nerdexam
CompTIA

SY0-701 · Question #884

A security analyst is reviewing the security of a SaaS application that the company intends to purchase. Which of the following documentations should the security analyst request from the SaaS…

The correct answer is B. Third-party audit. A third-party audit report (such as a SOC 2 or ISO 27001 certification) provides independent validation of the vendor’s security controls and assurance of its security posture.

Submitted by packet_pusher· Mar 6, 2026Security program management and oversight

Question

A security analyst is reviewing the security of a SaaS application that the company intends to purchase. Which of the following documentations should the security analyst request from the SaaS application vendor?

Options

  • AService-level agreement
  • BThird-party audit
  • CStatement of work
  • DData privacy agreement

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    82% (18)
  • C
    5% (1)
  • D
    5% (1)

Explanation

A third-party audit report (such as a SOC 2 or ISO 27001 certification) provides independent validation of the vendor’s security controls and assurance of its security posture.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice