CRISC Information Technology and Security Practice Question
An organization is migrating its customer relationship management (CRM) system to a SaaS provider. The vendor's audit report shows a SOC 2 Type II opinion with no exceptions, but the report's period ended eight months ago. The risk practitioner must assess whether the residual risk is acceptable. Which action BEST addresses the gap in assurance?
⚠ Common exam trap
The trap here is assuming that a Type II SOC 2 report provides perpetual assurance, when it only covers the specific audit period and requires a bridge letter for the gap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request a bridge letter or gap letter covering the period since the report ended and review the vendor's remediation of any changes.
SOC 2 Type II reports are point-in-time documents that cover only the stated audit period. When the report is stale, the risk practitioner needs evidence of controls during the gap. A bridge or gap letter is the standard mechanism for that period, supplemented by review of changes and incidents, allowing an informed residual risk determination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a penetration test against the SaaS provider's production environment to validate its controls directly.
Why it's wrong here
Penetration testing a third party's production environment without explicit contractual authorization is typically prohibited and may be illegal. Even with permission, a point-in-time penetration test does not replace the need for continuous control assurance across the full period, and it addresses only a narrow set of technical controls.
- ✓
Request a bridge letter or gap letter covering the period since the report ended and review the vendor's remediation of any changes.
Why this is correct
A bridge letter documents the vendor's controls and any changes during the gap between the audit period end and the current date. Reviewing it, along with any reported incidents or control changes, provides the missing assurance for the current period and allows the risk practitioner to judge whether residual risk remains acceptable.
- ✗
Require the vendor to purchase cyber insurance and name the organization as an additional insured as a compensating control.
Why it's wrong here
Insurance transfers some financial consequence of a loss but does not provide assurance that the vendor's controls are operating effectively. Naming the organization as an additional insured does not close the assurance gap, nor does it address the risk of data compromise or service failure before a claim is ever made.
- ✗
Accept the SOC 2 Type II report as sufficient evidence because it was issued by an independent CPA firm.
Why it's wrong here
A SOC 2 Type II report provides assurance only for the period it covers. Since the report period ended eight months ago, it does not reflect the current control environment, including any changes in management, infrastructure, or processes. Relying on it without bridge or gap-period evidence leaves the residual risk unassessed for the most recent period.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.