VIP Exclusive

SOC — System and Organization Controls VIP Practice Exam

SOC — This exam mirrors the knowledge domains required for AICPA SOC engagements (SOC 1, SOC 2, and SOC 3), as defined by the AICPA's AT-C Section 320 and the Trust Services Criteria (TSC). There is no single standardized SOC 'certification exam' — professionals performing SOC audits are typically CPAs or hold credentials such as CISA or CISSP; this is an original comprehensive practice set covering SOC engagement fundamentals, Trust Services Criteria, control testing, and reporting.

56
Questions
120m
Time Limit
75.00%
To Pass
Question 1 of 56👑 VIP

A service auditor is engaged to perform a SOC 2 Type II examination for a cloud-based payroll processing company. The engagement covers the period January 1 through December 31. During fieldwork, the auditor discovers that the company's logical access review process was not performed for the months of March and April due to a staff transition. Which of the following best describes how this finding should be reflected in the auditor's report?

Questions 2–56 and full explanations are VIP-exclusive.