wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ACCTG 38 MIDTERM EXAM

Total questions: 45

Worksheet time: 23mins

Name
Class
Date
1.

A worm is a software program that replicates itself in areas of idle memory until the system fails

a)

TRUE

b)

FALSE

2.

To preserve audit trails in a CBIS environment, transaction logs are permanent records of transactions

a)

TRUE

b)

FALSE

3.

A qualified opinion on management’s assessment of internal controls over the financial reporting system necessitates a qualified opinion on the financial statements?

a)

TRUE

b)

FALSE

4.

The same internal control objectives apply to manual and computer-based information

a)

TRUE

b)

FALSE

5.

A disaster recovery plan is a comprehensive statement of all actions to be taken after a disaster

a)

TRUE

b)

FALSE

6.

A strong internal control system will increase the amount of substantive testing that must be performed.

a)

TRUE

b)

FALSE

7.

Commercial software is more reliable than In-house developed systems

a)

TRUE

b)

FALSE

8.

The first step in the SDLC is to develop a systems strategy. commercial software are less reliable than In-house developed systems

a)

TRUE

b)

FALSE

9.

The objective of systems planning is to link systems projects to the strategic objectives of the firm.

a)

TRUE

b)

FALSE

10.

System maintenance is often viewed as the first phase of a new development cycle.

a)

TRUE

b)

FALSE

11.

Project initiation is the process by which systems proposals are assessed for consistency with the strategic systems plan and evaluated in terms of their feasibility and cost-benefit characteristics.

a)

TRUE

b)

FALSE

12.

To ensure sound internal control, program coding and program processing should be separated

a)

TRUE

b)

FALSE

13.

The presence of a SPLMS effectively guarantees program integrity

a)

TRUE

b)

FALSE

14.

The Database Administrator should be separated from systems development.

a)

TRUE

b)

FALSE

15.

Source program library controls(SPLC) should prevent and detect unauthorized access to application programs.

a)

TRUE

b)

FALSE

16.

The operating system performs all of the following tasks except

a)

translates third-generation languages into machine language

b)

assigns memory to applications

c)

authorizes user access

d)

schedules job processing

17.

A software program that allows access to a system without going through the normal log on procedures is called a

a)

logic bomb

b)

Trojan horse

c)

Worm

d)

back door

18.

All of the following are objectives of operating system control except

a)

protecting the OS from users

b)

protesting users from each other

c)

protecting users from themselves

d)

protecting the environment from users

19.

Which of the following is considered an unintentional threat to the integrity of the operating system?

a)

A hacker gaining access to the system because of a security flaw

b)

A hardware flaw that causes the system to crash

c)

a virus that formats the hard drive

d)

at the systems programmer accessing individual user files

20.

All of the following will reduce the exposure to computer viruses except

a)

Install antivirus software

b)

Install factory-sealed application software

c)

Assign ad control user passwords

d)

Install public domain software from reputable bulletin boards

21.

Which of the following would represent an internal control weakness in an IT environment?

a)

The computer librarian maintains the custody of computer application programs and files

b)

The data control group is solely responsible for distributing computer-generated reports

c)

Computer operators have access to operator instructions and have the authority to modify applications

d)

Computer programmers write and modify programs designed by system analysts.

22.

Which of the following controls would most likely provide protection against unauthorized changes in production programs?

a)

Restricting programmer access to the computer room

b)

Requiring two operators to be present during equipment operation

c)

Limiting program access to operators

d)

Implementing management review daily of run logs

23.

This act provides an overview of management and auditors responsibility in the implementation of internal control

a)

Sarbanes Act of 2001

b)

Sarbanes -Oxley Act

c)

Sarbanes-Oxley Act of 2001

d)

COSO Framework

24.

The five US private sector organizations that commissioned and sponsored the COSO include the following, except

a)

The Institute of Internal Auditor

b)

Financial Executives International

c)

Institute of Management Accountants

d)

Asian Institute of Management

25.

The following are internal controls components, except

a)

Monitoring

b)

Control Activities

c)

Risk Assessment

d)

Supervision

26.

It ensures the validity, accuracy of financial transactions

a)

Application control

b)

General Control

c)

Information system

d)

Risk assessment

27.

Which of the following is not a basic understanding of the audit process that the reader should know?

a)

Distinguish attest function and assurance

b)

concept of a management assertion

c)

recognize the relationship between assertions and audit objectives

d)

concept of audit risk

28.

IT audits are often conducted by a department called

a)

Information System Audit

b)

IS Risk Management

c)

System Audit Risk

d)

System Information Audit

29.

This means that the transaction should be validly process

a)

Transaction authorization

b)

Segregation of duties

c)

Supervisions

d)

Independent verification

30.

This refers to compensating control for lack of segregation of duties

a)

Transaction authorization

b)

Segregation of duties

c)

Supervision

d)

Independent verification

31.

The following functions should be segregated except

a)

holding the subsidiary ledger and general ledger

b)

system developer and computer operations

c)

database administrator and system development

d)

all of the choices must be separated

32.

Access controls include the following except

a)

limit personnel access

b)

physical access barriers

c)

proper-back up facilities

d)

disaster recovery plan

e)

independent verification

33.

The following are not part of the independent verification

a)

periodic batch total reconciliations

b)

periodic comparisons pf physical assets to accounting records

c)

review of management reports

d)

periodic audit by management

34.

It captures all directories, files, records, printers accessed during user sessions

a)

Access tokens

b)

Access control lists

c)

discretionary access control

d)

log-on procedures

35.

The following are controlling against malicious and destructive programs

a)

install public domain software

b)

routine back-up of key files

c)

establish educational programs

d)

establish corporate-wide policy for copyrighted, licensed software

36.

Refers to the ability of the system to continue reliable operations in the event of hardware failure

a)

Uninterruptible power supplies

b)

fault-tolerance control

c)

redundant arrays

d)

access control

37.

This approach has exclusive ownership of data files

a)

Flat file Approach

b)

Database Approach

c)

Individual File

d)

Database management

38.

It validates and authorizes access to the database in accordance with the user's level of authority

a)

Database Management System

b)

Source Program Library System

c)

Control Access List

d)

None of the choices

39.

It defines how user views a particular database that the user authorized to access

a)

Subschema

b)

Data Encryption

c)

Database Authorization Table

d)

User-Defined Procedures

40.

This back-up control technique means that when the files are updated, the old file is destroyed.

a)

Grand-parent-child technique

b)

Direct Access File Structure

c)

Back-up

d)

None of the choices

41.

Distributed data processing has the effect of consolidating some computer functions, thus the risk include

a)

incompatible hardware

b)

network and software redundancy

c)

lack of corporate standard

d)

more IT personnel

42.

It is the process by which system proposals are assessed for consistency

a)

Project initiation

b)

In-house development

c)

System strategy

d)

commercial pakages

43.

Which of the following does not include in the six Activities that distinguish an effective system development life cycle

a)

System authorization

b)

technical design

c)

maintenance and support

d)

user specification

44.

It stores program, retrieves programs, deletes obsolete program and document program changes

a)

Source Program Libray Management System

b)

Database Management System

c)

System Development Cycle System

d)

None of the choices

45.

This refers to a comprehensive statement of all actions to be taken before, during, and after the disaster

a)

Disaster Recovery Plan

b)

Back-Up Recovery Plan

c)

Second Site Back-Up Plan

d)

Hot Site