Free CPA ISC (Information Systems & Controls) Considerations for SOC Engagements Practice Questions
SOC engagement considerations on the CPA ISC exam cover SOC 1 (ICFR), SOC 2 (trust services criteria), and SOC 3 reports, control design and operating effectiveness testing, and reporting requirements under SSAE standards.
202 questions75 easy76 medium51 hard2026 syllabus
Sample Questions
Question 1
Easy
What is the PRIMARY difference between a SOC 2 report and a SOC 3 report?
🎉
Correct Answer: D
Solution
D is correct.
The primary difference between SOC 2 and SOC 3 reports is their intended audience and level of detail. A SOC 2 report is a restricted-use report intended for the service organization, user entities, and their auditors. It contains detailed descriptions of the service organization's system, the controls in place, the tests performed by the service auditor, and the results of those tests. A SOC 3 report is a general-use report that can be freely distributed (including on the service organization's website). It contains the auditor's opinion on whether controls were effective but does not include detailed control descriptions, test procedures, or test results. Both use the Trust Services Criteria.
Question 2
Medium
A SOC 2+ engagement differs from a standard SOC 2 engagement in that a SOC 2+ report:
🎉
Correct Answer: A
Solution
A is correct.
A SOC 2+ engagement includes the standard Trust Services Criteria plus additional criteria from other frameworks such as HIPAA, NIST Cybersecurity Framework, ISO 27001, or the Cloud Security Alliance STAR framework. The additional criteria are mapped alongside the Trust Services Criteria, allowing the service organization to demonstrate compliance with multiple standards in a single report.
Question 3
Hard
A financial technology company processes electronic funds transfers on behalf of 200 bank clients. The company is evaluating whether to obtain a SOC 1 or SOC 2 examination. Each bank client's external auditor reviews IT general controls as part of the banks' financial statement audits. Which SOC report is MOST appropriate?
🎉
Correct Answer: A
Solution
A is correct.
The key criterion for choosing between SOC 1 and SOC 2 is whether the service organization's controls are likely to be relevant to user entities' internal control over financial reporting. SOC 1 (under SSAE 18) is designed specifically for service organizations whose controls affect their clients' financial reporting. An EFT processor that moves funds on behalf of banks directly impacts those banks' cash balances and transaction recording; the controls over transaction completeness, accuracy, and authorization directly affect the banks' financial statements. Bank clients' external auditors will need the SOC 1 Type II report to evaluate ITGC for their financial statement audit, not a SOC 2 report.
FreeFellow was built by Jeffrey Ting, a credentialed actuary and CFA charterholder who passed thirteen of the hardest exams in finance on the first attempt, and paid four-figure prep fees for every one. The learning itself was always free. The price was a moat.
So he started writing his own questions, then lessons, then mock exams, until it grew into a full prep platform covering 35 finance credentials with more than 40,000 original practice questions. The name says exactly what it is: the question bank is free, and Fellow is what you become once you pass.
01
Cost shouldn't decide who gets in.
The exam is a fair gate. A four-figure prep course is not. FreeFellow takes the second gate down, so the exam is the only one left.
02
Free should mean free.
No trial clock, no email gate, no credit card. The question bank, worked solutions, lessons, and readiness score stay free, and they are enough to pass.
03
Built by someone who sat where you sit.
He paid for the big-name courses, found nothing he respected, and built the prep he wished had existed. Not a marketing team that has never sat an exam.