Certified Cloud Security Professional (CCSP) — Question 441
Which kind of SSAE audit report is most beneficial for a cloud customer, even though it's unlikely the cloud provider will share it?
Answer options
- A. SOC 3
- B. SOC 1 Type 2
- C. SOC 2 Type 2
- D. SOC 1 Type 1
Correct answer: C
Explanation
The SOC 2 Type 2 report is specifically designed to provide detailed information about a service provider's controls related to security, availability, processing integrity, confidentiality, and privacy over an extended period. This makes it particularly valuable for cloud customers assessing the provider's operational effectiveness. The other options do not offer the same depth of information regarding the controls relevant to cloud services.