Which report best proves security controls over six months?
A hosting provider needs to prove that its security controls have been in place over the last six months and have sufficiently protected customer data. Which of the following would provide the best proof that the hosting provider has met the requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests understanding of audit reports and time-based evidence; the key trap is confusing a point-in-time compliance framework with an attestation of control effectiveness over a period.
For proving security controls have been in place and effective over six months, a SOC 2 Type 2 report is the accepted industry standard. Community consensus confirms that this report audits operating effectiveness over a period of time, unlike point-in-time assessments.
Choosing NIST CSF or CIS Top 20, which are frameworks or compliance checklists, not audit reports that prove control effectiveness over a defined period. A vulnerability report is also point-in-time and does not demonstrate ongoing control operation.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A SOC 2 Type 2 report provides an independent auditor's opinion on the operating effectiveness of a service organization's controls over a specified period, typically 6 to 12 months. This directly matches the hosting provider's need to prove that security controls have been in place and sufficiently protected customer data over the last six months.
Community comment [1] correctly explains that the report focuses on security, availability, processing integrity, confidentiality, and privacy, and demonstrates the effectiveness of controls over time. Comment [2] reinforces that it covers a specified period like six months or more and assess how well controls protect customer data.
Why the Other Options Are Wrong
NIST CSF is a voluntary framework for improving cybersecurity risk management, not an audit report. It can help organizations assess their own posture but does not provide independent proof of control effectiveness over a period.
CIS Top 20 compliance reports (likely referring to CIS Controls) are benchmarks or self-assessment checklists. They are not third-party attestations and do not provide a historical record of control operation.
A vulnerability report is a point-in-time snapshot of weaknesses. While useful for identifying vulnerabilities, it does not prove that the provider maintained specific controls throughout the preceding six months.
Community Comment Notes
All commenters unanimously vote for B, with the top comment detailing why SOC 2 Type 2 is the correct choice. No dissenting views were provided. The comments emphasize the time-based nature of the report, which is the critical distinction in this question.
Official Reference
Exam Strategy
When you see 'over the last six months' or 'prove controls have been in place', immediately look for an audit report that covers a period, not a framework or point-in-time scan. Remember SOC 2 Type 2 = operational effectiveness over time; Type 1 = design at a point in time.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →