SSCP Security Auditing & Compliance Standards 2 — Questions and Answers
Question 1: Which audit type is performed without prior notice to the auditee to capture the true state of security controls?
- Announced audit
- Unannounced audit (Correct answer)
- Compliance audit
- Certification audit
Correct answer: Unannounced audit
Unannounced audits capture the genuine state of controls because staff cannot prepare or temporarily implement missing safeguards.
Question 2: Under HIPAA Security Rule, which of the following is a required implementation specification?
- Encryption of all PHI at rest
- Security awareness training
- Automatic logoff
- Audit controls (Correct answer)
Correct answer: Audit controls
Audit controls is a required specification under the Technical Safeguards section of the HIPAA Security Rule, while encryption is addressable.
Question 3: A SOC 2 Type II report differs from a SOC 2 Type I report primarily because it:
- Covers more Trust Services Criteria
- Evaluates control design and operating effectiveness over a period of time (Correct answer)
- Is intended for public release
- Includes financial reporting controls
Correct answer: Evaluates control design and operating effectiveness over a period of time
SOC 2 Type II assesses both the design and operating effectiveness of controls over a defined review period, not just their design at a point in time.
Question 4: Which PCI DSS requirement mandates that cardholder data environments use unique IDs for each person with computer access?
- Requirement 3
- Requirement 7
- Requirement 8 (Correct answer)
- Requirement 10
Correct answer: Requirement 8
PCI DSS Requirement 8 requires that all users be assigned a unique ID to ensure accountability and traceability of actions.
Question 5: Which term describes the practice of comparing an organization's security controls against an established baseline or best-practice framework?
- Gap analysis (Correct answer)
- Threat modeling
- Risk transference
- Vulnerability scanning
Correct answer: Gap analysis
A gap analysis identifies differences between the current state of controls and the desired baseline or framework requirements.
Question 6: The NIST Cybersecurity Framework's 'Identify' function primarily focuses on:
- Detecting anomalous events
- Developing organizational understanding of cybersecurity risk (Correct answer)
- Containing security incidents
- Recovering normal operations
Correct answer: Developing organizational understanding of cybersecurity risk
The Identify function helps organizations develop understanding of their assets, risks, and governance to manage cybersecurity risk.
Question 7: An auditor discovers that access rights have not been reviewed in 18 months. Which audit finding category best describes this?
- Observation
- Minor nonconformity
- Major nonconformity (Correct answer)
- Opportunity for improvement
Correct answer: Major nonconformity
A major nonconformity indicates a systematic failure or absence of a required control, such as a completely missing access review process.
Which audit type is performed without prior notice to the auditee to capture the true state of security controls?