Free MCQ tier

5,000 CPA practice questions are live across all six sections.

ISC topic guide

SOC reports explained for ISC CPA candidates.

SOC report questions usually test whether you understand who controls what, what the report covers, and what the user entity still has to do.

By World of Accountants editorial team. Last reviewed August 23, 2026. World of Accountants is independent and not affiliated with the AICPA, NASBA, Becker, NINJA, UWorld, Gleim, or other CPA review providers.

ISC sample question

Test the rule before you leave this ISC guide.

Read the topic explanation, then use this real ISC question to check whether the controlling fact is sticking.

ISC-000001ISC-IILogical access

During an IT controls walkthrough, a terminated employee still has access to the accounting system. Which control objective is most directly affected?

  1. A.Logical access should be removed timely when access is no longer appropriate.
  2. B.Physical inventory observation
  3. C.Depreciation accuracy
  4. D.Revenue cutoff only
Answer: A. Logical access should be removed timely when access is no longer appropriate.

Logical access should be removed timely when access is no longer appropriate.

Why the other answers are wrong
  • B. The choice "Physical inventory observation" misses the issue because inventory observation does not address system access.
  • C. The choice "Depreciation accuracy" misses the issue because depreciation accuracy is not the direct access-control issue.
  • D. The choice "Revenue cutoff only" misses the issue because access problems can affect many processes, not only cutoff.

Core idea

A SOC report gives information about controls at a service organization. It does not automatically replace the user entity's own controls.

What ISC likes to test

Watch for report scope, complementary user entity controls, control objectives, service commitments, and whether the report evidence fits the user's risk.

Common miss

Candidates often assume a clean SOC report means no user-side control work is needed. Complementary user entity controls still matter.

How to practice

For each SOC question, identify the service organization, the user entity, the control objective, and who is responsible for the control.

Practice loop

Use the topic, then answer questions while the idea is fresh.

Short practice sets are enough to expose whether the rule is sticking.

Practice ISC questions