nerdexam
(ISC)2

CISSP · Question #1002

An organization needs a general purpose document to prove that its internal controls properly address security, availability, processing integrity, confidentiality or privacy risks. Which of the…

The correct answer is C. A Service Organization Control (SOC) 2 report. A Service Organization Control (SOC) 2 report is a general purpose document that proves that an organization's internal controls properly address security, availability, processing integrity, confidentiality or privacy risks. A SOC 2 report is a type of attestation report that…

Submitted by neha2k· Mar 5, 2026Security Assessment and Testing

Question

An organization needs a general purpose document to prove that its internal controls properly address security, availability, processing integrity, confidentiality or privacy risks. Which of the following reports is required?

Options

  • AA Service Organization Control (SOC) 3 report
  • BThe Statement on Standards for Attestation Engagements No. 18 (SSAE 18)
  • CA Service Organization Control (SOC) 2 report
  • DThe International Organization for Standardization (ISO) 27001

How the community answered

(15 responses)
  • A
    7% (1)
  • C
    93% (14)

Explanation

A Service Organization Control (SOC) 2 report is a general purpose document that proves that an organization's internal controls properly address security, availability, processing integrity, confidentiality or privacy risks. A SOC 2 report is a type of attestation report that provides an independent and objective evaluation of the design and operating effectiveness of the internal controls of a service organization, such as a cloud provider, a data center, or a software-as-a- service provider. A SOC 2 report is based on the Trust Services Criteria, which are a set of standards that define the requirements for security, availability, processing integrity, confidentiality or privacy of the information and systems of a service organization. A SOC 2 report can be used by the service organization's customers, regulators, or other stakeholders to gain assurance and confidence in the service organization's internal controls.

Topics

#SOC 2 report#internal controls#security auditing

Community Discussion

No community discussion yet for this question.

Full CISSP Practice