SY0-701 · Question #528
Several customers want an organization to verify its security controls are operating effectively and have requested an independent opinion. Which of the following is the most efficient way to…
The correct answer is D. Provide a third-party attestation report. A third-party attestation report (such as a SOC 2 or ISO 27001 certification) is the most efficient solution because one independent audit produces a single report that can be shared with all requesting customers simultaneously, satisfying multiple parties at once. Why the…
Question
Several customers want an organization to verify its security controls are operating effectively and have requested an independent opinion. Which of the following is the most efficient way to address these requests?
Options
- AHire a vendor to perform a penetration test
- BPerform an annual self-assessment.
- CAllow each client the right to audit
- DProvide a third-party attestation report
How the community answered
(27 responses)- A7% (2)
- B7% (2)
- C4% (1)
- D81% (22)
Explanation
A third-party attestation report (such as a SOC 2 or ISO 27001 certification) is the most efficient solution because one independent audit produces a single report that can be shared with all requesting customers simultaneously, satisfying multiple parties at once.
Why the distractors are wrong:
- A (Penetration test): A pentest evaluates vulnerabilities and attack surface - it doesn't broadly attest that security controls are operating effectively, nor is it designed for customer assurance.
- B (Self-assessment): Self-assessments lack independence; customers asking for an independent opinion would rightly question the objectivity of an organization auditing itself.
- C (Right to audit): Allowing each client to audit individually is the least efficient option - it requires repeated time, resources, and access disruptions for every single customer request.
Memory tip: Think of it as the "one-to-many" principle. A third-party attestation report is created once and distributed to many - like a trusted certificate you hang on the wall for all visitors to see, rather than giving each visitor a personal tour of your security controls.
Topics
Community Discussion
No community discussion yet for this question.