Access Auditing as the SaaS Vendor Risk to Focus On

Answer Correct answer: A — Access auditing is the risk the company can still control, since the vendor owns the platform while entitlement reviews and log reviews limit exposure.

A company uses a SaaS vendor to host its customer database. The company would like to reduce the risk of customer data exposure if the systems are breached. Which of the following risks should the company focus on to achieve this objective?

  1. Access auditing Correct Answer
  2. Outsourced code development
  3. Supply chain
  4. Open ports and services

Community Votes

A
48%
C
32%
D
20%

48% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

In a SaaS relationship the customer's lever is data and access governance rather than infrastructure, so the question becomes who can read the customer database and whether the vendor will hand over the evidence through audit logs and right-to-audit terms.

Because the SaaS vendor runs the platform, the company cannot patch those servers or close their ports. The exposure it can still govern is who reaches the customer database, so access auditing is the risk area worth concentrating on.

Choosing supply chain simply because a vendor is involved. Supply chain risk covers tampered or counterfeit components and software provenance, and it does not change how much customer data an attacker can read once a breach happens.

Community Discussion (21 comments)

NolanR 👍 20 Selected: A
Its A bro are yall crazy? I just took the test and a 2 week course and saw this EXACT question.
ganymede 👍 9 Selected: D
D. Open ports and services The question is only asking about RISKS. "Which of the following RISKS should the company focus on to achieve this objective?" Access auditing is not a risk so toss it out. Misconfiguration is one of the top risks for cloud services. Do some research and you'll find many credible sources agreeing that it's one of the top risks to cloud services. Open ports and services is a very common cloud misconfiguration.
Shouqq_examtopics 👍 2 Selected: A
Access auditing involves monitoring and recording who accesses the data, what actions they perform, and ensuring that only authorized personnel have access to sensitive information
mikzer 👍 1 Selected: A
The company has to depend on or trust the SaaS vendor concerning B-D. Worry all it wants to about that. Get a different vendor if you can't trust it. A is the only one the company has control over to put focus upon.
AspiringNerd 👍 1 Selected: A
It’s A
cd48a66 👍 3 Selected: C
The answer is C. Supply Chain because the company uses a cloud provider to manage their database, making it essential to focus on the security practices of this provider as part of their supply chain risk management.
_deleteme_ 👍 2
A - If you do not audit how will you know who is accessing customer data? Key words "breach" & "exposure" whether it is the companies people or the vendors people. Per DION Training guide 701 - Accounting (Auditing) Tracks and records user activities, logins, actions, and changes. Helps detect security incidents, identify vulnerabilities, and provide evidence in case of breaches. Per 601 - Cloud Security Section - Configure, manage, and audit user access to virtualized servers. Security challenges with Software-as-a-Service (SaaS) providers ● Data confidentiality and integrity concerns ● Assess provider's cybersecurity protocols and support for security incidents ● Vendor selection should consider due diligence, historical performance, and commitment to security
Mizzcoors 👍 1 Selected: C
I'm sort of agreeing with Chat GBT on this one C. Supply chain When a company relies on a SaaS vendor to host its customer database, the supply chain risk becomes a critical concern. Supply chain risks refer to vulnerabilities introduced through third-party providers, including SaaS vendors. If the SaaS vendor's systems are breached, it could potentially expose the customer data of the company. Additionally, the CompTIA guide has: Supply chain - Cloud — many companies now run part or all of their network services via Internet- accessible clouds. The attacker only needs to find one account, service, or host with weak credentials to gain access. The attacker is likely to target the accounts used to develop services in the cloud or manage cloud systems. They may also try to attack the cloud service provider (CSP) as a way of accessing the victim system.
Ainevknow01 👍 2 Selected: C
SaaS vendor = supply chain
BD69 👍 2 Selected: A
I picked access auditing because that's really the only thing that makes sense here if the SaaS allows it. You have zero control over the ports & services, so that's a definite non-answer. Supply Chain is completely irrelevant. Outsourced code development is irrelevant (this is SaaS, so you aren't doing coding of the application)
fryderyk 👍 3 Selected: C
Supply chain seems the most probable. If it's SaaS, the customer is most likely not responsible for port configurations. They would be if that was PaaS or IaaS.
ps1hacker 👍 1 Selected: D
I think D is best. Sure supply chain or 3rd party code is possible, but open ports is MUCH more likely to be an issue.
slapster 👍 5 Selected: C
I am leaning towards Supply chain (C) here. The question is asking about which RISK to focus on, rather than how to mitigate that risk. Third-party hosting of a database is a supply chain risk. Access auditing is how they would go about reducing the risk, however I believe that is out of the scope of the question. Again, we are being asked to identify the risk itself, not how to combat/reduce it. B is wrong because they are not outsourcing any code development. I believe D is wrong because the SaaS vendor should be the one responsible for the service itself. Proper configuration by the vendor is definitely necessary and access auditing can be used to confirm it, however from the company's perspective, their risk is supply chain, not the open ports/services.
memodrums 👍 1 Selected: A
Since its a SaaS application, as the customer, you won't have to worry about open ports and services b/c the database will be fully controlled by the SaaS vendor. The only risk that would present itself is having the ability to audit the vendor to make sure they are adequately implementing the necessary controls to protect your data.
f8ecb59 👍 1
The question is asking what risk should the company focus on to reduce customer data exposure after a breach has already occurred. This should change how you think about the answer.
Biru04 👍 1 Selected: C
Supply chain security is management of the supply chain that focuses on risk management of external suppliers, vendors, logistics, and transportation.
klinkklonk 👍 1
Whose system is being breached though?
Mick84 👍 3 Selected: D
Many organizations assume that it’s the cloud provider’s responsibility to provide security, which is not true. So, organizations begin moving data into the cloud and essentially leave it all on the default configuration, without “reading the manual” and understanding all the features. And that’s understandable, because so many of the public cloud platforms make it so simple to get set up and stand up an environment – in some cases you can even try it free before fully committing. But while default settings may allow users to get up and running quickly, they lack the secure configurations.
dfc6822 👍 4
C. Supply chain When a company uses a SaaS (Software as a Service) vendor to host its customer database, the supply chain risk becomes a critical consideration. The supply chain in this context refers to the processes and systems involved in the development, distribution, and maintenance of the SaaS solution.
Jay987654 👍 4 Selected: A
Access auditing involves monitoring and recording user activities for abnormal access patterns or policy violations. Regular audits can help identify unauthorized access attempts, ensure users only have appropriate permissions, and verify compliance with company policies. This is particularly important when dealing with a SaaS vendor, as the vendor has direct access to the company’s customer database. Regular access audits can help ensure that the vendor is following proper security protocols and not exposing sensitive customer data.
Hs1208 👍 6 Selected: C
Supply Chain Risk: The company should assess and manage the risks associated with the SaaS vendor's supply chain. This includes the security practices of the vendor, the integrity of the software and infrastructure, and the security measures in place throughout the supply chain

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Access auditing determines whether the company can see who opened the customer database, when, and from where, which is the only lens it still has over data it no longer hosts. Under the shared responsibility model the vendor runs the platform, so the customer's remaining levers are entitlement reviews, least privilege, and continuous review of access logs. That focus limits exposure directly, because a breached account can only read what its holder was entitled to read, and unusual reads are caught while the window is still small.

Why the Other Options Are Wrong

Open ports and services are the vendor's infrastructure responsibility in a SaaS model, so the company cannot close them and can take no action by focusing there. Outsourced code development applies when a third party writes code for you, which does not happen when you simply subscribe to a hosted application. Supply chain risk addresses tampered or counterfeit components and software provenance; the vendor's place in the supply chain is real, but it does not decide how much customer data is exposed after the breach occurs.

Community Comment Notes

The vote splits three ways with access auditing ahead and supply chain second, and the strongest supporting argument is that the stem asks for a risk the company can act on rather than a condition it merely inherits. Commenters favouring supply chain point out that a SaaS provider is a third party, which is true but describes a relationship rather than a control over data exposure. Several also flag the trap in open ports and services: it is the right answer for IaaS, where the customer builds and hardens the host, and the wrong one for SaaS, where it does not.

Official Reference

Exam Strategy

Match the control to the cloud model before answering: infrastructure hardening belongs to IaaS, so port and service answers are distractors the moment the stem says SaaS, leaving access and data governance as the customer's own responsibility.

Frequently Asked Questions

Why are open ports and services a SaaS distractor but an IaaS risk?

In IaaS the customer builds and hardens the host, so exposed ports and unused services are its own misconfiguration to fix; in SaaS the provider runs the OS and network layer, so it cannot close them.

Does focusing on access auditing replace vendor due diligence?

No. Auditing continuously governs access to the data, while due diligence such as SOC 2 reports, penetration test results, and right-to-audit clauses assesses the vendor during the contract.

Related Analysis

← Back to SY0-601 Study Guide