Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 169 discussion

Actual exam question from ISC's CISSP
Question #: 169
Topic #: 1
[All CISSP Questions]

Which security audit standard provides the BEST way for an organization to understand a vendor's Information Systems (IS) in relation to confidentiality, integrity, and availability?

  • A. Service Organization Control (SOC) 2
  • B. Statement on Standards for Attestation Engagements (SSAE) 18
  • C. Statement on Auditing Standards (SAS) 70
  • D. Service Organization Control (SOC) 1
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
[Removed]
Highly Voted 2 years, 2 months ago
Selected Answer: A
Soc 2 for sure
upvoted 8 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
Rollizo
Highly Voted 2 years, 1 month ago
Selected Answer: A
SOC1 it is only financial... it is SOC2
upvoted 5 times
...
Jarn
Most Recent 5 months, 2 weeks ago
Selected Answer: B
SSAE 18 is the standard, which is what the question is looking for.
upvoted 1 times
...
klarak
7 months, 1 week ago
SSAE 18 seems to be the answer here: https://reciprocity.com/resources/what-is-a-ssae-18-audit/
upvoted 1 times
...
eboehm
7 months, 2 weeks ago
ugh I really dont like questions like this. Technically based on the wording the true answer is that it would be SSAE 18 as this defines how the SOC reports are generated. But the question is would a CEO/manager give a shit what standard was being using or would they just want the SOC 2 report
upvoted 1 times
eboehm
7 months, 2 weeks ago
Even though the officially correct answer is SSAE 18. The organization is concernted with the controls so ima go with SOC 2. SSAE 18 applies to all 3 reports. That would be the CEO answer. You would be in a world of hurt if a ceo for the audit standard to achieve confidentiality, integrity, and availability and you were like well actually the standard is defining 3 reports
upvoted 1 times
...
...
dm808
8 months ago
Selected Answer: B
The question is asking about an auditing standard SSAE 18 is a standard. SOC 1 an 2 are reports.. and SOC reports are defined in the SSAE 18
upvoted 1 times
...
YesPlease
11 months, 2 weeks ago
Selected Answer: A
Answer A) Service Organization Control (SOC) 2 The other three refer to financial standards. https://ssae-16.com/soc-1/#:~:text=The%20SOC1%20Report%20is%20what,of%20May%201%2C%202017).
upvoted 1 times
...
7f7b53c
12 months ago
B. Soc is not a standard
upvoted 1 times
...
Dann108
1 year, 2 months ago
Selected Answer: A
SOC 2 is a voluntary compliance standard for service organizations,
upvoted 1 times
...
MShaaban
1 year, 3 months ago
It is A.
upvoted 1 times
...
HughJassole
1 year, 5 months ago
Answer is B, the question clearly states "standard". The SSAE 18 is a standard that is used to generate the SOC2 report. "The Statement on Standards for Attestation Engagements 18, or SSAE 18, is a standard that auditors can use to review the controls of technology vendors and other service providers so that businesses using those vendors can be confident that the vendors’ controls-particularly those related to cybersecurity" https://reciprocity.com/understanding-ssae-18-requirements/
upvoted 1 times
...
RVoigt
1 year, 9 months ago
Selected Answer: A
CISSP Official Study Guide pg 729 - "SOC 2 Engagements Assess the organization's controls that affect the security (confidentiality, integrity, and availability) and privacy of information stored in a system. SOC 2 audit results are confidential and are normally only shared outside the organization under an NDA."
upvoted 3 times
...
ST811
1 year, 10 months ago
Why A? SOC2 should be confidential
upvoted 1 times
...
somkiatr
1 year, 10 months ago
Selected Answer: B
B (SSAE) would be correct. Reference : https://www.advancedbusinesssolutions.com/whats-a-soc-compliant-service-provider/
upvoted 3 times
...
Ivanchun
1 year, 11 months ago
Selected Answer: A
Select A, SOC 1 is about the financial report?
upvoted 1 times
...
Petergriffith
1 year, 12 months ago
Definitely A... SOC 2 provides, CIA + Privacy + Process Integrity + Security (Data Loss etc.)
upvoted 1 times
...
Firedragon
2 years ago
Selected Answer: B
B. The question asks "security audit standard". Among the 4 answers, only ssae 18 is a Generally Accepted Auditing Standard. SOC1, SOC2 and SAS70 are all report types. https://www.esgthereport.com/what-are-ssae-18-standards/ SSAE 18 is an AICPA standard that provides guidelines for evaluating the effectiveness of information security, availability, processing integrity, confidentiality, and privacy controls in cloud computing services.
upvoted 4 times
somkiatr
1 year, 10 months ago
Agreed.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...