SOC Cheat Sheet 2026
The 30 highest-yield SOC facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
- When reporting on the Processing Integrity trust service criterion, which data quality dimension is most directly assessed? → Accuracy, completeness, and timeliness of data processing
- In SOC practice, what is a needs assessment? → A systematic process to identify gaps between current conditions and desired outcomes
- What is the purpose of 'walkthrough procedures' in a SOC audit? → To confirm that the auditor's understanding of controls matches how they actually operate
- Which of the following is a characteristic of 'sufficient' audit evidence under attestation standards? → There is enough of it to support the auditor's conclusion
- Which digital tool would an auditor most likely review to evaluate a service organization's change management controls? → A ticketing system with change request records and approvals
- A SOC 2 report's distribution list is restricted to which parties? → Existing user entities, prospective user entities with a signed NDA, and their auditors
- For a SOC 2 engagement, management of the service organization is responsible for: → Preparing the description of the system and providing a written assertion
- Which party is responsible for preparing the system description included in a SOC 2 report? → Management of the service organization
- Which phase comes immediately after evidence gathering in an audit process? → Evaluation and reporting
- Which COSO framework component is concerned with identifying and analyzing risks to the achievement of organizational objectives? → Risk Assessment
- Which of the following is an example of a preventive control for information security? → Requiring multi-factor authentication before system access
- When an auditor traces a transaction from its origination through the system to the final record, this technique is called: → Tracing
- What does MTTR measure in the context of disaster recovery and system reliability? → The average time required to restore a failed system to normal operation
- Under CC3.2, an entity is required to analyze risks considering which two dimensions? → Likelihood and impact
- Which standard governs the performance of a SOC 2 engagement by a CPA firm? → SSAE No. 18 AT-C Section 205
- In SOC practice, what is a corrective action plan? → A documented strategy to address identified compliance deficiencies and prevent recurrence
- Which concept best describes the process of identifying improvements to controls based on lessons learned from prior SOC audit cycles? → Root cause analysis and remediation tracking
- Which AICPA standard governs the performance of SOC 1 engagements? → SSAE No. 18 (AT-C Section 320)
- Which risk response strategy involves shifting the financial consequences of a risk to a third party, such as through insurance? → Risk sharing
- Which metric is most relevant when analyzing the effectiveness of an access control related to SOC 2 Security criteria? → Rate of unauthorized access attempts that were successfully blocked
- A cloud service provider uses infrastructure-as-code (IaC) tools for system deployments. How does this practice support SOC 2 compliance? → It enforces consistent, auditable, and repeatable environment configurations
- A project team building a SOC compliance roadmap uses a work breakdown structure (WBS). What does the WBS primarily provide? → A hierarchical decomposition of project deliverables into manageable components
- Which of the following best describes a 'residual risk' in a SOC audit context? → The risk that remains after controls have been applied
- In a SOC engagement, 'inherent risk' refers to risk: → Before considering any controls or risk responses
- In SOC practice, what is the purpose of a standard operating procedure (SOP)? → To document step-by-step instructions for routine tasks to ensure consistency and quality
- Which of the following is an example of a 'logical access' control that would commonly appear as a control objective in a SOC 2 Security category? → Multi-factor authentication for system logins
- Which risk response strategy is most appropriate when the cost of mitigating a project risk exceeds the potential impact? → Accept
- When assessing fraud risk under SOC 2, which COSO component does the service organization primarily address? → Risk Assessment
- What is the primary goal of access control in information security? → Restrict unauthorized access
- Which Trust Services Criteria category is MANDATORY for every SOC 2 engagement? → Security (Common Criteria)
Turn these facts into recall:
Was this helpful?