nerdexam
(ISC)2

CCSP · Question #817

Which kind of SSAE audit report is most beneficial for a cloud customer, even though it's unlikely the cloud provider will share it?

The correct answer is C. SOC 2 Type 2. SOC 2 Type 2 evaluates a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy over an extended period of time (typically 6–12 months), demonstrating operational effectiveness rather than just design. This makes it f

Submitted by chiamaka_o· Apr 18, 2026Legal, Risk and Compliance

Question

Which kind of SSAE audit report is most beneficial for a cloud customer, even though it's unlikely the cloud provider will share it?

Options

  • ASOC 3
  • BSOC 1 Type 2
  • CSOC 2 Type 2
  • DSOC 1 Type 1

How the community answered

(29 responses)
  • A
    3% (1)
  • C
    93% (27)
  • D
    3% (1)

Explanation

SOC 2 Type 2 evaluates a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy over an extended period of time (typically 6–12 months), demonstrating operational effectiveness rather than just design. This makes it far more valuable to cloud customers than a Type 1 (point-in-time snapshot) or SOC 1 (focused on financial reporting controls). SOC 3 is a sanitized public summary with far less detail. Providers are reluctant to share SOC 2 Type 2 because it contains detailed, sensitive information about their internal security architecture and any identified exceptions.

Topics

#SOC reports#Cloud audit#Compliance#Third-party risk

Community Discussion

No community discussion yet for this question.

Full CCSP Practice