CISSP Security Assessment and Testing Practice Question
An organization is planning an external audit for SOC 2 Type II compliance. Which TWO of the following are true about this type of audit?
⚠ Common exam trap
CISSP often tests the SOC 1 vs SOC 2 vs SOC 3 distinction — candidates confuse SOC 2 (Trust Services Criteria, restricted use) with SOC 1 (financial reporting) or SOC 3 (general-use, no detail), and mislabel Type II as a point-in-time or internal audit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It reports on controls over a period of time, typically 6–12 months
Option A is correct because a SOC 2 Type II audit reports on the design and operating effectiveness of controls over a period of time, typically a 6–12 month observation window, rather than a single point in time as in a Type I report. Option B is correct because SOC 2 is an independent third-party examination against the AICPA Trust Services Criteria, which cover security (common criteria) plus availability, processing integrity, confidentiality, and privacy. Option C is incorrect because SOC 2 is performed by an independent CPA firm, not by the organization's own internal staff. Option D is incorrect because SOC 2 addresses the Trust Services Criteria, not financial reporting controls, which are the domain of SOC 1 (SSAE 18/ISAE 3402). Option E is incorrect because SOC 2 reports are restricted-use documents distributed under NDA to management, customers, and other specified parties, not public documents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It reports on controls over a period of time, typically 6–12 months
Why this is correct
A SOC 2 Type II report provides an in-depth assessment of a service organization's controls over a specified period, typically spanning six to twelve months. This extended observation period allows the auditor to test the operating effectiveness of controls, demonstrating their consistent application and reliability over time. This contrasts sharply with a Type I report, which only describes controls at a specific point in time without testing their effectiveness.
- ✓
It is a third-party audit that evaluates controls for security, availability, processing integrity, confidentiality, and privacy
Why this is correct
A SOC 2 audit is inherently a third-party assessment, conducted by an independent Certified Public Accountant (CPA) firm, ensuring objectivity and credibility. This comprehensive evaluation specifically assesses the design and operating effectiveness of controls relevant to the Trust Service Criteria (TSC) of security, availability, processing integrity, confidentiality, and privacy. These criteria are fundamental to safeguarding customer data and system reliability for user entities.
- ✗
It is an internal audit performed by the organization's staff
Why it's wrong here
A SOC 2 audit is strictly an external assessment, mandated to be performed by an independent CPA firm, not by the organization's internal staff. This independence is crucial for providing an unbiased and objective opinion on the service organization's control environment. Internal audits, while valuable for internal governance and improvement, lack the necessary independence and external validation required for a SOC 2 report, which is intended for external stakeholders.
- ✗
It focuses solely on financial reporting controls
Why it's wrong here
The scope of a SOC 2 report is specifically designed to address controls related to the security, availability, processing integrity, confidentiality, and privacy of a service organization's systems and data. It does not focus solely on financial reporting controls, which are the primary subject of a SOC 1 report. SOC 1 reports are intended for user entities' auditors to evaluate controls relevant to financial statement audits, a distinct purpose from SOC 2's operational and data security focus.
- ✗
It is a public document available to anyone
Why it's wrong here
A SOC 2 report is considered a restricted-use document, meaning its distribution is limited to the service organization, its user entities, and their respective auditors. It is not a public document available to anyone, due to the sensitive and proprietary information it contains about the service organization's control environment. In contrast, a SOC 3 report, which is a general-use report, provides a high-level summary of a SOC 2 audit and can be freely distributed to the public.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.