nerdexam
CompTIA

SY0-701 · Question #435

A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following…

The correct answer is D. Due diligence. Due diligence in this context involves evaluating the security, availability, processing integrity, confidentiality, and privacy of the SaaS application by reviewing the SOC 2 report provided by the vendor. This process helps ensure that the vendor meets the required security…

Submitted by paula_co· Mar 6, 2026Security program management and oversight

Question

A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?

Options

  • AInternal audit
  • BPenetration testing
  • CAttestation
  • DDue diligence

How the community answered

(34 responses)
  • A
    15% (5)
  • B
    3% (1)
  • C
    6% (2)
  • D
    76% (26)

Explanation

Due diligence in this context involves evaluating the security, availability, processing integrity, confidentiality, and privacy of the SaaS application by reviewing the SOC 2 report provided by the vendor. This process helps ensure that the vendor meets the required security and operational standards before the SaaS application is implemented.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice