WorksheetsComputer Security - IT Audit
Total questions: 15
Worksheet time: 6mins
Name
Class
Date
1.
IT _____________ is a process that provides assurance for IT and IS and helps to mitigate risks associated with use of technology.
a)
control
b)
governance
c)
risk management
d)
review
2.
An internal audit is typically conducted by auditors who work for the organization, but this task may be outsourced to other organizations.
a)
True
b)
False
3.
Which of the following components is not part of IT governance?
a)
control planning
b)
security assessment
c)
managing incident response
d)
control development
4.
Which of the following components is not part of IT compliance?
a)
IT audit
b)
security assessment
c)
control development
d)
IT compliance assessment
5.
An audit _____________ outlines the overall authority, scope and responsibilities of the audit function.
a)
exit report
b)
comprehensive report
c)
letter of intent
d)
charter
6.
Fieldwork is part of the ______________ process
a)
assessment
b)
reporting
c)
follow-up
d)
planning
7.
The audit response verification can be obtained at the _______________ stage of an IT audit.
a)
assessment
b)
report
c)
follow-up
d)
planning
8.
The scope of an IT audit often varies, but can involve any combination of the following:
a)
organizational, compliance, application and social
b)
organizational, compliance, application and technical
c)
regional, compliance, application and technical
d)
organizational, compliance, systems and technical
9.
Which of the following is an IT security audit program goal?
a)
Provide an objective and independent review of an organization’s policies, information systems and controls.
b)
Provide reasonable assurance that appropriate and effective IT controls are in place.
c)
Provide audit recommendations for both corrective actions and improvement to controls.
d)
All of the answers are correct.
10.
A threat profile refers to:
a)
what is the likelihood of the threats happening.
b)
what threats or risks will affect the asset.
c)
what impact or effect would the loss of the asset have on the operation of the organization or its personnel.
d)
All of the above are correct.
11.
The diagram above refers to:
a)
how audit goals are determined.
b)
how audit reviews are analysed.
c)
how audit reports are created.
d)
how an audit is conducted.
12.
In an IT audit, the exit meeting:
a)
discusses preliminary findings.
b)
determines all problems found.
c)
is where the chief auditor reads his/her final audit report.
d)
already determines the answers from auditees beforehand.
13.
The IS auditor must use instinct when deciding which findings to present to various levels of management.
a)
True
b)
False
14.
The IS auditor should always judge which findings are material to various levels of management and should report them accordingly.
a)
True
b)
False
15.
Audit documentation includes all of the following EXCEPT:
a)
audit program
b)
audit steps performed
c)
audit charter
d)
audit recommendations
100 %
