nerdexam
(ISC)2

CCSP · Question #320

Which kind of SSAE audit reviews controls dealing with the organization's controls for assuring the confidentiality, integrity, and availability of data? Response:

The correct answer is B. SOC 2. SOC 2 reports specifically focus on controls related to security, availability, processing integrity, confidentiality, and privacy of user data, known as the Trust Services Criteria.

Submitted by dimitri_ru· Apr 18, 2026Legal, Risk and Compliance

Question

Which kind of SSAE audit reviews controls dealing with the organization's controls for assuring the confidentiality, integrity, and availability of data? Response:

Options

  • ASOC 1
  • BSOC 2
  • CSOC 3
  • DSOC 4

How the community answered

(66 responses)
  • A
    2% (1)
  • B
    89% (59)
  • C
    3% (2)
  • D
    6% (4)

Why each option

SOC 2 reports specifically focus on controls related to security, availability, processing integrity, confidentiality, and privacy of user data, known as the Trust Services Criteria.

ASOC 1

SOC 1 reports primarily focus on internal controls over financial reporting (ICFR) and do not specifically address data security, availability, and confidentiality.

BSOC 2Correct

A SOC 2 (Service Organization Control 2) audit report focuses on a service organization's controls relevant to the security, availability, processing integrity, confidentiality, and privacy of the data it processes for its users. These are collectively known as the Trust Services Criteria (TSC), directly addressing the confidentiality, integrity, and availability (CIA) of data.

CSOC 3

SOC 3 reports are general use reports that provide a less detailed, publicly available version of a SOC 2 report, without the detailed description of the system or the controls.

DSOC 4

SOC 4 is not a recognized or standard SSAE audit report type.

Concept tested: SSAE audit types (SOC 1, SOC 2, SOC 3)

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-soc-2-type-2

Topics

#SOC Reports#SSAE#Audit and Assurance#CIA Triad

Community Discussion

No community discussion yet for this question.

Full CCSP Practice