What Process Involves Requesting a SOC 2 Report from a SaaS Vendor?
A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between due diligence, attestation, and internal audit; the common trap is confusing the vendor's SOC 2 report (an attestation) with the analyst's own evaluation process (due diligence).
When evaluating a SaaS application, requesting a SOC 2 report is a key part of due diligence. This process helps assess a vendor's security, availability, processing integrity, confidentiality, and privacy controls before implementation.
Choosing C. Attestation is the most common mistake because SOC 2 is itself an attestation report. However, the question asks what the analyst is conducting by requesting the report—that is due diligence, not the attestation itself.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
D. Due diligence is correct because the analyst is evaluating a third-party SaaS vendor before implementation. Requesting a SOC 2 report is a standard vendor risk assessment step to verify that the vendor has adequate controls.
As comment [1] explains, due diligence involves evaluating security, compliance, and risk associated with a third-party vendor, and a SOC 2 report is used to assess controls related to security, availability, processing integrity, confidentiality, and privacy.
Comment [2] reinforces that due diligence verifies various aspects including security, compliance, and risks, and the analyst is performing this by asking for the SOC 2 report to make an informed decision.
Comment [3] notes that vendor selection should consider due diligence, historical performance, and commitment to security, matching the scenario exactly.
Why the Other Options Are Wrong
A. Internal audit is incorrect because internal audits are conducted by an organization's own audit function on its own processes, not by a customer evaluating a vendor.
B. Penetration testing is incorrect because that would involve actively attempting to exploit vulnerabilities, while the scenario describes a passive review of a compliance report.
C. Attestation is incorrect because while a SOC 2 report is an attestation, the analyst is not performing the attestation—the vendor or a third-party auditor does that. The analyst is using the report as part of due diligence.
Community Comment Notes
The community overwhelmingly supports D, with all votes for D. Comment [1] provides the most detailed reasoning and aligns with the official definition of due diligence. Comments [2] and [3] add practical context, emphasizing that a SOC 2 report is a common tool for vendor risk assessment. No comments support other options, confirming the correct answer.
Official Reference
Exam Strategy
When you see a question asking what the analyst is doing by requesting a report, focus on the action and purpose, not the report itself. Memorize that due diligence is the vendor evaluation process, while attestation refers to the independent audit report produced by the vendor's auditor.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →