Courseiva

SSCP Security Operations and Administration Practice Question

A healthcare organization's security team is reviewing a third-party cloud provider that will store electronic protected health information. The provider's SOC 2 Type II report is two years old, and the provider has since migrated to a new data center. Which action should the security administrator take FIRST to determine whether the provider still meets the organization's security requirements?

⚠ Common exam trap

The trap here is assuming that any SOC 2 Type II report satisfies due diligence regardless of its age or the scope of systems it covered.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request the provider's current SOC 2 Type II report or bridge letter covering the new data center period.

A SOC 2 Type II report is point-in-time evidence covering a defined audit period and specific systems. Because the provider migrated to a new data center after the report was issued, the prior opinion does not cover the current environment. Requesting an updated report or a bridge letter is the correct first action because it provides current, independent assurance before the organization makes contractual or technical decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Request the provider's current SOC 2 Type II report or bridge letter covering the new data center period.

    Why this is correct

    A SOC 2 Type II report covers a historical period, and the migration to a new data center means the controls assessed in the old report may no longer be representative. Requesting an updated report or a bridge letter that covers the gap is the appropriate first step because it gives current, independent evidence of control effectiveness before any contractual or technical decisions are made.

  • ✗

    Immediately terminate the contract and select a new cloud provider with a current SOC 2 report.

    Why it's wrong here

    Terminating the contract without first gathering current evidence is premature and disruptive. The provider may have a valid current report or bridge letter that addresses the data center migration. SSCP guidance emphasizes due diligence and risk-based decision making, so the administrator should assess the actual control status before taking drastic contractual action that could disrupt patient services.

  • ✗

    Accept the existing SOC 2 Type II report because it demonstrates the provider has a mature security program.

    Why it's wrong here

    A two-year-old report covering a previous data center does not provide assurance about the current environment. Controls, personnel, and infrastructure may have changed significantly during migration. Relying on stale audit evidence creates an unverified risk assumption. The administrator should obtain current evidence rather than assuming the provider's security posture remained unchanged after a major infrastructure move.

  • ✗

    Perform a full penetration test of the provider's new data center without notifying the provider.

    Why it's wrong here

    Unauthorized penetration testing of a third-party environment is unethical, likely illegal, and violates the provider's acceptable use and contractual terms. Even if the goal is to validate controls, testing must be explicitly authorized in writing. The first step should be obtaining existing audit documentation, not conducting unauthorized offensive testing against infrastructure the organization does not own or control.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.