What Process Involves Requesting a SOC 2 Report from a SaaS Vendor?

A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?

  1. Internal audit
  2. Penetration testing
  3. Attestation
  4. Due diligence Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the distinction between due diligence, attestation, and internal audit; the common trap is confusing the vendor's SOC 2 report (an attestation) with the analyst's own evaluation process (due diligence).

When evaluating a SaaS application, requesting a SOC 2 report is a key part of due diligence. This process helps assess a vendor's security, availability, processing integrity, confidentiality, and privacy controls before implementation.

Choosing C. Attestation is the most common mistake because SOC 2 is itself an attestation report. However, the question asks what the analyst is conducting by requesting the report—that is due diligence, not the attestation itself.

Community Discussion (4 comments)

cri88 👍 8 Selected: D
D. Due diligence In this context, due diligence refers to the process of evaluating the security, compliance, and risk associated with a third-party vendor or service, such as a SaaS application. Requesting a SOC 2 report is a common part of the due diligence process to assess the vendor's controls related to security, availability, processing integrity, confidentiality, and privacy. Internal audit (A) refers to an organization's internal review of its own processes, not an external vendor. Penetration testing (B) involves actively testing for vulnerabilities by simulating attacks, which is not applicable here. Attestation (C) refers to a third-party audit or certification, such as the SOC 2 report itself, but the analyst is conducting due diligence by requesting the report.
9149f41 👍 1 Selected: D
Due Diligence is a type of practice. it verify and assess various aspects, including security, compliance, and risks. The security analyst is performing due diligence by asking for a SOC 2 report from the SaaS vendor to make an informed decision.
PAWarriors 👍 1 Selected: D
Security challenges with Software-as-a-Service (SaaS) providers --> Vendor selection should consider due diligence, historical performance and commitment to security
Cee007 👍 1 Selected: D
D. Due diligence Due diligence in this context involves evaluating the security, availability, processing integrity, confidentiality, and privacy of the SaaS application by reviewing the SOC 2 report provided by the vendor. This process helps ensure that the vendor meets the required security and operational standards before the SaaS application is implemented.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

D. Due diligence is correct because the analyst is evaluating a third-party SaaS vendor before implementation. Requesting a SOC 2 report is a standard vendor risk assessment step to verify that the vendor has adequate controls.

As comment [1] explains, due diligence involves evaluating security, compliance, and risk associated with a third-party vendor, and a SOC 2 report is used to assess controls related to security, availability, processing integrity, confidentiality, and privacy.

Comment [2] reinforces that due diligence verifies various aspects including security, compliance, and risks, and the analyst is performing this by asking for the SOC 2 report to make an informed decision.

Comment [3] notes that vendor selection should consider due diligence, historical performance, and commitment to security, matching the scenario exactly.

Why the Other Options Are Wrong

A. Internal audit is incorrect because internal audits are conducted by an organization's own audit function on its own processes, not by a customer evaluating a vendor.

B. Penetration testing is incorrect because that would involve actively attempting to exploit vulnerabilities, while the scenario describes a passive review of a compliance report.

C. Attestation is incorrect because while a SOC 2 report is an attestation, the analyst is not performing the attestation—the vendor or a third-party auditor does that. The analyst is using the report as part of due diligence.

Community Comment Notes

The community overwhelmingly supports D, with all votes for D. Comment [1] provides the most detailed reasoning and aligns with the official definition of due diligence. Comments [2] and [3] add practical context, emphasizing that a SOC 2 report is a common tool for vendor risk assessment. No comments support other options, confirming the correct answer.

Official Reference

Exam Strategy

When you see a question asking what the analyst is doing by requesting a report, focus on the action and purpose, not the report itself. Memorize that due diligence is the vendor evaluation process, while attestation refers to the independent audit report produced by the vendor's auditor.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide