M03_Risk assessment –IT understanding

M03_Risk assessment – IT understanding

Professional Development

6 Qs

quiz-placeholder

Similar activities

All About Vehicles

All About Vehicles

4th Grade - Professional Development

11 Qs

Level 1 - Certification

Level 1 - Certification

Professional Development

10 Qs

CompTIA Workshop

CompTIA Workshop

Professional Development

8 Qs

IS101 - Hardware Review after Assembly

IS101 - Hardware Review after Assembly

Professional Development

10 Qs

Meeting 3 - Software and Operating System - 12.2B.21

Meeting 3 - Software and Operating System - 12.2B.21

Professional Development

10 Qs

ICOFR INSIGHT SERIES #2

ICOFR INSIGHT SERIES #2

Professional Development

10 Qs

Prosedur seleksi,evaluasi dan pengembangan vendor

Prosedur seleksi,evaluasi dan pengembangan vendor

Professional Development

10 Qs

M03_Risk assessment –IT understanding

M03_Risk assessment – IT understanding

Assessment

Quiz

Other

Professional Development

Medium

Created by

Lily Lin

Used 1+ times

FREE Resource

6 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

1 min • 1 pt

M03Q1. During your audit engagements, what layers of technology do you commonly identify as relevant? Select all that apply.

Application

Database

Operating system

Network

2.

MULTIPLE SELECT QUESTION

1 min • 1 pt

M03Q2. Based on the scenario presented, which layers would be considered relevant to risk assessment?

Application, Database and Operating System.

Application and Operating System.

Application and Database

Database and Operating System

3.

MULTIPLE SELECT QUESTION

1 min • 1 pt

M03Q3. What areas does the engagement team document in the IT Understanding Screen?

How the entity uses IT as part of financial reporting and related business processes.

The entity’s IT organization.

The entity’s IT policies and procedures.

All of the above.

4.

MULTIPLE SELECT QUESTION

2 mins • 1 pt

M03Q4. When do we use the SSC instructions and reporting templates in KAEG?

To document your evaluation of a service organization controls (SOC) report.

To communicate the nature, timing and extent of procedures performed by the SSC auditor on behalf of the group engagement team and/or SSC user auditors.

When a SOC report is not provided by the Service Organization.

When the SSC auditor identifies issues that may require an audit response.

5.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

M03Q5. Did you find it easy navigating KAEG?

Yes

No

6.

MULTIPLE SELECT QUESTION

2 mins • 1 pt

M03Q6. When do we involve a team member with specialization in IT in response to a cybersecurity incident?

When an exception is noted during your testing of database access.

If an interface from an external source does not successfully complete.

When a cybersecurity incident at any layer comes to your attention during the audit.

When an terminated employee retains access privileges to a financially relevant application.