SY0-701 Security Program Management and Oversight Practice Question
Procurement is reviewing a new payroll SaaS provider. The business wants independent evidence that the vendor's controls were designed and operating effectively over the last six months. Which document should the security team request?
⚠ Common exam trap
A common mix-up: candidates confuse a SOC 2 Type I (design only) with Type II (design and operating effectiveness over time), or mistakenly think a patch list or pentest result provides equivalent assurance for ongoing control effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A SOC 2 Type II report from an independent auditor.
A SOC 2 Type II report provides independent assurance that a service organization's controls are not only designed appropriately (Type I) but also operating effectively over a specified period, typically six to twelve months. This aligns directly with the procurement team's requirement for evidence of control effectiveness over the last six months, making it the correct choice for evaluating a SaaS vendor's security posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A SOC 2 Type II report from an independent auditor.
Why this is correct
A SOC 2 Type II report is designed to show both the design and operating effectiveness of controls over a period of time. That makes it especially useful for assessing an ongoing SaaS provider relationship. It gives procurement and security an independent assurance artifact that can support vendor due diligence and third-party risk review.
- ✗
A software patch list showing recent updates installed on the vendor's servers.
Why it's wrong here
A software patch list only reflects the vendor's claimed remediation activity at a single point in time; it provides no independent verification that the control environment is designed properly or that controls operated effectively over the audit period. Patch management is just one operational task, and the list does not demonstrate how the vendor protects sensitive payroll data through access controls, encryption, or change management. Without a third-party attestation, procurement cannot rely on it as a basis for evaluating the SaaS provider's overall security posture.
- ✗
A penetration test screenshot showing one web application vulnerability was fixed.
Why it's wrong here
A penetration test screenshot showing a single vulnerability fixed is an unreliable form of evidence because it lacks the full report's scope, methodology, and remediation verification. It tells procurement only that one specific finding was addressed, not that the vendor's broader control set—such as security monitoring, incident response, and logical access controls—is effective over time. A point-in-time screenshot also cannot attest to the operating effectiveness of controls that protect payroll data continuously.
- ✗
An internal email from the vendor's security manager stating that controls are mature.
Why it's wrong here
An internal email from the vendor's security manager is a self-assertion that carries no independent assurance because the vendor has a financial interest in the deal. It does not reference any objective criteria, audit methodology, or evidence of control testing, and there is no third-party verification. Procurement should require an independent auditor's report, not an unverified opinion from the vendor's own staff.
Go deeper
Related to this question
Learn chapter
Security Policies and Procedures
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Security posture
An organization's overall cybersecurity strength, including policies, controls, and readiness to defend against and respond to threats.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.