ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During due-diligence for an IaaS provider, you discover the provider can only furnish a recently issued SOC 2 Type I report. Your internal audit charter and Sarbanes-Oxley (SOX) obligations require evidence that the provider's controls operate effectively for at least six continuous months. From the standpoint of audit requirements, what is the most appropriate next step?
Accept the Type I report and plan to implement additional customer-side technical controls.
Wait until the provider's next annual audit cycle and ask internal audit to revisit the issue then.
De-scope the provider from SOX by classifying the hosted workload as non-financial data.
Request that the provider obtain a SOC 2 Type II (or equivalent) report covering operating effectiveness over a multi-month period.
A SOC 2 Type I report evaluates whether the cloud provider's controls are suitably designed, but only as of a single point in time. It does not demonstrate that the controls were operating effectively over a period, which is exactly what SOX and most internal audit programs demand. A SOC 2 Type II (or comparable assurance such as an ISAE 3402 Type II) covers both design and operating effectiveness over a defined review period, typically 6-12 months, so it satisfies the requirement. Simply accepting the risk, relying on customer-side compensating controls, or waiting until next year would still leave the compliance gap unresolved.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between a SOC 2 Type I and SOC 2 Type II report?
Open an interactive chat with Bash
What are Sarbanes-Oxley (SOX) audit requirements for internal controls?
Open an interactive chat with Bash
What is ISAE 3402 and how does it compare to SOC 2 Type II?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .