▸case-22 Our healthcare application needs to comply with HIPAA Security Rule Administrative Safeguards (§ 164.308). What is the specific requirement regarding security management processes? | pass→pass | 10,896 | 9,145 | -16% | 1 | 1 | 0% | 1,851 | 1,894 | +2% | 0 | 0 | — |
▸case-02 Our enterprise customer insists we provide a SOC 2 Type I report covering our security operations over the past 12 months. Is a Type I report the appropriate vehicle for evaluating operational effectiveness across a historical timeframe? | pass→pass | 12,518 | 13,180 | +5% | 1 | 1 | 0% | 1,915 | 2,343 | +22% | 0 | 0 | — |
▸case-07 Our internal compliance team conducts monthly internal audit samplings and presents security metric reviews to executive leadership. Which CC series section specifically tracks ongoing monitoring activities? | pass→pass | 3,993 | 5,599 | +40% | 1 | 1 | 0% | 624 | 1,210 | +94% | 0 | 0 | — |
▸case-16 A B2C application processes consumer personal data, requiring user consent management, access rights, and data subject erasure handling under customer agreements. Which Trust Service Category governs this? | pass→pass | 5,699 | 6,665 | +17% | 1 | 1 | 0% | 797 | 1,286 | +61% | 0 | 0 | — |
▸case-01 We are preparing our initial SOC 2 audit for our SaaS enterprise platform. Our product VP suggests we only evaluate Availability and Confidentiality to save money and time, excluding Security. How should our audit scope be structured? | pass→pass | 12,542 | 17,425 | +39% | 1 | 1 | 0% | 1,887 | 2,871 | +52% | 0 | 0 | — |
▸case-03 We are planning our first SOC 2 Type II audit report for our cloud hosting service. Our compliance officer asks what time window the auditor will evaluate for operational effectiveness. What standard historical period length is expected? | pass→pass | 8,491 | 9,009 | +6% | 1 | 1 | 0% | 1,207 | 1,544 | +28% | 0 | 0 | — |
▸case-04 Our security team is mapping internal HR background check procedures, code of conduct attestations, and board security oversight policies to SOC 2 Common Criteria controls. Which specific CC sub-series governs tone at the top and control environment? | pass→pass | 6,552 | 7,464 | +14% | 1 | 1 | 0% | 1,080 | 1,517 | +40% | 0 | 0 | — |
▸case-05 When documenting how security responsibilities are communicated to internal employees and how whistleblower reports are processed, which Common Criteria series section applies? | fail→fail | 10,939 | 8,149 | -26% | 1 | 1 | 0% | 1,683 | 1,622 | -4% | 0 | 0 | — |
▸case-06 We are conducting our annual risk identification matrix update, analyzing potential fraud scenarios and vulnerability impact levels. Which CC series range covers this risk assessment process? | fail→pass | 6,844 | 7,129 | +4% | 1 | 1 | 0% | 1,069 | 1,391 | +30% | 0 | 0 | — |
▸case-08 We are designing automated preventive controls and business procedure safeguards to mitigate system risks. Which CC control block addresses business control activities selection and implementation? | pass→pass | 6,304 | 6,961 | +10% | 1 | 1 | 0% | 1,043 | 1,452 | +39% | 0 | 0 | — |
▸case-09 We need to map our Okta multi-factor authentication policies, AWS IAM role RBAC reviews, and physical data center badge log reviews to SOC 2. Which CC control series handles logical and physical access management? | fail→fail | 6,220 | 7,377 | +19% | 1 | 1 | 0% | 1,083 | 1,450 | +34% | 0 | 0 | — |
▸case-10 Our SRE team wants to align daily incident response drills, patch management routines, and anomaly detection monitoring against SOC 2 criteria. Which CC series covers system operations and vulnerability detection? | fail→pass | 8,898 | 11,917 | +34% | 1 | 1 | 0% | 1,413 | 2,031 | +44% | 0 | 0 | — |
▸case-11 Our DevOps pipeline enforces peer code reviews, CI/CD testing gates, and approval workflows before production deployment. Which specific CC section controls change management? | pass→pass | 7,014 | 8,322 | +19% | 1 | 1 | 0% | 1,098 | 1,584 | +44% | 0 | 0 | — |
▸case-12 We contract third-party vendor risk management tools and maintain insurance coverage for cyber liability to offset systemic operational exposures. Which CC section evaluates risk mitigation strategies? | pass→pass | 7,748 | 6,614 | -15% | 1 | 1 | 0% | 1,157 | 1,368 | +18% | 0 | 0 | — |
▸case-13 An e-commerce company is scoping SOC 2 criteria and needs to ensure their redundant multi-region AWS setup and disaster recovery RTO/RPO objectives are properly evaluated. Which Trust Service Category applies? | pass→pass | 6,908 | 12,873 | +86% | 1 | 1 | 0% | 1,040 | 2,189 | +110% | 0 | 0 | — |
▸case-14 A healthtech startup stores proprietary client trading algorithms and trade secrets under strict non-disclosure obligations. Which specific Trust Service Category explicitly protects confidential business data? | pass→pass | 4,163 | 7,656 | +84% | 1 | 1 | 0% | 633 | 1,306 | +106% | 0 | 0 | — |
▸case-15 A fintech company operates a real-time payment gateway that must guarantee transaction completeness, accuracy, and timely execution without duplicate processing. Which Trust Service Category applies? | pass→pass | 4,379 | 8,072 | +84% | 1 | 1 | 0% | 718 | 1,495 | +108% | 0 | 0 | — |
▸case-17 We are preparing for our first SOC 2 readiness engagement. The CEO asks what output we should produce to highlight unfulfilled criteria before hiring a CPA firm. What tool or exercise provides this mapping? | pass→pass | 11,725 | 13,964 | +19% | 1 | 1 | 0% | 1,725 | 2,395 | +39% | 0 | 0 | — |
▸case-18 During our audit, the CPA firm issued several Information Document Requests (IDR) and raised questions regarding our backup restoration tests. What structured material helps streamline these auditor discussions? | fail→pass | 15,669 | 18,782 | +20% | 1 | 1 | 0% | 2,342 | 2,921 | +25% | 0 | 0 | — |
▸case-19 Our startup wants a fast compliance report to show enterprise buyers that our security controls are properly designed as of today, without waiting 6 months to track logs. Which report type should we request? | pass→pass | 6,973 | 6,715 | -4% | 1 | 1 | 0% | 1,088 | 1,271 | +17% | 0 | 0 | — |
▸case-20 We are mapping our security policies to ISO/IEC 27001:2022 Annex A controls to prepare for an upcoming ISO certification audit. Which ISO control domain covers physical security perimeters? | pass→pass | 4,036 | 5,595 | +39% | 1 | 1 | 0% | 685 | 1,235 | +80% | 0 | 0 | — |
▸case-21 We process credit card payments and need to align with PCI DSS v4.0 Requirement 3. What is required for storing Primary Account Numbers (PAN)? | pass→pass | 16,714 | 15,844 | -5% | 1 | 1 | 0% | 2,666 | 2,804 | +5% | 0 | 0 | — |