cc6.1-4-001

CC6.1 · D4 · f1

D4
Difficulty
3
Gaps
1
Red Herrings
80%
Avg Score

Task

You are conducting a SOC 2 Type II readiness assessment for Vantage Corp covering Q4 2025 (October 1 – December 31, 2025). You have been provided with multiple evidence artifacts. Review all documents, cross-reference them, and assess compliance with CC6.1 (Logical Access Security). Note that not all documents may be relevant to this control. Identify genuine findings only — consider whether exceptions or compensating controls adequately address apparent gaps before flagging them.

Evidence

Findings

IDTypeSeverityFinding
F-001red_herringlowLegacy ETL service account has a manual key (but has valid CISO exception)
The legacy-etl service account has a manually created key, violating the policy's workload identity requirement. However, the exception register shows EXC-2025-004 — a current, CISO-approved exception...
F-002gapcriticalTerraform import service account with editor role still active 9 months after use
terraform-import has roles/editor (extremely broad permissions) and a key that was last used March 12, 2025. The exception register shows EXC-2025-003 expired on April 8, 2025. The key and service acc...
F-003gaphighMonitoring agent exception expired but key still in use
The monitoring-agent service account has a manually created key (violating workload identity policy). Exception EXC-2025-002 covered this until December 10, 2025 — but the key was still actively used ...
F-004gapmediumLegacy ETL exception compensating control (key rotation) not evidenced
EXC-2025-001 and its renewal EXC-2025-004 list compensating controls including 'key stored in HashiCorp Vault' and 'automated daily key usage audit.' However, the GCP service account data shows the le...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic100%100%100%100%3/33
Opus 4.7Anthropic75%100%60%75%3/35
GPT-5.5OpenAI100%100%100%100%3/33
GPT-4.1OpenAI86%100%75%86%3/34
Haiku 4.5Anthropic67%100%50%67%3/36
GPT-4oOpenAI50%67%40%50%2/35