Courseiva
mediumMultiple ChoiceObjective-mapped

Verifying Current Security Controls Beyond SOC 2 Type II

A company is evaluating a new cloud service provider. The provider has a SOC 2 Type II report covering the previous year. Which additional assurance should the company request to verify the provider's current security controls?

Quick Answer

The answer is to request a penetration test report covering the current year. This is correct because a SOC 2 Type II report, while valuable, only validates controls over a historical period—typically the prior year—and does not guarantee that the same security posture exists today. A current penetration test provides independent, active validation of the provider’s existing controls, identifying exploitable vulnerabilities that a static report cannot reveal. On the CompTIA SecurityX CAS-004 exam, this question tests your ability to distinguish between assurance types: a SOC 2 Type II is a point-in-time audit, whereas a penetration test offers real-time evidence. A common trap is choosing the SOC 2 Type II itself, but remember that historical reports cannot verify current security. Memory tip: “Past reports prove past performance; a pen test proves present protection.”

⚠ Common exam trap

The CASP+ exam often tests the distinction between historical assurance (SOC 2 Type II) and current assurance (penetration test), tempting candidates to accept the SOC 2 report as sufficient or to propose continuous monitoring, which is impractical without direct access to the provider's systems.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Request a penetration test report covering the current year

A SOC 2 Type II report provides assurance over controls in place during a historical period (the previous year), but it does not guarantee that those controls remain effective today. Requesting a current-year penetration test report (Option C) gives the company direct, timely evidence of the provider's security posture, including any vulnerabilities that may have emerged since the SOC 2 audit period ended.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the SOC 2 report as sufficient

    Why it's wrong here

    The report is historical and may not reflect current state.

  • Implement continuous monitoring of the provider

    Why it's wrong here

    Continuous monitoring is an internal process, not an assurance request.

  • Request a penetration test report covering the current year

    Why this is correct

    Provides current assessment of security posture.

  • Request a third-party audit of the SOC 2 report

    Why it's wrong here

    SOC 2 is already performed by a third party.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CAS-005

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is evaluating a vendor that will process sensitive customer data. The vendor's SOC 2 Type II report shows that controls were in place but had several exceptions noted. Which of the following is the BEST course of action?

medium
  • A.Perform a risk assessment on the exceptions
  • B.Request a SOC 2 Type I report instead
  • C.Accept the vendor because it has a Type II report
  • D.Reject the vendor immediately due to exceptions

Why A: A SOC 2 Type II report with exceptions indicates that controls were tested over a period and found to have gaps. The best course is to perform a risk assessment on the exceptions to evaluate their severity, impact on confidentiality, integrity, or availability of sensitive data, and determine if compensating controls or remediation plans are acceptable. This aligns with the risk management framework required for vendor due diligence under compliance standards like GDPR or PCI DSS.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.