CCSP Legal, Risk, and Compliance Practice Question
A cloud customer is preparing for an audit of its cloud environment. The provider offers a SOC 2 Type II report covering security and availability. What does this report provide to the customer's auditors?
⚠ Common exam trap
The trap here is conflating SOC 2 Type I and Type II reports, treating a point-in-time design description as evidence of operating effectiveness over time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An opinion on the design and operating effectiveness of the provider's controls over a period of time.
A SOC 2 Type II report is an attestation covering a period, with the service auditor opining on the design and operating effectiveness of controls against selected trust services criteria. For the customer's auditors, it supplies independent evidence of sustained control operation, though they must still consider scope, period, and complementary user entity controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A certification issued by the AICPA that the provider fully complies with all applicable laws and regulations.
Why it's wrong here
SOC 2 is an attestation engagement, not a certification, and it does not assert legal or regulatory compliance. It reports on controls against trust services criteria selected by the provider. Auditors still perform their own compliance assessment rather than treating the report as a legal certification.
- ✓
An opinion on the design and operating effectiveness of the provider's controls over a period of time.
Why this is correct
A SOC 2 Type II report covers a period and includes the service auditor's opinion on both the suitability of design and the operating effectiveness of controls. This gives the customer's auditors evidence that controls functioned consistently, which is more persuasive than a point-in-time description.
- ✗
A guarantee that the provider's controls will remain effective for the next twelve months.
Why it's wrong here
A SOC 2 Type II report covers a historical period and provides no forward-looking guarantee. Control effectiveness can change after the period ends. Auditors typically review the report's period, scope, and complementary user entity controls, and may request bridge letters for gaps.
- ✗
A point-in-time description of controls without any testing of operating effectiveness.
Why it's wrong here
That describes a SOC 2 Type I report, which addresses design at a specific date. A Type II report extends coverage over a period and tests operating effectiveness. Confusing the two types would lead the customer to rely on weaker evidence than the report actually provides.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.