nerdexam
(ISC)2

CCSP · Question #655

Audits are either done based on the status of a system or application at a specific time or done as a study over a period of time that takes into account changes and processes. Which of the…

The correct answer is D. SOC Type 2, six months. SOC Type 2 audits are done over a period of time, with six months being the minimum duration. SOC Type 1 audits are designed with a scope that's a static point in time, and the other times provided for SOC Type 2 are incorrect.

Submitted by the_admin· Apr 18, 2026Legal, Risk and Compliance

Question

Audits are either done based on the status of a system or application at a specific time or done as a study over a period of time that takes into account changes and processes. Which of the following pairs matches an audit type that is done over time, along with the minimum span of time necessary for it?

Options

  • ASOC Type 2, one year
  • BSOC Type 1, one year
  • CSOC Type 2, one month
  • DSOC Type 2, six months

How the community answered

(31 responses)
  • A
    3% (1)
  • C
    6% (2)
  • D
    90% (28)

Explanation

SOC Type 2 audits are done over a period of time, with six months being the minimum duration. SOC Type 1 audits are designed with a scope that's a static point in time, and the other times provided for SOC Type 2 are incorrect.

Topics

#SOC reports#Audit types#Compliance#Service Organization Controls

Community Discussion

No community discussion yet for this question.

Full CCSP Practice