CoStudy

HomeCertificationsCPA ISC › SOC engagements

SOC engagements — CPA ISC practice questions

59 multiple-choice questions and 24 flashcards on SOC engagements, about 16% of the CPA ISC bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

SOC engagements is one of 5 chapters in CoStudy's CPA — Information Systems & Controls (ISC) [Discipline] bank, and it holds 59 of the bank's 378 multiple-choice questions — roughly 16% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free SOC engagements practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

A service auditor's independence would be impaired if the auditor:

  1. Reviewed the service organization's SOC 1 report drafts before issuing the final opinion
  2. Attended the service organization's board meeting as an observer during the fieldwork week
  3. Held a direct financial interest in the service organization being examined for SOC report
  4. Discussed proposed findings with service organization management during the exit conference call

Answer: C — Held a direct financial interest in the service organization being examined for SOC report

A) Review of draft reports is a normal audit step. C) Correct — a direct financial interest impairs independence. B) Board attendance as observer generally doesn't impair independence. D) Findings discussions are a normal audit step.

A SOC for Cybersecurity report is intended primarily for:

  1. User entity auditors evaluating internal control over financial reporting processes
  2. Vendors and suppliers seeking to demonstrate PCI DSS card data handling compliance
  3. Regulatory examiners performing statutory examinations of insurance carrier reserves
  4. General-use stakeholders (board, investors) reviewing the entity's cyber risk program

Answer: D — General-use stakeholders (board, investors) reviewing the entity's cyber risk program

A) That describes SOC 1, not SOC for Cybersecurity. D) Correct — SOC for Cybersecurity is a general-use report on cyber risk programs. C) That is statutory examination, not SOC. B) That is PCI compliance, not SOC for Cybersecurity.

A SOC 2 report for a SaaS provider states that the provider's security depends partly on the customer enforcing strong password policies and promptly de-provisioning terminated employees' accounts within the customer's own systems. This is an example of:

  1. A control deficiency in the service provider's own control environment
  2. A Complementary User Entity Control (CUEC) — a control the service organization's control objective assumes the USER ENTITY (customer) will implement, and whose omission by the customer could undermine the overall control objective even if the provider's own controls are sound
  3. An irrelevant disclosure that auditors should ignore
  4. Evidence that the SOC 2 report itself is invalid

Answer: B — A Complementary User Entity Control (CUEC) — a control the service organization's control objective assumes the USER ENTITY (customer) will implement, and whose omission by the customer could undermine the overall control objective even if the provider's own controls are sound

A) Incorrect — this isn't a deficiency in the PROVIDER'S controls; it's an explicit disclosure of a control the CUSTOMER must implement for the overall objective to hold. B) Correct — this is a textbook Complementary User Entity Control: the service organization's control design assumes certain controls will be implemented by the user entity itself (here, password policy enforcement and timely de-provisioning), and failing to analyze/implement CUECs is a common and consequential audit/customer oversight gap. C) Incorrect — CUECs are a critical part of interpreting a SOC report correctly; ignoring them risks a false sense of security about controls the customer must actually implement themselves. D) Incorrect — disclosing CUECs is standard, expected SOC reporting practice, not evidence of report invalidity.

The Availability Trust Services Criterion evaluates whether the system is:

  1. Available for operation and use as committed to user entities in service agreements
  2. Free of any errors in transaction processing across financial and operational reports
  3. Protected from unauthorized disclosure of sensitive customer information at all times
  4. Compliant with all state and federal privacy laws applicable to the data collected

Answer: A — Available for operation and use as committed to user entities in service agreements

A) Correct — Availability addresses uptime and access as committed. B) That describes Processing Integrity, not Availability. C) That describes Confidentiality, not Availability. D) That describes Privacy, not Availability.

SOC 1 control objectives are set by:

  1. The service auditor unilaterally without input from the service organization's management
  2. The AICPA in a fixed framework identical for every SOC 1 engagement everywhere issued
  3. The user entity's independent auditor at the beginning of each SOC 1 engagement
  4. The service organization's management, subject to service auditor's suitability review

Answer: D — The service organization's management, subject to service auditor's suitability review

A) Management sets objectives, not the auditor alone. B) SOC 1 objectives are not standardized across engagements. C) The user auditor doesn't set SOC 1 objectives. D) Correct — management sets objectives; auditor evaluates suitability.

The Processing Integrity Trust Services Criterion evaluates whether processing is:

  1. Available for operation and use as committed to user entities in service agreements
  2. Protected from unauthorized disclosure of sensitive customer information at all times
  3. Complete, valid, accurate, timely, and authorized to meet the entity's objectives
  4. Compliant with all state and federal privacy laws applicable to the data collected

Answer: C — Complete, valid, accurate, timely, and authorized to meet the entity's objectives

A) That describes Availability. C) Correct — Processing Integrity addresses completeness, accuracy, timeliness, authorization. B) That describes Confidentiality. D) That describes Privacy.

The examination period for a Type 2 SOC report typically covers:

  1. A single point in time as of the report date, no operating effectiveness period at all
  2. A period covering only one calendar quarter of the service organization's business cycle
  3. A period of at least six months and typically twelve months of ongoing operations tested
  4. A period covering only two business weeks of the service organization's operations tested

Answer: C — A period of at least six months and typically twelve months of ongoing operations tested

A) That describes a Type 1 report, not Type 2. C) Correct — Type 2 typically covers 6-12 months of operating effectiveness. B) One quarter is too short for a standard Type 2 period. D) Two weeks is far too short for a Type 2 period.

A SOC 1 report addresses controls at a service organization that are relevant to:

  1. Trust Services Criteria for security, availability, and confidentiality controls
  2. Cybersecurity risk management program at the enterprise reporting boundary
  3. User entities' internal control over financial reporting (ICFR) processes
  4. General-use marketing summaries suitable for distribution to the public at large

Answer: C — User entities' internal control over financial reporting (ICFR) processes

A) That describes SOC 2, not SOC 1. B) That describes SOC for Cybersecurity, not SOC 1. C) Correct — SOC 1 addresses controls relevant to user entities' ICFR. D) That describes SOC 3, not SOC 1.

Complementary User Entity Controls (CUECs) are controls that:

  1. The service auditor tests directly at the service organization during Type 2 fieldwork
  2. The subservice organization must operate for the service organization to succeed
  3. The user entity must operate for the service organization's controls to be effective
  4. The service organization operates in place of the user entity's own internal controls

Answer: C — The user entity must operate for the service organization's controls to be effective

A) The service auditor tests the service org's controls, not CUECs at user entities. B) That describes CSOCs, not CUECs. C) Correct — CUECs are controls the user entity must operate. D) The service org doesn't substitute for user entity controls.

Reflecting on this newest batch of ISC content — SOC report type selection, CUECs, cloud shared responsibility, encryption scope, ABAC, incident response phases, PKI revocation, MFA factor categories, DPIA triggers, TSC mandatory/optional categories, insider threat program design, DR testing approaches, honeypots, and COBIT 2019 design factors — the unifying exam skill is best described as:

  1. Memorizing each topic as an isolated fact with no connection to assurance or governance judgment
  2. Applying structured judgment to determine which specific framework, control, or assurance mechanism correctly addresses a given organizational context or risk scenario — recognizing that different mechanisms (SOC report types, access control models, testing approaches) serve genuinely different purposes and aren't interchangeable
  3. Assuming any single security control or report type is universally sufficient for every scenario
  4. Ignoring the distinction between mandatory and optional/contextual elements within any given framework

Answer: B — Applying structured judgment to determine which specific framework, control, or assurance mechanism correctly addresses a given organizational context or risk scenario — recognizing that different mechanisms (SOC report types, access control models, testing approaches) serve genuinely different purposes and aren't interchangeable

A) Incorrect — as demonstrated throughout this batch, the content specifically requires connecting facts to applied judgment (e.g., recognizing WHY a SOC 1 vs SOC 3 choice matters for a specific stakeholder need), not isolated memorization. B) Correct — the unifying skill across this batch is exactly this kind of applied, context-sensitive judgment: correctly matching a specific mechanism (the right SOC report type, the right access control model, the appropriate DR testing approach, the correctly triggered DPIA) to the organizational context or risk scenario presented, recognizing that these mechanisms are NOT interchangeable and serve genuinely distinct purposes. C) Incorrect — the content specifically shows that no single control or report type is universally sufficient (e.g., a SOC 3 report cannot substitute for a SOC 1 need); over-generalizing this way would lead to real errors. D) Incorrect — the mandatory-vs-optional distinction (e.g., Security as the mandatory TSC category vs. the four optional ones) is specifically highlighted as an important, testable distinction, not one to be ignored.

SOC engagements flashcards

3 cards from the 24 in this chapter.

What is SOC?

System and Organization Controls — AICPA attestation engagements over service organization controls.

Renewing a contract with a risky, SOC-2-lacking vendor with undisclosed subcontractors — considerations?

Risk tier/criticality, available alternative assurance for the missing SOC 2, and added fourth-party exposure from undisclosed subcontractors.

Bridge letter?

Service org's letter covering gap between SOC report period end and user's audit date. Confirms no significant changes.

Practise the full chapter

These are a sample. The full SOC engagements chapter runs 83 items with per-chapter progress tracking, on the web and in the iOS app.

Open CPA ISC in CoStudy →

Other CPA ISC chapters

All CPA ISC practice questions →