5.5 Explain types and purposes of audits and assessments
Objective 5.5 sits in Security Program Management and Oversight, which carries 20% of the Security+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.
Objective title verbatim from the official objectives. CompTIA exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
Which type of audit demonstrates that an independent assessor validated a cloud provider's controls against a specific regulatory framework such as FedRAMP?
The concept
The weight a compliance claim carries depends on who produced it. A review run by the same organization that built the system is useful for finding problems and worth nothing as proof to a customer, because the reviewer answers to the party being reviewed. Independence is the property that makes a finding transferable, which is why frameworks customers are meant to rely on all require an accredited third party to do the assessment.
Why this answer
Validation against FedRAMP by an outside assessor is, by definition, an external audit.
- Correct. Independence is what makes the finding usable by customers.
- BSame organization, same reporting line. A customer has no reason to treat the conclusion as impartial.
- CCovers one flaw a researcher happened to find. Silent on the control set as a whole.
- DThe scoping agreement signed before a test begins, not a result anyone can be shown.
Now you: objective 5.5 questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A company's own compliance team reviews the security control framework every quarter and reports the results directly to the chief information security officer, without engaging any outside firm. Which audit type does this describe?
Sample question 2 of 3
A cloud provider hires an independent CPA firm to test its controls over a six month period. The firm then issues a SOC 2 report that customers can rely on as proof of compliance. What is the SOC 2 report itself best described as?
Sample question 3 of 3
A researcher privately reports a vulnerability to a vendor. After six months with no patch or response, the researcher publishes full technical details, including exploit code, to force action. Which disclosure approach is this?
That’s 3 of the full Security+ bank.
Keep going free: 10 questions per certification in bank practice, with no account.
Continue practicingRead the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.
More objectives in Security Program Management and Oversight
- 5.1 5.1 Summarize elements of effective security governance
- 5.2 5.2 Explain elements of the risk management process
- 5.3 5.3 Explain the processes associated with third-party risk assessment and management
- 5.4 5.4 Summarize elements of effective security compliance
- 5.6 5.6 Given a scenario, implement security awareness practices