Free MCQ tier5,000 CPA practice questions are live across all six sections.
ISC sample question
See the kind of ISC judgment this guide prepares you to answer.
Use the example to test your starting point, then move into a focused ISC set while the idea is fresh.
ISC-000001ISC-IILogical access
During an IT controls walkthrough, a terminated employee still has access to the accounting system. Which control objective is most directly affected?
- A.Logical access should be removed timely when access is no longer appropriate.
- B.Physical inventory observation
- C.Depreciation accuracy
- D.Revenue cutoff only
Answer: A. Logical access should be removed timely when access is no longer appropriate.Logical access should be removed timely when access is no longer appropriate.
Why the other answers are wrong
- B. The choice "Physical inventory observation" misses the issue because inventory observation does not address system access.
- C. The choice "Depreciation accuracy" misses the issue because depreciation accuracy is not the direct access-control issue.
- D. The choice "Revenue cutoff only" misses the issue because access problems can affect many processes, not only cutoff.
Study workflow
Use ISC questions as a review system, not a click-through drill.
The fastest way to waste a question bank is to answer a set, glance at the score, and move on. For ISC, treat every missed question as a note about how you read facts, applied rules, or eliminated distractors.
ISC topic guides
Use these ISC topic pages before your next practice set.
ISCSOC reports explained for ISC CPA candidatesService organization reports, user controls, scope, and control responsibility.
ISCSOC 1 vs SOC 2 for ISC CPA candidatesSOC 1 versus SOC 2, ICFR, trust services, report users, and Type 1 vs Type 2.
ISCAccess controls for ISC CPA candidatesLeast privilege, provisioning, deprovisioning, authentication, authorization, and segregation of duties.
AUD / FAR / REG / BAR / ISC / TCPHard CPA practice questions for exam-like reviewHard CPA questions across all six sections with explanations and review tools.
AUD / FAR / REG / BAR / ISC / TCPCPA practice test-style MCQ setsBuild a practice test-style MCQ set with explanations and section filters.
BAR / ISC / TCPBAR vs ISC vs TCP: which CPA discipline should you choose?Compare the three CPA discipline choices before choosing your path.
Sample questions
Try a few ISC examples before opening the full bank.
These are real questions from the current question bank. The practice app includes more questions, filters, explanations, bookmarks, and progress tracking.
ISC-000001ISC-IILogical access
During an IT controls walkthrough, a terminated employee still has access to the accounting system. Which control objective is most directly affected?
- A.Logical access should be removed timely when access is no longer appropriate.
- B.Physical inventory observation
- C.Depreciation accuracy
- D.Revenue cutoff only
Answer: A. Logical access should be removed timely when access is no longer appropriate.Logical access should be removed timely when access is no longer appropriate.
Why the other answers are wrong
- B. The choice "Physical inventory observation" misses the issue because inventory observation does not address system access.
- C. The choice "Depreciation accuracy" misses the issue because depreciation accuracy is not the direct access-control issue.
- D. The choice "Revenue cutoff only" misses the issue because access problems can affect many processes, not only cutoff.
ISC-000002ISC-IChange management
During an IT controls walkthrough, developers can approve and deploy their own production code changes. Which control weakness exists?
- A.Backups are automatically ineffective
- B.Segregation of duties is weak in the change-management process.
- C.Only physical security is affected
- D.The system has no business objective
Answer: B. Segregation of duties is weak in the change-management process.Segregation of duties is weak in the change-management process.
Why the other answers are wrong
- A. The choice "Backups are automatically ineffective" misses the issue because the fact pattern is about change approval and deployment.
- C. The choice "Only physical security is affected" misses the issue because the weakness is logical/process control.
- D. The choice "The system has no business objective" misses the issue because systems can have objectives even with weak change controls.
ISC-000003ISC-IIISystem availability
During an IT controls walkthrough, a company cannot restore critical data during a backup test. Which risk is most direct?
- A.Payroll tax rates are misstated
- B.Inventory costing is automatically wrong
- C.The entity may not be able to recover systems and data when needed.
- D.The risk is eliminated because backups exist
Answer: C. The entity may not be able to recover systems and data when needed.The entity may not be able to recover systems and data when needed.
Why the other answers are wrong
- A. The choice "Payroll tax rates are misstated" misses the issue because the fact pattern is about recovery capability.
- B. The choice "Inventory costing is automatically wrong" misses the issue because backup restoration does not directly determine costing.
- D. The choice "The risk is eliminated because backups exist" misses the issue because untested or failed backups may not support recovery.
ISC-000004ISC-IVSOC reporting
During an IT controls walkthrough, a SOC report identifies complementary user entity controls. What should the user entity do?
- A.Assume the service organization performs all user controls
- B.Document the matter for completion review but make no change unless the amount is individually material
- C.Treat CUECs as financial statement disclosures only
- D.Evaluate whether those complementary controls are designed and operating at the user entity.
Answer: D. Evaluate whether those complementary controls are designed and operating at the user entity.Evaluate whether those complementary controls are designed and operating at the user entity.
Why the other answers are wrong
- A. The choice "Assume the service organization performs all user controls" misses the issue because cUECs are responsibilities of the user entity.
- B. The choice "Ignore the controls because they are outside the report" misses the issue because cUECs are relevant to relying on the report.
- C. The choice "Treat CUECs as financial statement disclosures only" misses the issue because they are control responsibilities, not merely disclosures.
ISC-000005ISC-IIApplication controls
During an IT controls walkthrough, an automated three-way match blocks payment when purchase order, receipt, and invoice details do not agree. What type of control is this?
- A.It is an automated application control.
- B.A manual detective control only
- C.A board governance policy
- D.A disaster recovery control
Answer: A. It is an automated application control.It is an automated application control. The tested issue is Application controls, so the best answer must match that rule and respond directly to the facts in the stem.
Why the other answers are wrong
- B. The choice "A manual detective control only" misses the issue because the system automatically prevents or flags payment.
- C. The choice "A board governance policy" misses the issue because the control operates inside the transaction process.
- D. The choice "A disaster recovery control" misses the issue because the control validates transaction data, not system recovery.
ISC-000006ISC-ILogical access
An access review finds that a terminated system administrator's privileged account remains enabled. Logs show no activity after termination. Which response best addresses the control risk?
- A.Close the finding because the logs show no use
- B.Disable the account, investigate the period of inappropriate access, and determine whether other access records need review
- C.Keep the account enabled for continuity and monitor it annually
- D.Delete the logs so the inactive account cannot be misunderstood
Answer: B. Disable the account, investigate the period of inappropriate access, and determine whether other access records need reviewAn enabled privileged account creates an avoidable unauthorized-access risk even when no activity is currently visible. The account should be disabled and the exposure period investigated.
Why the other answers are wrong
- A. Absence of observed use does not eliminate the risk created by an enabled privileged account.
- C. Continuity does not justify retaining inappropriate privileged access after termination.
- D. Logs are evidence and should be preserved, not deleted.
ISC-000007ISC-IIChange management
A production outage requires an emergency code change. The change is approved verbally and implemented successfully, but the organization has no documented retrospective review process. Which control improvement is most important?
- A.Prohibit every emergency change, regardless of business impact
- B.Allow developers to approve all future changes without documentation
- C.Require a timely post-implementation review of authorization, testing, segregation, and the resulting production change
- D.Delete the emergency ticket after the system is stable
Answer: C. Require a timely post-implementation review of authorization, testing, segregation, and the resulting production changeEmergency changes may be necessary, but a documented retrospective review provides accountability and checks whether the emergency path bypassed required controls or introduced new risk.
Why the other answers are wrong
- A. A mature process manages emergency changes with compensating and retrospective controls rather than prohibiting every urgent response.
- B. Removing documentation and segregation increases the change-management risk.
- D. The ticket is part of the audit trail and should be retained.
ISC-000008ISC-IVSOC reports and user controls
A service organization provides a Type 2 report covering July 1 through June 30, while the user entity's year-end is December 31. Which evidence is most useful for the July-through-December gap?
- A.The service organization's marketing brochure
- B.The prior year's financial statements only
- C.A bridge letter or additional procedures addressing controls during the gap, together with relevant complementary user controls
- D.A statement that the SOC report automatically covers all future periods
Answer: C. A bridge letter or additional procedures addressing controls during the gap, together with relevant complementary user controlsThe report does not cover the six-month gap. A bridge letter or additional procedures can address the period, while the user entity must also evaluate the complementary controls assigned to it.
Why the other answers are wrong
- A. Marketing material does not provide evidence that controls operated during the gap.
- B. Prior-year financial statements do not test current-period service-organization controls.
- D. A Type 2 report has a defined period and does not automatically extend into the future.