Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 210 discussion

Actual exam question from ISC's CISSP
Question #: 210
Topic #: 1
[All CISSP Questions]

A cloud hosting provider would like to provide a Service Organization Control (SOC) report relevant to its security program. This report should an abbreviated report that can be freely distributed. Which type of report BEST meets this requirement?

  • A. SOC 1
  • B. SOC 2 Type 1
  • C. SOC 2 Type 2
  • D. SOC 3
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
matt1976
Highly Voted 2 years, 2 months ago
Answer is D - A SOC 3 report is basically a redacted SOC2 report. It’s intended for a public audience, and is usually available on an organization’s website.
upvoted 16 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 2 times
...
...
041ba31
Most Recent 6 months, 1 week ago
Its quite concerning to see the amount of questions that are that incorrect answers marked as "Correct Answer". SOC 2 type 1 report is clearly incorrect, it focuses on the could provider's CIA+ processes and procedures, generating a report that is CONFIDENTIAL. Correct answer should be D, SOC 3, which focuses on the same principles as SOC 2 but generates a "high view" report thatcan be freely distributed.
upvoted 1 times
...
Dtony66
6 months, 3 weeks ago
Selected Answer: D
D is correct.
upvoted 1 times
...
Soleandheel
11 months, 2 weeks ago
SOC 3 report is essentially a summary of the SOC 2 report. SOC 3 can be freely distributed while SOC 2 is not for distribution.
upvoted 1 times
Soleandheel
11 months, 2 weeks ago
Therefore, the answer is D. SOC 3
upvoted 1 times
...
...
74gjd_37
1 year, 2 months ago
Selected Answer: D
This is expressly mentioned on page 26 of the Official ISC2 CISSP CBK reference that SOC3 is a light version for distribution.
upvoted 4 times
...
georgegeorge125487
1 year, 3 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
MShaaban
1 year, 3 months ago
Answer is D. SOC3. SOC2 is not for distribution.
upvoted 1 times
...
Dee83
1 year, 10 months ago
D. SOC 3
upvoted 1 times
...
olulado
1 year, 10 months ago
Ans B . What is SOC 2 Type 1? SOC 2 Type 1 compliance evaluates an organization's cybersecurity controls at a single point in time. The goal is to determine whether the internal controls put in place to safeguard customer data are sufficient and designed correctly.
upvoted 1 times
...
Jamati
2 years ago
Selected Answer: D
SOC3 because they're public.
upvoted 3 times
...
WiDeBarulho
2 years, 1 month ago
Selected Answer: D
SOC 2 reports are restricted. SOC 3 are to be freely distributed. For more info go here: https://linfordco.com/blog/soc-2-vs-soc-3/
upvoted 3 times
...
JAckThePip
2 years, 1 month ago
Answer correct "Developed by the American Institute of CPAs (AICPA), SOC 2 defines criteria for managing customer data based on five “trust service principles”—security, availability, processing integrity, confidentiality and privacy." https://www.imperva.com/learn/data-security/soc-2-compliance/
upvoted 1 times
Jamati
2 years ago
Given answer is not correct.
upvoted 1 times
...
...
inmymind84
2 years, 2 months ago
Selected Answer: D
Correct, D
upvoted 4 times
...
stickerbush1970
2 years, 2 months ago
Selected Answer: D
Agree with D.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...