CAS-004 Governance, Risk, and Compliance Practice Question
A company is conducting a vendor risk assessment and receives a SOC 2 Type II report from a cloud service provider. The report covers a 12-month period and includes an opinion on the effectiveness of controls. Which of the following is the primary benefit of using this report?
⚠ Common exam trap
The trap is overstating what SOC 2 provides — candidates pick A (guarantees compliance) or D (real-time monitoring) because they conflate attestation with certification or continuous monitoring, but SOC 2 is a periodic, independent opinion on control effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It offers an independent assessment of control effectiveness over time
A SOC 2 Type II report provides an independent auditor's opinion on the effectiveness of a service organization's controls over a period of time (here, 12 months). This temporal coverage is the key benefit: it demonstrates that controls operated effectively throughout the period, not just on a single date. For vendor risk assessment, this gives assurance about sustained control performance rather than a point-in-time snapshot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It guarantees the vendor is compliant with all regulations
Why it's wrong here
A SOC 2 Type II report provides an independent auditor's opinion on control effectiveness over a period, giving assurance about the vendor's security practices. It does not guarantee regulatory compliance, since SOC 2 criteria differ from legal frameworks such as GDPR or HIPAA. It is tempting because it evidences strong controls, but it would be the right artefact only when assessing control design and operating effectiveness, not regulatory conformance.
- ✓
It offers an independent assessment of control effectiveness over time
Why this is correct
A SOC 2 Type II report tests controls across a defined audit period rather than a single point in time, so the auditor's opinion addresses whether controls operated effectively throughout those 12 months. This satisfies the vendor risk assessment's need for evidence of sustained control performance.
- ✗
It eliminates the need for a right-to-audit clause
Why it's wrong here
A SOC 2 report evidences the vendor's control environment; it does not transfer audit rights or remove the need to verify controls yourself. Right-to-audit clauses grant contractual permission to inspect, which a third-party attestation cannot confer. It is tempting because the report reduces direct testing, but it supplements rather than replaces that clause.
- ✗
It provides real-time monitoring data from the vendor
Why it's wrong here
Real-time telemetry comes from monitoring tooling such as CloudWatch or the vendor's status dashboard, not from an attestation report. A SOC 2 Type II report gives a historical, point-in-time opinion over a 12-month period, so it cannot supply live data. It is tempting because continuous assurance is a genuine vendor-risk goal, but that requires contractual monitoring rights.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.