SY0-701 - Security Program Management and Oversight - Section 5.5

Explain types and purposes of audits and assessments.

Distinguish internal audits from external audits and regulatory examinations, and explain how attestation formalises a responsible party's assertion that controls are operating effectively. Compare penetration testing and compliance assessments in terms of their objectives, recognising that penetration testing identifies exploitable weaknesses while a compliance assessment measures alignment with a specific standard or regulatory requirement.

internal vs external auditattestationpenetration testingcompliance assessmentregulatory examination

Practice question for this objective

Free sampleSecurity Program Management and Oversightmedium

A growing payments SaaS firm keeps losing enterprise deals because prospective customers and their own auditors will not accept the firm's word that its controls work. The chief information security officer needs evidence that is produced by parties independent of the firm's own staff, so that a buyer's audit team can rely on it without re-running its own review. Which TWO activities most directly deliver that independent, externally produced assurance about the firm's security controls? Select TWO.

  • ACommission a SOC 2 Type II report from a registered external audit firm that examines both the design and the operating effectiveness of the controls over a multi-month observation window. Correct
  • BEngage an independent external penetration testing firm under a signed rules-of-engagement document to attempt real, chained exploitation of the production platform and report the verified findings. Correct
  • CHave the firm's own internal audit team review the controls against an internal checklist and present the results to the firm's management committee each quarter.
  • DAsk the engineering team to complete a control self-assessment questionnaire and have the head of engineering sign it off before sending it to prospects.
  • EPublish the platform's availability dashboard showing monthly uptime percentages and incident response times for the hosted service to reassure prospects.
Independent control assurance for external buyers comes from third-party assessments such as a SOC 2 Type II attestation and an external penetration test, not internal or self-produced evidence. Buyers and their auditors need assurance produced by parties independent of the assessed firm. A SOC 2 Type II is an external attestation covering control operating effectiveness over a period, and an external penetration test independently verifies weaknesses through real exploitation. Internal audit and a signed self-assessment are produced inside the firm and lack that independence, while an availability dashboard measures uptime rather than control effectiveness.

Why A is correct: A SOC 2 Type II is an attestation produced by an independent external auditor over a defined period, so a buyer's audit team can rely on it as third-party evidence rather than the firm's own assurances about its controls.

Why B is correct: An external penetration test is performed by a party independent of the firm and demonstrates control weaknesses through real exploitation, giving buyers third-party evidence of effectiveness that an internal claim cannot match.

Why C is wrong: Internal audit is genuinely useful and feels rigorous, but it is staffed and reported inside the firm, so an external buyer cannot treat its conclusions as the independent assurance the customers are demanding.

Why D is wrong: A self-assessment looks like evidence because it is documented and signed, but it is produced and attested by the very team being assessed, so it carries none of the independence a buyer's auditors require.

Why E is wrong: An uptime dashboard is tempting because it is objective public data, but it reports service availability rather than assessing security controls, so it answers a different question than the assurance the buyers are seeking.

See more SY0-701 practice questions, answers explained.

More in this domain

Back to all Security Program Management and Oversight objectives, or the SY0-701 cert hub.

Examworthy is not affiliated with or endorsed by CompTIA. Original, blueprint-aligned practice material only.