ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 252 - SY0-601 discussion

Report
Export

A security practitioner is performing due diligence on a vendor that is being considered for cloud services. Which of the following should the practitioner consult for the best insight into the current security posture of the vendor?

A.
PCI DSS standards
Answers
A.
PCI DSS standards
B.
SLA contract
Answers
B.
SLA contract
C.
CSF framework
Answers
C.
CSF framework
D.
SOC 2 report
Answers
D.
SOC 2 report
Suggested answer: D

Explanation:

A SOC 2 report is a document that provides an independent assessment of a service organization’s controls related to the Trust Services Criteria of Security, Availability, Processing Integrity, Confidentiality, or Privacy. A SOC 2 report can help a security practitioner evaluate the current security posture of a vendor that provides cloud services1.

asked 02/10/2024
Shauqi Naufaldy
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first