Hard1 markMultiple Choice
Area III: SOC EngagementsSOC ReportingAudit OpinionsSOC 2

CPA · Question 33 · Area III: SOC Engagements

A service auditor is issuing a SOC 2® Type II report. Testing identified that a key control for revoking terminated user access failed in 5 out of 25 instances sampled. The failure resulted in terminated employees retaining access for up to 2 weeks. What type of opinion should the auditor likely issue?

Answer options:

A.

Unqualified opinion

B.

Qualified opinion

C.

Disclaimer of opinion

D.

Adverse opinion

How to approach this question

Assess severity. Small error = Unqualified with exceptions. Material error = Qualified. Pervasive failure = Adverse. 20% failure on access control is material.

Full Answer

B.Qualified opinion✓ Correct
B
A qualified opinion states that the controls were effective 'except for' the specific matter identified. A 20% failure rate in a key security control is material enough to prevent an unqualified opinion but typically results in a qualification rather than an adverse opinion unless the breach was pervasive across all criteria.

Common mistakes

Thinking any error = Adverse.

Practice the full CPA ISC Practice Exam

82 questions · hints · full answers · grading

More questions from this exam