Reasoning: B is operational, not a compliance artifact.
Conclusion: B is correct.
OCI documentation lists “compliance documents like certificates (A), attestations (C), and bridge letters (D) for standards like SOC or ISO; penetration test reports (B) are security assessments, not formal compliance docs.” Only B stands apart per OCI’s compliance terminology.