exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 108 discussion

Actual exam question from ISC's CCSP
Question #: 108
Topic #: 1
[All CCSP Questions]

Which type of audit report is considered a "restricted use" report for its intended audience?

  • A. SAS-70
  • B. SSAE-16
  • C. SOC Type 1
  • D. SOC Type 2
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 4 years, 2 months ago
the question doesn't seem correct The SOC 2 Type 1 is not extremely useful for determining the security and trust of an organization. The SOC 2 Type 1 only reviews the design of controls, not how they are implemented and maintained, or their function. The SOC 2 Type 2 report, however, does just that. This is why the SOC 2 Type 2 is the sort of report that is extremely useful for getting a true assessment of an organization’s security posture.
upvoted 21 times
Most Recent 1 week, 2 days ago
Selected Answer: C
A SOC Type 1 report (Service Organization Control Type 1) is considered a restricted use report because it is intended for a specific audience, typically management, auditors, and regulators. It focuses on the design and implementation of internal controls at a point in time, rather than ongoing operational effectiveness.
upvoted 1 times
4 months, 1 week ago
Selected Answer: C
SOC Type 1 reports are often intended for restricted use, meaning they are designed for specific, intended users, such as management or those charged with governance, not for the general public or broader external use. They evaluate the design of a service organization's controls at a specific point in time.
upvoted 2 times
5 months, 4 weeks ago
Selected Answer: D
upvoted 1 times
8 months, 1 week ago
Selected Answer: B
SSAE-16 includes SOC1 and SOC2. Both are restricted. "SSAE-16, which stands for Statement on Standards for Attestation Engagements No. 16, was introduced by the AICPA as a replacement for SAS-70. SSAE-16 introduced several changes and improvements to the auditing and reporting process for service organizations, particularly for those providing services that could impact their clients' financial reporting. SSAE-16 is part of a broader framework for attestation engagements, including SOC (Service Organization Control) reports (SOC1 and SOC2)."
upvoted 1 times
6 months, 3 weeks ago
SSAE is an auditing standard, not a report by itself. My take is SOC 2 is then answer.
upvoted 3 times
1 year, 3 months ago
You may get type 2 reports, but never type 1 report (soc 1 or 2 does not matter). Type 1 reports are always classified with no exceptions in real life since it pertains to a “specific time” as against type 2. Ask any auditor friend, they will tell.
upvoted 1 times
1 year, 4 months ago
Selected Answer: D
SOC Type 2 reports include a description of the service organization's system, a detailed testing of the design and operating effectiveness of controls, and an opinion provided by an independent auditor.
upvoted 1 times
1 year, 7 months ago
Selected Answer: D
SOC 2 Type 2 is the correct answer.
upvoted 1 times
1 year, 7 months ago
Selected Answer: C
Type 1 report just provides a report of procedures / controls an organization has put in place as of a point in time (no required audit so no outside audience; i.e., more restrictive). A Type 2 report has an audit period and provides evidence of how an organization operated its controls over a period of time (required audit so outside audience; i.e., less restrictive). Restrictive is observed from the perspective of the data owner's view.
upvoted 1 times
1 year, 8 months ago
A SOC Type 2 audit report is considered a "restricted use" report for its intended audience. SOC, or Service Organization Controls, is a set of auditing standards and guidelines developed by the American Institute of Certified Public Accountants (AICPA) to help service organizations demonstrate the effectiveness of their internal controls and processes. A SOC Type 2 audit report is a detailed assessment of a service organization's controls over a specific period of time, typically six to nine months. Because this report contains sensitive information about the organization's internal controls and processes, it is considered a "restricted use" report and is only intended for the organization's management, board of directors, and other stakeholders who have a need to know the information contained in the report.
upvoted 4 times
1 year, 10 months ago
Selected Answer: D
Yes it is D
upvoted 4 times
2 years, 3 months ago
Request to update the choices as both "SOC Type 1" and "SOC Type 2" (whether SOC1 or SOC2) are both restricted to their intended users. Also SOC3 (which does not have any type) are for public use.
upvoted 3 times
2 years, 5 months ago
Note that it does not mention SOC 1 or SOC 2, but Type 1 & Type 2. There is something worng with this question. Type 2 is in a period of time - 6 months Type 1 is in a specific time, when the control/design was checked.
upvoted 1 times
2 years, 8 months ago
both are restricted but SOC1 is more restrictive SOC 1 - Use of these reports is restricted to the management of the service organization, user entities, and user auditors. SOC 2 - Use of these reports are restricted. Taken from https://us.aicpa.org/interestareas/frc/assuranceadvisoryservices/serviceorganization-smanagement
upvoted 2 times
2 years, 10 months ago
SOC 2 is the right answer
upvoted 1 times
1 year, 10 months ago
Correct, but either type 1 or 2 would fall under SOC 2. So the answer could be either one.
upvoted 1 times
2 years, 10 months ago
They mean SoC 1 which is true, which is a control report that focuses strictly on an organization’s financial statements and a service organization’s controls that can impact a customer’s financial statements
upvoted 3 times
3 years, 6 months ago
The options include SOC Type I & II, not SOC 2 Type II. SOC Type I - provides a description of the controls provided by the audited organization and the auditor opinion based on the description, BUT... does not involve actual testing of controls. SOC Type 1 reports are intended for restricted use, only to be seen by the actual service organization, its current clients, or its auditors. These reports are not intended for wider or public distribution. So, the answer is correct folks.
upvoted 2 times
3 years, 6 months ago
First of all, there's no SOC Type I, and SOC Type 2. SOC 1 does not have both versions. Only SOC 2. Under such premise, SOC 2 in any of its forms is intended only for restricted use. The only one for a wider audience its the SOC 3 report. So I agree, the question or answers are incorrect.
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago