Free CPA ISC (Information Systems & Controls) Considerations for SOC Engagements Practice Questions

SOC engagement considerations on the CPA ISC exam cover SOC 1 (ICFR), SOC 2 (trust services criteria), and SOC 3 reports, control design and operating effectiveness testing, and reporting requirements under SSAE standards.

201 questions 78 easy 74 medium 49 hard 2026 syllabus

Sample Questions

Question 1 Easy
In a SOC 2 engagement, the Availability criterion evaluates:
Solution
A is correct.

The Availability criterion in the Trust Services Criteria evaluates whether the system is available for operation and use as committed or agreed upon, typically as defined in service level agreements. This includes controls over system monitoring, capacity planning, redundancy, failover mechanisms, incident management, and disaster recovery that support the system's operational availability.
Question 2 Medium
How does a SOC for Cybersecurity engagement differ from a SOC 2 engagement?
Solution
A is correct.

A key distinction is that a SOC for Cybersecurity engagement evaluates an entity's enterprise-wide cybersecurity risk management program, not a specific system or service, and the resulting report is intended for general use by a broad range of stakeholders. In contrast, a SOC 2 engagement evaluates controls at a service organization related to the Trust Services Criteria for a specific system or service, and the report is restricted to user entities, their auditors, and certain specified parties. The SOC for Cybersecurity engagement also relies on management's description criteria and on control criteria that may come from any suitable framework, while SOC 2 reports against the AICPA Trust Services Criteria.
Question 3 Hard
Management is considering a SOC for Cybersecurity examination to provide assurance about its cybersecurity risk management program. How does this engagement differ from a SOC 2 examination?
Solution
D is correct.

SOC for Cybersecurity and SOC 2 are fundamentally different engagement types. SOC for Cybersecurity evaluates an entity's cybersecurity risk management program at the organization level, covering governance, risk assessment processes, communication, monitoring activities, and the cybersecurity controls themselves. It uses the AICPA's description criteria for the management description and allows the entity to select its own control criteria, such as the NIST Cybersecurity Framework or the Trust Services Criteria. Any organization can undergo a SOC for Cybersecurity examination; it is not limited to service organizations. In contrast, SOC 2 is specifically designed for service organizations and evaluates controls related to a defined system or service against the Trust Services Criteria. The report audience also differs: SOC for Cybersecurity reports are intended for a broad range of stakeholders, while SOC 2 reports are restricted-use.

Guides & Articles

About FreeFellow

Jeffrey Ting, founder of FreeFellow
Jeffrey Ting
FSA, CFA · Founder

FreeFellow was built by Jeffrey Ting, a credentialed actuary and CFA charterholder who has passed thirteen of the hardest exams in finance, all on his first attempt. He paid four-figure prep fees along the way.

So he started writing his own questions, then lessons, then mock exams, until it grew into a full prep platform covering 40 exams with more than 45,000 original practice questions.

01
Cost shouldn't decide who gets in.

A CFA charter, a CPA license, an actuarial credential. Each opens a real career, but prep fees add to the cost of getting there. FreeFellow keeps its original question bank and written lessons free so you can study even if a paid course is out of reach.

02
Free should mean free.

The original question bank, the worked solutions, the topic lessons, mixed practice, and your readiness score stay free, forever. Full access needs a free account, and practice usage limits apply. Fellow adds AI grading on supported exams, spaced-repetition flashcards, full-length mock exams, analytics, and a study plan that adapts to your progress.