identity as a Service (IDaaS) solution, a Service Organization Control (SOC) 2 report offers the most comprehensive attestation of detailed controls related to security and operational aspects.

Submitted by luis.pe· Mar 5, 2026Security Assessment and Testing

Question

Which of the following reports provides the BEST attestation of detailed controls when evaluating an Identity as a Service (IDaaS) solution?

Options

  • AService Organization Control (SOC) 1
  • BService Organization Control (SOC) 2
  • CService Organization Control (SOC) 3
  • DStatement on Auditing Standards (SAS) 70

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    72% (21)
  • C
    17% (5)
  • D
    3% (1)

Why each option

When evaluating an Identity as a Service (IDaaS) solution, a Service Organization Control (SOC) 2 report offers the most comprehensive attestation of detailed controls related to security and operational aspects.

AService Organization Control (SOC) 1

SOC 1 reports primarily focus on controls relevant to a user entity's internal control over financial reporting, not the detailed security and operational controls of an IDaaS solution.

BService Organization Control (SOC) 2Correct

A SOC 2 report specifically addresses controls related to security, availability, processing integrity, confidentiality, and privacy, which are critical Trust Services Criteria for an IDaaS solution. It provides detailed information on the service organization's system and the suitability of the design and operating effectiveness of controls, making it ideal for evaluating an IDaaS provider.

CService Organization Control (SOC) 3

SOC 3 reports are general-use reports that provide a high-level overview without the detailed control information necessary for a thorough technical evaluation of an IDaaS solution.

DStatement on Auditing Standards (SAS) 70

SAS 70 is an outdated auditing standard that has been replaced by the SOC reporting framework and focused on internal controls over financial reporting, not the broader operational controls of an IDaaS.

Concept tested: Evaluating IDaaS controls using audit reports (SOC 2)

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-1-2-3

Topics

#IDaaS evaluation#SOC reports#Third-party risk#Vendor assessment

Community Discussion

No community discussion yet for this question.

Full CISSP Practice