SOC Risk and Control Objectives 3 — Questions and Answers
Question 1: Which SOC 2 criterion addresses the requirement for an organization to implement controls to prevent or detect unauthorized access to systems?
- CC3.2
- CC6.1 (Correct answer)
- CC4.1
- CC8.1
Correct answer: CC6.1
CC6.1 requires the entity to implement logical access security software, infrastructure, and architectures to protect against threats from sources outside its boundaries.
Question 2: What is the key difference between a Type 1 and Type 2 SOC report?
- Type 1 covers operational controls; Type 2 covers financial controls
- Type 1 reports on design suitability at a point in time; Type 2 reports on operating effectiveness over a period (Correct answer)
- Type 1 is for cloud vendors; Type 2 is for on-premise vendors
- Type 1 requires a walkthrough; Type 2 requires only inquiry
Correct answer: Type 1 reports on design suitability at a point in time; Type 2 reports on operating effectiveness over a period
A Type 1 report assesses whether controls are suitably designed as of a specific date, while a Type 2 report also tests whether those controls operated effectively throughout the review period.
Question 3: Under CC3.2, an entity is required to analyze risks considering which two dimensions?
- Likelihood and impact (Correct answer)
- Frequency and severity
- Probability and cost
- Exposure and velocity
Correct answer: Likelihood and impact
CC3.2 requires management to estimate the significance of identified risks using likelihood and impact as the two primary dimensions of risk analysis.
Question 4: A company's SOC 2 report lists 'employee security awareness training' as a control. If no training records exist for the review period, what type of finding would this generate?
- A qualified opinion with an exception noted
- A control deficiency or deviation from the stated control (Correct answer)
- An adverse opinion on the entire report
- A scope limitation requiring a disclaimer
Correct answer: A control deficiency or deviation from the stated control
Missing evidence of control operation results in a control deviation or deficiency, which the service auditor documents in the report's test results.
Question 5: Which risk response strategy involves shifting the financial consequences of a risk to a third party, such as through insurance?
- Risk avoidance
- Risk reduction
- Risk sharing (Correct answer)
- Risk acceptance
Correct answer: Risk sharing
Risk sharing (or transfer) moves the financial impact of a risk to another party, commonly accomplished through insurance or contractual agreements.
Question 6: In a SOC 1 report, which party is responsible for the completeness and accuracy of the system description?
- The service auditor
- The user auditor
- The service organization's management (Correct answer)
- The AICPA
Correct answer: The service organization's management
The service organization's management is responsible for preparing the description of its system and for the assertion that the description is fairly presented.
Question 7: What does the 'control environment' component of COSO primarily influence in a SOC engagement?
- The technical configuration of IT systems
- The tone and culture that shapes how controls are designed and operated (Correct answer)
- The frequency of control testing by auditors
- The selection of applicable trust services criteria
Correct answer: The tone and culture that shapes how controls are designed and operated
The control environment is the foundation of COSO and reflects management's philosophy, ethical values, and commitment to competence, all of which influence how other controls function.
Which SOC 2 criterion addresses the requirement for an organization to implement controls to prevent or detect unauthorized access to systems?