For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeCPA®CPA ISC Practice ExamQuestion 14
    Medium1 markMultiple Choice
    Area I: Information SystemsCloud ComputingSaaSAudit EvidenceSOC 2

    CPA · Question 14 · Area I: Information Systems

    A company uses a SaaS-based CRM. The auditor wants to verify that the company's data is backed up. The SaaS provider's contract states they perform daily backups. What is the MOST appropriate evidence for the auditor to request?

    Answer options:

    A.

    Screenshots of the company's internal server backup logs.

    B.

    A written representation from the company's IT manager.

    C.

    The SaaS provider's source code for the backup script.

    D.

    A SOC 2 Type II report from the SaaS provider covering the Availability criteria.

    How to approach this question

    When auditing a cloud vendor (SaaS), you generally cannot go onsite. You rely on Third-Party Assurance reports (SOC reports).

    Full Answer

    D.A SOC 2 Type II report from the SaaS provider covering the Availability criteria.✓ Correct
    For SaaS vendors, the most appropriate and reliable evidence is a SOC 2 report (specifically covering Availability) which provides an independent auditor's opinion on the design and operating effectiveness of the provider's backup controls.

    Common mistakes

    Thinking the client can back up SaaS data themselves (sometimes they can, but the question asks about the provider's obligation).
    Question 13All questionsQuestion 15

    Practice the full CPA ISC Practice Exam

    82 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A CPA is performing a risk assessment for a client that uses a public cloud provider for its core...HardQ02During a walkthrough of a client's change management process, the auditor notes that developers h...HardQ03A service organization provides a real-time transaction processing platform. The service level ag...HardQ04An auditor is reviewing a SQL query used by the finance team to generate a report of all sales tr...HardQ05A healthcare clearinghouse is preparing for a SOC 2® engagement. They utilize a private cloud dep...Hard
    View all 82 questions →