wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

RoadtoCertificate Week1

Total questions: 10

Worksheet time: 10mins

Name
Class
Date
1.

1. Which of the following is the PRIMARY purpose of a risk-based audit?

a)

High-impact areas are addressed first.

b)

Audit resources are allocated efficiently.

c)

Material areas are addressed first.

d)

Management concerns are prioritized.

2.

2. An IS auditor notes that failed login attempts to a core financial system are automatically logged and the logs are retained for a year by the organization. This logging is:

a)

An effective preventive control.

b)

A valid detective control.

c)

Not an adequate control.

d)

A corrective control.

3.

3. A centralized antivirus system determines whether each personal computer has the latest signature files and installs the latest signature files before allowing a PC to connect to the network. This is an example of a:

a)

Directive control

b)

Corrective control

c)

Compensating control

d)

Detective control

4.

4. An IS auditor is reviewing a project risk assessment and notices that the overall residual risk level is high due to confidentiality requirements. Which of the following types of risk is normally high due to the number of unauthorized users the project may affect?

a)

Control risk

b)

Compliance risk

c)

Inherent risk

d)

Residual risk

5.

5. An IS auditor is carrying out a system configuration review. Which of the following is the BEST evidence in support of the current system configuration settings?

a)

System configuration values that are imported to a spreadsheet by the system administrator

b)

Standard report with configuration values that are retrieved from the system by the IS auditor

c)

Dated screenshot of the system configuration settings that are made available by the system administrator

d)

Annual review of approved system configuration values by the business owner

6.

6. In a risk-based IS audit, where both inherent and control risk have been assessed as high, an IS auditor would MOST likely compensate for this scenario by performing additional:

a)

Stop-or-go sampling

b)

Substantive testing

c)

Compliance testing

d)

Discovery sampling

7.

7. Which of the following should be the FIRST action of an IS auditor during a dispute with a department manager over audit findings?

a)

Retest the control to validate the finding

b)

Engage a third party to validate the finding

c)

Include the finding in the report with the department manager's comments

d)

Revalidate the supporting evidence for the finding

8.

8. A PRIMARY benefit derived for an organization employing control self-assessment techniques is that it:

a)

Can identify high-risk areas that might need a detailed review later.

b)

Allows IS auditors to independently assess risk

c)

Can be used as a replacement for traditional audits

d)

Allows management to relinquish responsibility for control

9.

9. An IS audit department considers implementing continuous auditing techniques for a multinational retail enterprise that requires high availability of its key systems. A PRIMARY benefit of continuous auditing is that:

a)

Effective preventive controls are enforced.

b)

System integrity is ensured.

c)

Errors can be corrected in a timely fashion.

d)

Fraud can be detected more quickly.

10.

10. Which of the following represents the GREATEST potential risk in an electronic data in (EDI) environment?

a)

Lack of transaction authorizations

b)

Loss or duplication of EDI transmissions

c)

Transmission delay

d)

Deletion or manipulation of transactions prior to, or after, establishment of application controls