CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard
A large enterprise is evaluating two cloud storage vendors for a contract involving sensitive financial data. Instead of conducting its own costly on-site security audit of each vendor, the enterprise requests each vendor's independent SOC 2 Type II report to evaluate their security controls over a sustained period. What is the primary purpose of relying on a SOC 2 Type II report in this scenario?
- ATo obtain third-party assurance of the vendor's control effectiveness over an extended period without conducting a full independent audit
- BTo guarantee the vendor meets data sovereignty requirements for the client's country
- CTo replace the need for a business associate agreement with the vendor
- DTo verify the vendor's compliance with a single point-in-time snapshot of controls
Show answer & explanationAnswer & explanation
Correct answer: A. To obtain third-party assurance of the vendor's control effectiveness over an extended period without conducting a full independent audit
A SOC 2 Type II report is an independent auditor's assessment of a service organization's controls related to security, availability, and confidentiality, evaluated over an extended period (typically 6-12 months), allowing customers to gain assurance without performing their own costly audits.
Why the other options are wrong
- B. SOC 2 reports address security and operational controls, not geographic data sovereignty requirements.
- C. A BAA is a separate legal requirement specific to HIPAA-covered ePHI and is unrelated to SOC 2 reporting.
- D. A Type II report evaluates controls over a sustained period; a Type I report, by contrast, is a point-in-time snapshot.
SOC 2 Type II Report
An independent auditor's report assessing a service organization's security, availability, and confidentiality controls over a sustained period, used by customers to gain assurance without conducting their own audits.
- Type II evaluates controls over time (e.g., 6-12 months); Type I is a snapshot
- Based on AICPA Trust Services Criteria
- Commonly requested during cloud vendor due diligence
Memory trick: SOC 1 is financial, SOC 2 is security, SOC 3 is public summary