CISSP Security Assessment and Testing Practice Question
Which type of SOC report provides a public summary of controls related to security, availability, confidentiality, integrity, and privacy, but does not include detailed testing results?
⚠ Common exam trap
Test-takers frequently confuse SOC 2 Type II (which includes detailed testing results) with SOC 3, or assume that SOC 2 Type I (point-in-time) is a public summary, when in fact SOC 3 is the only report designed for public distribution without detailed testing results.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SOC 3
SOC 3 reports are designed for public distribution and provide a high-level summary of an organization's controls related to security, availability, confidentiality, integrity, and privacy (the Trust Services Criteria). Unlike SOC 2 reports, SOC 3 reports do not include detailed testing results, control descriptions, or the auditor's opinion on control effectiveness, making them suitable for marketing or public disclosure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SOC 2 Type II
Why it's wrong here
A SOC 2 Type II report details a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy over a specified period, typically 6-12 months. While it provides an in-depth assessment of control effectiveness over time, it is a restricted-use report, meaning it is only available to user entities and their auditors, not for public distribution. Therefore, it does not provide a public summary.
- ✓
SOC 3
Why this is correct
A SOC 3 report is specifically designed for general public use, offering a high-level summary of a service organization's internal controls related to the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Unlike SOC 2 reports, it omits the detailed description of controls and test results, making it suitable for marketing purposes or posting on a website without revealing sensitive operational details. Its primary purpose is public assurance.
- ✗
SOC 1 Type II
Why it's wrong here
A SOC 1 Type II report evaluates a service organization's controls that are relevant to a user entity's internal control over financial reporting (ICFR) over a specified period. This report is critical for user entities to comply with financial regulations like Sarbanes-Oxley (SOX) and includes an opinion on the fairness of the control description and the operating effectiveness of controls. However, it is a restricted-use report, not intended for public disclosure, and its scope is limited to financial controls, not a general public summary of controls.
- ✗
SOC 2 Type I
Why it's wrong here
A SOC 2 Type I report provides an opinion on the fairness of the presentation of management's description of a service organization's system and the suitability of the design of its controls to achieve the related Trust Services Criteria at a specific point in time. While it addresses security, availability, processing integrity, confidentiality, or privacy, it does not assess the operating effectiveness of these controls over a period, nor is it intended for public consumption. It's a restricted-use report for user entities.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.