CISA Protection of Information Assets Practice Question
An IS auditor is reviewing a software-as-a-service (SaaS) provider that hosts a company's customer relationship management (CRM) data. The contract states the provider will maintain a SOC 2 Type II report, but the most recent report covers a period ending 14 months ago, and the provider has not responded to requests for a bridge letter. Which of the following should the auditor conclude?
⚠ Common exam trap
The trap here is treating a previously issued SOC 2 Type II report as ongoing assurance, when its coverage is limited to the stated period and a bridge letter is needed to address the gap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assurance over the provider's controls for the current period is inadequate and requires further action.
Third-party assurance is only valid for the period it covers. A SOC 2 Type II report ending 14 months ago, with no bridge letter explaining the intervening period, leaves the auditor without evidence that controls operated effectively during the current period. The correct conclusion is that assurance is inadequate, and the auditor should pursue a current report, a bridge letter, or alternative procedures before relying on the provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The provider is noncompliant with the contract and should be replaced immediately.
Why it's wrong here
The contract requires maintaining a SOC 2 Type II report, but the auditor has not established that the provider failed to obtain one, only that the current evidence is stale and a bridge letter is missing. Recommending immediate replacement is an operational decision beyond the audit conclusion. The auditor should first pursue additional assurance and report the gap rather than prescribe contract termination.
- ✓
Assurance over the provider's controls for the current period is inadequate and requires further action.
Why this is correct
The report is stale and no bridge letter covers the gap, so the auditor cannot rely on it to conclude controls are effective today. Third-party assurance must align with the period under review. The appropriate conclusion is that assurance is insufficient, prompting follow-up such as requesting a current report, obtaining a bridge letter, or applying additional procedures and considering the risk in the audit report.
- ✗
The company should perform a penetration test of the SaaS provider's environment to close the gap.
Why it's wrong here
A penetration test examines technical vulnerabilities at a point in time and does not substitute for the broad control assurance a SOC 2 Type II report provides. It also typically requires the provider's cooperation, which is already lacking. The core issue is insufficient assurance for the current period, so requesting a current report or bridge letter is the appropriate response rather than a penetration test.
- ✗
The provider's controls are effective because a SOC 2 Type II report was previously issued.
Why it's wrong here
A SOC 2 Type II report provides assurance only for the period it covers, not indefinitely. A report ending 14 months ago says nothing about controls in the intervening months, and the absence of a bridge letter leaves that gap unexplained. Concluding controls remain effective ignores the staleness of the evidence and the provider's nonresponsiveness, which are themselves warning signs.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.