A security analyst is evaluating a SaaS application that the human resources department would like to implement. The analyst requests a SOC 2 report from the SaaS vendor. Which of the following processes is the analyst most likely conducting?
Choose an answer
Tap an option to check your answer.
Correct answer: Due diligence.
Why this is the answer
The analyst is performing due diligence by requesting a SOC 2 report. Due diligence involves taking reasonable steps to avoid harm to other persons or their property, often by performing research and investigation before entering into an agreement or making a decision. In this context, the analyst is investigating the security posture of a third-party SaaS vendor to ensure it meets the organization's security requirements before implementation. An internal audit is an independent assessment performed by an organization's own staff. Penetration testing involves actively exploiting vulnerabilities to test security controls. Attestation is the act of providing a formal statement or testimony that something is true, which the SOC 2 report itself is, but the analyst's action of requesting it is due diligence.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed