Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security analyst is reviewing the organization's third-party risk management program. The organization recently onboarded a new SaaS provider that will process sensitive customer data. The provider has provided a SOC 2 Type II report, but the analyst notices that the report is over 18 months old and covers a different service than the one being used. Which of the following should the analyst recommend?

⚠ Common exam trap

The trap here is assuming that any SOC 2 report is sufficient, when in fact its recency and scope are critical for it to be meaningful for the specific service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request a current SOC 2 Type II report that specifically covers the service being used, or conduct an on-site assessment if one is not available.

Third-party risk management requires current and relevant assurance. A SOC 2 Type II report must be recent and cover the specific service in use. Requesting an updated report or conducting an on-site assessment ensures the organization has accurate information to assess the provider's controls. Other options rely on outdated, unverified, or inappropriate methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept the existing SOC 2 Type II report since it demonstrates the provider's overall security posture.

    Why it's wrong here

    A SOC 2 report that is 18 months old and covers a different service does not provide assurance for the current service. Security controls and environments change over time, and the report may not reflect current risks. Accepting it would leave the organization unaware of potential control gaps in the service actually being used, undermining third-party risk management.

  • ✓

    Request a current SOC 2 Type II report that specifically covers the service being used, or conduct an on-site assessment if one is not available.

    Why this is correct

    A SOC 2 Type II report must be current and scoped to the relevant service to provide assurance. An outdated report covering a different service is insufficient. Requesting an updated report or performing an on-site assessment ensures the organization obtains accurate, relevant information about the provider's controls, enabling informed risk decisions and compliance with due diligence requirements.

  • ✗

    Perform a penetration test against the provider's service to validate its security controls.

    Why it's wrong here

    Penetration testing without authorization is illegal and unethical. Even with authorization, a penetration test provides a point-in-time view of vulnerabilities, not a comprehensive assessment of the provider's control environment over time. It does not replace the need for a current SOC 2 report or an on-site assessment for third-party risk management.

  • ✗

    Rely on the provider's self-attestation of compliance with industry best practices.

    Why it's wrong here

    Self-attestation lacks independent verification and is generally considered weaker evidence than a third-party audit. The provider may have incentives to downplay risks, and without independent validation, the organization cannot be confident in the provider's controls. This approach does not meet the standard for due diligence when processing sensitive customer data.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.