Courseiva
Security Assessment and TestinghardMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

Which type of SOC report provides a public summary of controls related to security, availability, confidentiality, integrity, and privacy, but does not include detailed testing results?

⚠ Common exam trap

Test-takers frequently confuse SOC 2 Type II (which includes detailed testing results) with SOC 3, or assume that SOC 2 Type I (point-in-time) is a public summary, when in fact SOC 3 is the only report designed for public distribution without detailed testing results.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SOC 3

SOC 3 reports are designed for public distribution and provide a high-level summary of an organization's controls related to security, availability, confidentiality, integrity, and privacy (the Trust Services Criteria). Unlike SOC 2 reports, SOC 3 reports do not include detailed testing results, control descriptions, or the auditor's opinion on control effectiveness, making them suitable for marketing or public disclosure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SOC 2 Type II

    Why it's wrong here

    A SOC 2 Type II report details a service organization's controls relevant to security, availability, processing integrity, confidentiality, or privacy over a specified period, typically 6-12 months. While it provides an in-depth assessment of control effectiveness over time, it is a restricted-use report, meaning it is only available to user entities and their auditors, not for public distribution. Therefore, it does not provide a public summary.

  • SOC 3

    Why this is correct

    A SOC 3 report is specifically designed for general public use, offering a high-level summary of a service organization's internal controls related to the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy). Unlike SOC 2 reports, it omits the detailed description of controls and test results, making it suitable for marketing purposes or posting on a website without revealing sensitive operational details. Its primary purpose is public assurance.

  • SOC 1 Type II

    Why it's wrong here

    A SOC 1 Type II report evaluates a service organization's controls that are relevant to a user entity's internal control over financial reporting (ICFR) over a specified period. This report is critical for user entities to comply with financial regulations like Sarbanes-Oxley (SOX) and includes an opinion on the fairness of the control description and the operating effectiveness of controls. However, it is a restricted-use report, not intended for public disclosure, and its scope is limited to financial controls, not a general public summary of controls.

  • SOC 2 Type I

    Why it's wrong here

    A SOC 2 Type I report provides an opinion on the fairness of the presentation of management's description of a service organization's system and the suitability of the design of its controls to achieve the related Trust Services Criteria at a specific point in time. While it addresses security, availability, processing integrity, confidentiality, or privacy, it does not assess the operating effectiveness of these controls over a period, nor is it intended for public consumption. It's a restricted-use report for user entities.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.