Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 269 discussion

Actual exam question from ISC's CCSP
Question #: 269
Topic #: 1
[All CCSP Questions]

Different types of audits are intended for different audiences, such as internal, external, regulatory, and so on.
Which of the following audits are considered "restricted use" versus being for a more broad audience?

  • A. SOC Type 2
  • B. SOC Type 1
  • C. SOC Type 3
  • D. SAS-70
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Sa007788
Highly Voted 3 years, 10 months ago
bad question, both soc1 and soc2 are restectided evenif we use type1 or type2
upvoted 7 times
...
babusartop17
Highly Voted 3 years, 5 months ago
Answer should be Soc2 Type 2 -- which ironically is not even on the options list.
upvoted 5 times
xaccan
3 years, 1 month ago
soc 1 is the correct answer.
upvoted 2 times
...
...
Lee_Lah
Most Recent 9 months, 1 week ago
Selected Answer: A
A - SOC 2
upvoted 1 times
...
joeee7
1 year, 4 months ago
soc type 1
upvoted 1 times
...
Pika26
1 year, 6 months ago
Selected Answer: B
B: Soc Type 1
upvoted 1 times
...
ikamalbhatt
1 year, 6 months ago
Selected Answer: A
Sox2 type 2: Of the SOC reports, the SOC 2 Type 2 report is most commonly restricted to a limited audience. This is because the SOC 2 Type 2 report provides a more detailed assessment of the effectiveness of a service organization's controls over a period of time, which may include sensitive or proprietary information. Therefore, service organizations may choose to restrict the distribution of SOC 2 Type 2 reports to only those customers or potential customers who have signed a non-disclosure agreement (NDA) or other confidentiality agreement. However, it is important to note that the decision to restrict the distribution of a SOC report is up to the service organization that is being audited. Some service organizations may choose to restrict the distribution of other types of SOC reports (such as SOC 1 or SOC 3) based on their own internal policies or agreements with customers.
upvoted 1 times
...
budjones
1 year, 8 months ago
Yes I agree The answer is A and not B
upvoted 1 times
...
DaddyPan
2 years, 4 months ago
SOC 2 Type 2 are for clients for clients with an NDA. Not for public consumption
upvoted 1 times
...
xav1er
2 years, 6 months ago
Selected Answer: A
Based on my previous post, you need to be an User and have NDA signed with cloud provider in order to access SOC2 reports, I would go with answer A: SOC2
upvoted 2 times
...
xav1er
2 years, 6 months ago
SOC1 & SOC2 both restricted based on ISC2 materials: SOC1: Use of these reports is restricted to the management of the service organization, user entities, and user auditors SOC2: A key difference between a SOC 2 report and a SOC 3 report is that a SOC 2 report is generally restricted in distribution and coverage, requiring a nondisclosure agreement (NDA) due to the information it contains, whereas a SOC 3 report is broadly available, with limited information and details included within it (often used to instill confidence in prospective clients or for marketing purposes).
upvoted 4 times
...
ilu456
2 years, 7 months ago
soc 2 type 2 should be correct answer
upvoted 1 times
...
kepalon
2 years, 8 months ago
Selected Answer: A
A & B are correct: maybe B is more restricted????
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...