nerdexam
(ISC)2

CCSP · Question #686

Because cloud providers will not give detailed information out about their infrastructures and practices to the general public, they will often use established auditing reports to ensure public…

The correct answer is C. SOC 3. SOC Type 3 audit reports are very similar to SOC Type 2, with the exception that they are intended for general release and public audiences.SAS-70 audits have been deprecated. SOC Type 1 audit reports have a narrow scope and are intended for very limited release, whereas SOC…

Submitted by omar99· Apr 18, 2026Legal, Risk and Compliance

Question

Because cloud providers will not give detailed information out about their infrastructures and practices to the general public, they will often use established auditing reports to ensure public trust, where the reputation of the auditors serves for assurance. Which type of audit reports can be used for general public trust assurances?

Options

  • ASOC 2
  • BSAS-70
  • CSOC 3
  • DSOC 1

How the community answered

(48 responses)
  • A
    6% (3)
  • B
    2% (1)
  • C
    90% (43)
  • D
    2% (1)

Explanation

SOC Type 3 audit reports are very similar to SOC Type 2, with the exception that they are intended for general release and public audiences.SAS-70 audits have been deprecated. SOC Type 1 audit reports have a narrow scope and are intended for very limited release, whereas SOC Type 2 audit reports are intended for wider audiences but not general release.

Topics

#Cloud Compliance#Audit Reports#SOC Reports#Public Assurance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice