Back to Questions
CISA
QUESTION #6852
Question 1
In evaluating a cloud service provider, an auditor finds the provider has SOC 2 Type I certification but no Type II certification. What is the PRIMARY limitation of Type I certification?
Correct Answer Explanation
SOC 2 Type I reports evaluate whether controls are suitably designed at a specific point in time. Type II reports test whether controls operated effectively over a period (usually 6-12 months). Type I provides significantly less assurance because well-designed controls might not be consistently implemented or effective in practice.
Sign in to join the conversation and share your thoughts.
Log In to Comment