Free CPA ISC (Information Systems & Controls) Security, Confidentiality and Privacy Practice Questions

Security, confidentiality, and privacy on the CPA ISC exam tests cybersecurity frameworks (NIST), access control mechanisms, encryption standards, incident response procedures, data privacy regulations (GDPR, CCPA), and IT risk assessment methodologies.

425 questions 208 easy 154 medium 63 hard 2026 syllabus

Sample Questions

Question 1 Easy
Which Trust Services criterion is included in every SOC 2 examination?
Solution
B is correct.

In a SOC 2 engagement, the Security criterion (also called the Common Criteria) is mandatory and must be included in every examination. Security is considered the foundation because it addresses the protection of information and systems against unauthorized access, which underpins the other four optional criteria (Availability, Processing Integrity, Confidentiality, and Privacy). Organizations select which additional criteria to include based on their services and client needs, but Security is never optional. This structure comes from the AICPA Trust Services Criteria.
Question 2 Medium
The authentication method providing the strongest protection against credential theft through phishing attacks is:
Solution
A is correct.

FIDO2 hardware security keys provide the strongest phishing resistance among these methods by binding authentication to the legitimate website's origin. A phishing site using a different origin cannot obtain a valid authentication response for the legitimate site. The private key remains on the device rather than being submitted as a reusable credential.
Question 3 Hard
For a firm comparing the NIST Cybersecurity Framework (CSF) 2.0 with the AICPA Trust Services Criteria (TSC), the key distinction in their scope and application is that:
Solution
C is correct.

The NIST CSF 2.0 is a voluntary framework (not a regulation) that organizes cybersecurity risk management activities into six core functions - Govern, Identify, Protect, Detect, Respond, and Recover - and is designed for enterprise-wide use across any sector. The TSC, developed by the AICPA, defines criteria across five categories (security, availability, processing integrity, confidentiality, and privacy) and serves as the basis for SOC 2 attestation engagements performed by CPAs. The key distinction is that the TSC is specifically designed for attestation and reporting, while the NIST CSF is a broader risk management tool.

Guides & Articles

About FreeFellow

Jeffrey Ting, founder of FreeFellow
Jeffrey Ting
FSA, CFA · Founder

FreeFellow was built by Jeffrey Ting, a credentialed actuary and CFA charterholder who has passed thirteen of the hardest exams in finance, all on his first attempt. He paid four-figure prep fees along the way.

So he started writing his own questions, then lessons, then mock exams, until it grew into a full prep platform covering 40 exams with more than 45,000 original practice questions.

01
Cost shouldn't decide who gets in.

A CFA charter, a CPA license, an actuarial credential. Each opens a real career, but prep fees add to the cost of getting there. FreeFellow keeps its original question bank and written lessons free so you can study even if a paid course is out of reach.

02
Free should mean free.

The original question bank, the worked solutions, the topic lessons, mixed practice, and your readiness score stay free, forever. Full access needs a free account, and practice usage limits apply. Fellow adds AI grading on supported exams, spaced-repetition flashcards, full-length mock exams, analytics, and a study plan that adapts to your progress.