CAS-004 Governance, Risk, and Compliance Practice Question
An organization is evaluating a third-party vendor that will have access to its customer database. The vendor provides a SOC 2 Type II report dated six months ago. Which of the following is the BEST next step?
⚠ Common exam trap
CAS-005 often tests the misconception that a SOC 2 report alone satisfies vendor due diligence, when in fact it is an input to—not a replacement for—a risk-based assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a vendor risk assessment using a security questionnaire
Even with a recent SOC 2 Type II report, the organization should still perform its own vendor risk assessment using a security questionnaire to evaluate controls specific to the engagement, scope, and data sensitivity. A SOC 2 report covers the vendor's controls but does not address the organization's specific risk tolerance, contractual requirements, or gaps not in the report's scope. This is the best next step because it validates and contextualizes the report.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a vendor risk assessment using a security questionnaire
Why this is correct
A SOC 2 Type II report covers controls over a period, but it is six months old and may not address your specific data flows. A risk assessment using a security questionnaire gathers current, scenario-specific evidence about how the vendor protects your customer database.
- ✗
Accept the SOC 2 report as sufficient evidence
Why it's wrong here
A six-month-old SOC 2 Type II covers a historical period, so it cannot evidence controls operating today, and the report's scope may not address the customer database access. Accepting it outright is tempting because Type II reports are the standard vendor assurance artefact when current and scoped to the relevant services.
- ✗
Perform an on-site audit of the vendor
Why it's wrong here
An on-site audit duplicates assurance the SOC 2 Type II already provides through an independent CPA firm, and the stem gives no indication the report's scope or period is deficient. On-site audits suit vendors lacking independent attestation, or when contractual or regulatory obligations demand direct verification beyond a third-party report.
- ✗
Request a new penetration test report from the vendor
Why it's wrong here
A penetration test probes for exploitable vulnerabilities at a point in time; it does not attest to the vendor's ongoing security controls, which is what the SOC 2 Type II already evidences. Penetration test reports are the right artefact when assessing a specific system's technical attack surface, not for validating organisational control effectiveness.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.