CAS-004 Governance, Risk, and Compliance Practice Question
A financial institution is evaluating a cloud service provider for hosting customer data. During the due diligence process, which report would best help the institution assess the provider's control environment and compliance with SOC 2?
⚠ Common exam trap
CAS-005 often tests the distinction between SOC 2 Type I (design at a point in time) and Type II (operating effectiveness over time), and candidates frequently pick ISO 27001 or a pentest report as equivalent evidence when the question specifically asks about SOC 2 compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SOC 2 Type II report
A SOC 2 Type II report is the correct choice because it provides an independent auditor's opinion on the design AND operating effectiveness of a service provider's controls over a period of time (typically 3-12 months). This directly addresses the financial institution's need to assess the provider's control environment and SOC 2 compliance. Type II is specifically designed for vendor due diligence where evidence of sustained control operation is required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SOC 2 Type II report
Why this is correct
A SOC 2 Type II report covers the design and operating effectiveness of controls over a review period, giving evidence that the provider's control environment actually functioned. Type I only assesses design at a point in time, so it cannot demonstrate sustained SOC 2 compliance during due diligence.
- ✗
ISO 27001 certificate
Why it's wrong here
An ISO 27001 certificate attests to an information security management system, not to the SOC 2 Trust Services Criteria control environment the institution must assess. It is tempting as a recognised security credential, and would be correct where the requirement is ISMS certification rather than SOC 2 reporting.
- ✗
Penetration test report
Why it's wrong here
A penetration test report documents point-in-time exploitation findings against specific targets, not the design and operating effectiveness of controls over a period. It is tempting because it evidences security testing, but SOC 2 assurance requires a service auditor's report covering the trust services criteria.
- ✗
Vulnerability scan results
Why it's wrong here
Vulnerability scan results list technical weaknesses at a point in time; they do not describe the provider's control environment or SOC 2 compliance. They are tempting as concrete security evidence, and would be correct when assessing patch status or technical exposure rather than control design and operation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.