SOC Business Continuity and Disaster Recovery 2 — Questions and Answers
Question 1: Which availability monitoring control best satisfies AICPA Trust Services Criteria requirements?
- Reviewing employee access logs to detect unauthorized login attempts
- Conducting quarterly penetration tests on production systems
- Encrypting all data at rest using AES-256 encryption standards
- Tracking system uptime against documented SLAs and investigating deviations (Correct answer)
Correct answer: Tracking system uptime against documented SLAs and investigating deviations
Monitoring actual uptime against committed SLAs and formally investigating deviations directly addresses the AICPA Availability criterion's requirement to meet performance commitments.
Question 2: What is the key distinction between a SOC 2 Type I and Type II report for business continuity controls?
- Type I evaluates control design at a point in time; Type II tests operating effectiveness over a period (Correct answer)
- Type I covers all five Trust Services Criteria; Type II covers only availability and security
- Type I is restricted to management; Type II is available for public distribution
- Type I focuses on financial reporting controls; Type II focuses on operational controls
Correct answer: Type I evaluates control design at a point in time; Type II tests operating effectiveness over a period
A SOC 2 Type I assesses whether controls are suitably designed at a specific date, while Type II assesses whether those controls operated effectively over a review period (typically 6–12 months).
Question 3: Which backup storage practice best supports SOC 2 availability and continuity requirements?
- Storing unencrypted backups on-site for the fastest possible restore times
- Keeping all backup copies in the primary data center to simplify management
- Encrypting backups and storing them at a geographically separated off-site location (Correct answer)
- Archiving backups to removable media in a locked cabinet within the same building
Correct answer: Encrypting backups and storing them at a geographically separated off-site location
Encrypting and storing backups at a geographically separate location protects against both unauthorized disclosure and site-wide disasters, supporting both the availability and confidentiality criteria.
Question 4: What does MTTR measure in the context of disaster recovery and system reliability?
- The maximum tolerable time allowed before declaring a formal disaster
- The average time required to restore a failed system to normal operation (Correct answer)
- The minimum testing time required for DR plan certification
- The mean number of transactions processed per recovery hour
Correct answer: The average time required to restore a failed system to normal operation
MTTR (Mean Time to Repair or Recover) is an operational metric reflecting the average time it takes to restore a failed system, indicating the efficiency of incident response and recovery processes.
Question 5: A SOC 2 auditor discovers the service organization's DR plan has not been tested in over 18 months. What is the most likely audit impact?
- No audit impact if the plan is comprehensive and well-documented
- A qualified opinion covering all five Trust Services Criteria
- A finding limited to the processing integrity criterion only
- A noted control deficiency, as untested plans cannot demonstrate operating effectiveness (Correct answer)
Correct answer: A noted control deficiency, as untested plans cannot demonstrate operating effectiveness
SOC 2 Type II requires evidence of operating effectiveness; a plan that has never been tested provides no such evidence, resulting in a documented control deficiency.
Question 6: Which NIST publication provides comprehensive guidance on IT contingency planning?
- NIST SP 800-34: Contingency Planning Guide for Federal Information Systems (Correct answer)
- NIST SP 800-53: Security and Privacy Controls for Information Systems
- NIST SP 800-37: Risk Management Framework for Information Systems
- NIST SP 800-61: Computer Security Incident Handling Guide
Correct answer: NIST SP 800-34: Contingency Planning Guide for Federal Information Systems
NIST SP 800-34 is specifically dedicated to IT contingency planning, covering BIA, recovery strategy selection, plan development, and testing.
Question 7: What is the primary operational difference between a warm site and a cold site?
- A warm site is cloud-hosted; a cold site requires physical infrastructure installation
- A warm site has hardware pre-installed but needs data restoration; a cold site requires complete setup from scratch (Correct answer)
- A warm site supports only read-only operations; a cold site supports full production workloads
- A warm site is maintained by a third party; a cold site is owned exclusively by the organization
Correct answer: A warm site has hardware pre-installed but needs data restoration; a cold site requires complete setup from scratch
A warm site has hardware and connectivity ready but requires restoring data and configuring applications, while a cold site is an empty facility requiring both equipment and data to be set up before use.
Which availability monitoring control best satisfies AICPA Trust Services Criteria requirements?