Free MCQ tier

5,000 CPA practice questions are live across all six sections.

ISC topic guide

SOC 1 vs SOC 2 for ISC CPA candidates.

SOC 1 and SOC 2 questions are mostly about purpose. The right report depends on the risk, user, control objective, and what the report is meant to support.

By World of Accountants editorial team. Last reviewed August 23, 2026. World of Accountants is independent and not affiliated with the AICPA, NASBA, Becker, NINJA, UWorld, Gleim, or other CPA review providers.

ISC sample question

Test the rule before you leave this ISC guide.

Read the topic explanation, then use this real ISC question to check whether the controlling fact is sticking.

ISC-000001ISC-IILogical access

During an IT controls walkthrough, a terminated employee still has access to the accounting system. Which control objective is most directly affected?

  1. A.Logical access should be removed timely when access is no longer appropriate.
  2. B.Physical inventory observation
  3. C.Depreciation accuracy
  4. D.Revenue cutoff only
Answer: A. Logical access should be removed timely when access is no longer appropriate.

Logical access should be removed timely when access is no longer appropriate.

Why the other answers are wrong
  • B. The choice "Physical inventory observation" misses the issue because inventory observation does not address system access.
  • C. The choice "Depreciation accuracy" misses the issue because depreciation accuracy is not the direct access-control issue.
  • D. The choice "Revenue cutoff only" misses the issue because access problems can affect many processes, not only cutoff.

Core idea

SOC 1 reports focus on controls relevant to user entities' internal control over financial reporting. SOC 2 reports focus on trust services criteria such as security, availability, processing integrity, confidentiality, or privacy.

What ISC likes to test

Expect report purpose, intended users, complementary user entity controls, Type 1 versus Type 2, scope, period covered, and whether the report fits the question's risk.

Common miss

Candidates often choose SOC 2 because it sounds more technical, even when the question is about financial reporting controls.

How to practice

Ask what the user needs evidence about: financial reporting controls point toward SOC 1; broader trust services criteria point toward SOC 2.

Practice loop

Use the topic, then answer questions while the idea is fresh.

Short practice sets are enough to expose whether the rule is sticking.

Practice ISC questions