nerdexam
Isaca

CCAK · Question #103

Your company is purchasing an application from a vendor. They do not allow you to perform an on-site audit on their information system. However, they say, they will provide the third-party audit…

The correct answer is B. SOC 2, TYPE 2. A SOC 2, Type 2 report is the industry-standard third-party attestation report provided by cloud vendors and SaaS providers to customers who cannot perform on-site audits. SOC 2 reports assess controls relevant to security, availability, processing integrity, confidentiality…

Cloud Audit Reporting and Assurance

Question

Your company is purchasing an application from a vendor. They do not allow you to perform an on-site audit on their information system. However, they say, they will provide the third-party audit attestation on the adequate control design within their environment. Which report is the vendor providing you?

Options

  • ASOC 3
  • BSOC 2, TYPE 2
  • CSOC 1
  • DSOC 2, TYPE 1

How the community answered

(30 responses)
  • A
    13% (4)
  • B
    77% (23)
  • C
    7% (2)
  • D
    3% (1)

Explanation

A SOC 2, Type 2 report is the industry-standard third-party attestation report provided by cloud vendors and SaaS providers to customers who cannot perform on-site audits. SOC 2 reports assess controls relevant to security, availability, processing integrity, confidentiality, and privacy (Trust Services Criteria). A Type 2 report covers both the design and the operating effectiveness of controls over a defined period (typically 6–12 months), making it far more valuable than Type 1 (design only). SOC 1 (C) addresses financial reporting controls, SOC 3 (A) is a public-facing summary without detailed findings, and SOC 2 Type 1 (D) only covers design at a point in time.

Topics

#SOC reports#Third-party attestation#Vendor risk assessment#Control assurance

Community Discussion

No community discussion yet for this question.

Full CCAK Practice