CAS-004 Governance, Risk, and Compliance Practice Question
During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?
⚠ Common exam trap
CAS-005 often tests the Type I vs Type II distinction — candidates pick 'point-in-time snapshot' thinking it sounds rigorous, but that describes Type I, not Type II.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides assurance over the design and operating effectiveness of controls over a period.
A SOC 2 Type II report provides assurance over the design and operating effectiveness of a service organization's controls over a specified period, typically 3–12 months. This period-based testing distinguishes it from Type I, which only assesses design at a point in time. For vendor risk management, Type II gives the analyst evidence that controls actually operated effectively throughout the audit window.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It provides assurance over the design and operating effectiveness of controls over a period.
Why this is correct
A SOC 2 Type II report covers an audit period, not a single point in time, so it evidences that controls were designed and actually operated effectively throughout that window. This lets the analyst judge sustained control performance rather than relying on a Type I snapshot.
- ✗
It offers a snapshot of the vendor's security posture at a single point in time.
Why it's wrong here
Type II evaluates control effectiveness across an audit period, whereas a point-in-time snapshot describes Type I. It is tempting because Type I reports do capture posture at a single date, and would be the correct artefact when only design suitability at one moment matters.
- ✗
It provides a real-time vulnerability scan of the vendor's network.
Why it's wrong here
A SOC 2 Type II report covers controls over a period, not live scanning, so it cannot deliver real-time vulnerability findings. It is tempting because continuous vulnerability scanning is a genuine security control, and would be the right evidence source when assessing a vendor's current technical weaknesses.
- ✗
It verifies the vendor's compliance with PCI DSS.
Why it's wrong here
SOC 2 reports against Trust Services Criteria, not the PCI DSS standard, so it does not verify cardholder-data compliance. It is tempting because PCI DSS attestation is the correct evidence when a vendor handles payment card data and that framework is the assessment scope.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.