Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam SY0-601 topic 1 question 853 discussion

Actual exam question from CompTIA's SY0-601
Question #: 853
Topic #: 1
[All SY0-601 Questions]

Which of the following security program audits includes a comprehensive evaluation of the security controls in place at an organization over a six- to 12-month time period?

  • A. NIST CSF
  • B. SOC 2 Type II
  • C. ISO 27001
  • D. PCI DSS
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ekiel
1 month ago
Selected Answer: B
SOC 2 TYPE 1 and 2 Report • SOC 2 - Trust Services Criteria (security controls) – Firewalls, intrusion detection, and multi-factor authentication • Type I audit – Tests controls in place at a particular point in time • Type II – Tests controls over a period of at least six consecutive months
upvoted 1 times
...
Ravnit
1 month ago
Selected Answer: B
SOC 2 Type II audits involve a comprehensive evaluation of an organization's security controls over a specified period, typically six to 12 months
upvoted 2 times
...
Ravnit
1 month ago
B is right SOC 2 Type II audits involve a comprehensive evaluation of an organization's security controls over a specified period, typically six to 12 months.
upvoted 2 times
...
CircaG
1 month ago
Selected Answer: B
B. SOC 2 (Service Organization Control 2) Type II audits are conducted over a period of time (typically six to 12 months) and provide a comprehensive evaluation of the security controls and processes implemented by a service organization. This audit assesses the effectiveness of controls related to security, availability, processing integrity, confidentiality, and privacy. The Type II designation indicates that the audit covers a specific timeframe and provides an evaluation of the operational effectiveness of controls over that period.
upvoted 1 times
...
paCer66
1 month ago
B seems to be correct.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...