Certified Cloud Security Professional – CCSP – Question453

Which kind of SSAE audit report is most beneficial for a cloud customer, even though it’s unlikely the cloud provider will share it?

A.
SOC 3
B. SOC 1 Type 2
C. SOC 2 Type 2
D. SOC 1 Type 1

Correct Answer: C

Explanation:

Explanation: The SOC 3 is the least detailed, so the provider is not concerned about revealing it. The SOC 1 Types 1 and 2 are about financial reporting and not relevant. The SOC 2 Type 2 is much more detailed and will most likely be kept closely held by the provider.