SaaS SaaS Security and Compliance 2 — Questions and Answers
Question 1: What is a SOC 2 Type I report?
- An audit covering controls over a minimum 6-month period
- A snapshot audit confirming that controls are suitably designed at a specific point in time (Correct answer)
- A penetration test report
- A certification for cloud infrastructure providers only
Correct answer: A snapshot audit confirming that controls are suitably designed at a specific point in time
SOC 2 Type I evaluates whether a vendor's security controls are suitably designed at a specific point in time, unlike Type II which tests effectiveness over a period.
Question 2: What does CASB stand for in SaaS security?
- Cloud Access Security Broker (Correct answer)
- Centralized Application Security Baseline
- Compliance and Security Benchmarking
- Cloud Application Security Bridge
Correct answer: Cloud Access Security Broker
A Cloud Access Security Broker (CASB) sits between users and SaaS providers to enforce security policies, visibility, and compliance.
Question 3: Which of the following is a key component of Zero Trust security for SaaS environments?
- Trusting all traffic inside the corporate VPN
- Never trust, always verify — requiring authentication for every access request (Correct answer)
- Blocking all third-party SaaS integrations
- Relying solely on perimeter firewalls
Correct answer: Never trust, always verify — requiring authentication for every access request
Zero Trust requires continuous verification of every user and device regardless of location, eliminating the concept of a trusted internal network.
Question 4: What is data loss prevention (DLP) in the context of SaaS?
- A backup system that prevents data from being lost during outages
- Technology that detects and prevents unauthorized sharing or exfiltration of sensitive data (Correct answer)
- A redundancy mechanism that replicates data across multiple data centers
- An encryption tool for SaaS API communications
Correct answer: Technology that detects and prevents unauthorized sharing or exfiltration of sensitive data
DLP in SaaS detects and prevents users from sharing, uploading, or exfiltrating sensitive data in unauthorized ways.
Question 5: What is the purpose of a vulnerability disclosure policy (VDP) for a SaaS company?
- To define how the company discloses its own security breaches to customers
- To establish a process for security researchers to report vulnerabilities responsibly (Correct answer)
- To outline the company's patch deployment schedule
- To list all known software vulnerabilities in a public registry
Correct answer: To establish a process for security researchers to report vulnerabilities responsibly
A VDP provides a clear, safe channel for security researchers to report discovered vulnerabilities to the SaaS company without fear of legal action.
Question 6: Which US law requires publicly traded SaaS companies to disclose material cybersecurity incidents to investors?
- CCPA
- SEC Cybersecurity Disclosure Rules (Correct answer)
- FISMA
- NIST CSF
Correct answer: SEC Cybersecurity Disclosure Rules
The SEC's 2023 cybersecurity disclosure rules require publicly traded companies, including SaaS firms, to report material cybersecurity incidents within four business days.
What is a SOC 2 Type I report?