nerdexam
CompTIA

SY0-701 · Question #887

A security analyst is reviewing the security or a SaaS application that the company intends to purchase. Which of the following documentations should the security analyst request from the SaaS applica

The correct answer is B. Third-party audit. A third-party audit provides independent verification that the SaaS vendor’s security controls and processes meet industry standards, which helps the security analyst assess the actual security posture of the application before purchase.

Submitted by kim_seoul· Mar 6, 2026Security program management and oversight

Question

A security analyst is reviewing the security or a SaaS application that the company intends to purchase. Which of the following documentations should the security analyst request from the SaaS application vendor?

Options

  • AService-level agreement
  • BThird-party audit
  • CStatement or work
  • DData privacy agreement

How the community answered

(51 responses)
  • A
    8% (4)
  • B
    78% (40)
  • C
    12% (6)
  • D
    2% (1)

Explanation

A third-party audit provides independent verification that the SaaS vendor’s security controls and processes meet industry standards, which helps the security analyst assess the actual security posture of the application before purchase.

Community Discussion

No community discussion yet for this question.

Full SY0-701 Practice