Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?

⚠ Common exam trap

CAS-005 often tests the Type I vs Type II distinction — candidates pick 'point-in-time snapshot' thinking it sounds rigorous, but that describes Type I, not Type II.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides assurance over the design and operating effectiveness of controls over a period.

A SOC 2 Type II report provides assurance over the design and operating effectiveness of a service organization's controls over a specified period, typically 3–12 months. This period-based testing distinguishes it from Type I, which only assesses design at a point in time. For vendor risk management, Type II gives the analyst evidence that controls actually operated effectively throughout the audit window.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It provides assurance over the design and operating effectiveness of controls over a period.

    Why this is correct

    A SOC 2 Type II report covers an audit period, not a single point in time, so it evidences that controls were designed and actually operated effectively throughout that window. This lets the analyst judge sustained control performance rather than relying on a Type I snapshot.

  • ✗

    It offers a snapshot of the vendor's security posture at a single point in time.

    Why it's wrong here

    Type II evaluates control effectiveness across an audit period, whereas a point-in-time snapshot describes Type I. It is tempting because Type I reports do capture posture at a single date, and would be the correct artefact when only design suitability at one moment matters.

  • ✗

    It provides a real-time vulnerability scan of the vendor's network.

    Why it's wrong here

    A SOC 2 Type II report covers controls over a period, not live scanning, so it cannot deliver real-time vulnerability findings. It is tempting because continuous vulnerability scanning is a genuine security control, and would be the right evidence source when assessing a vendor's current technical weaknesses.

  • ✗

    It verifies the vendor's compliance with PCI DSS.

    Why it's wrong here

    SOC 2 reports against Trust Services Criteria, not the PCI DSS standard, so it does not verify cardholder-data compliance. It is tempting because PCI DSS attestation is the correct evidence when a vendor handles payment card data and that framework is the assessment scope.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.