WorksheetsACCTG 38 MIDTERM EXAM
Total questions: 45
Worksheet time: 23mins
A worm is a software program that replicates itself in areas of idle memory until the system fails
TRUE
FALSE
To preserve audit trails in a CBIS environment, transaction logs are permanent records of transactions
TRUE
FALSE
A qualified opinion on management’s assessment of internal controls over the financial reporting system necessitates a qualified opinion on the financial statements?
TRUE
FALSE
The same internal control objectives apply to manual and computer-based information
TRUE
FALSE
A disaster recovery plan is a comprehensive statement of all actions to be taken after a disaster
TRUE
FALSE
A strong internal control system will increase the amount of substantive testing that must be performed.
TRUE
FALSE
Commercial software is more reliable than In-house developed systems
TRUE
FALSE
The first step in the SDLC is to develop a systems strategy. commercial software are less reliable than In-house developed systems
TRUE
FALSE
The objective of systems planning is to link systems projects to the strategic objectives of the firm.
TRUE
FALSE
System maintenance is often viewed as the first phase of a new development cycle.
TRUE
FALSE
Project initiation is the process by which systems proposals are assessed for consistency with the strategic systems plan and evaluated in terms of their feasibility and cost-benefit characteristics.
TRUE
FALSE
To ensure sound internal control, program coding and program processing should be separated
TRUE
FALSE
The presence of a SPLMS effectively guarantees program integrity
TRUE
FALSE
The Database Administrator should be separated from systems development.
TRUE
FALSE
Source program library controls(SPLC) should prevent and detect unauthorized access to application programs.
TRUE
FALSE
The operating system performs all of the following tasks except
translates third-generation languages into machine language
assigns memory to applications
authorizes user access
schedules job processing
A software program that allows access to a system without going through the normal log on procedures is called a
logic bomb
Trojan horse
Worm
back door
All of the following are objectives of operating system control except
protecting the OS from users
protesting users from each other
protecting users from themselves
protecting the environment from users
Which of the following is considered an unintentional threat to the integrity of the operating system?
A hacker gaining access to the system because of a security flaw
A hardware flaw that causes the system to crash
a virus that formats the hard drive
at the systems programmer accessing individual user files
All of the following will reduce the exposure to computer viruses except
Install antivirus software
Install factory-sealed application software
Assign ad control user passwords
Install public domain software from reputable bulletin boards
Which of the following would represent an internal control weakness in an IT environment?
The computer librarian maintains the custody of computer application programs and files
The data control group is solely responsible for distributing computer-generated reports
Computer operators have access to operator instructions and have the authority to modify applications
Computer programmers write and modify programs designed by system analysts.
Which of the following controls would most likely provide protection against unauthorized changes in production programs?
Restricting programmer access to the computer room
Requiring two operators to be present during equipment operation
Limiting program access to operators
Implementing management review daily of run logs
This act provides an overview of management and auditors responsibility in the implementation of internal control
Sarbanes Act of 2001
Sarbanes -Oxley Act
Sarbanes-Oxley Act of 2001
COSO Framework
The five US private sector organizations that commissioned and sponsored the COSO include the following, except
The Institute of Internal Auditor
Financial Executives International
Institute of Management Accountants
Asian Institute of Management
The following are internal controls components, except
Monitoring
Control Activities
Risk Assessment
Supervision
It ensures the validity, accuracy of financial transactions
Application control
General Control
Information system
Risk assessment
Which of the following is not a basic understanding of the audit process that the reader should know?
Distinguish attest function and assurance
concept of a management assertion
recognize the relationship between assertions and audit objectives
concept of audit risk
IT audits are often conducted by a department called
Information System Audit
IS Risk Management
System Audit Risk
System Information Audit
This means that the transaction should be validly process
Transaction authorization
Segregation of duties
Supervisions
Independent verification
This refers to compensating control for lack of segregation of duties
Transaction authorization
Segregation of duties
Supervision
Independent verification
The following functions should be segregated except
holding the subsidiary ledger and general ledger
system developer and computer operations
database administrator and system development
all of the choices must be separated
Access controls include the following except
limit personnel access
physical access barriers
proper-back up facilities
disaster recovery plan
independent verification
The following are not part of the independent verification
periodic batch total reconciliations
periodic comparisons pf physical assets to accounting records
review of management reports
periodic audit by management
It captures all directories, files, records, printers accessed during user sessions
Access tokens
Access control lists
discretionary access control
log-on procedures
The following are controlling against malicious and destructive programs
install public domain software
routine back-up of key files
establish educational programs
establish corporate-wide policy for copyrighted, licensed software
Refers to the ability of the system to continue reliable operations in the event of hardware failure
Uninterruptible power supplies
fault-tolerance control
redundant arrays
access control
This approach has exclusive ownership of data files
Flat file Approach
Database Approach
Individual File
Database management
It validates and authorizes access to the database in accordance with the user's level of authority
Database Management System
Source Program Library System
Control Access List
None of the choices
It defines how user views a particular database that the user authorized to access
Subschema
Data Encryption
Database Authorization Table
User-Defined Procedures
This back-up control technique means that when the files are updated, the old file is destroyed.
Grand-parent-child technique
Direct Access File Structure
Back-up
None of the choices
Distributed data processing has the effect of consolidating some computer functions, thus the risk include
incompatible hardware
network and software redundancy
lack of corporate standard
more IT personnel
It is the process by which system proposals are assessed for consistency
Project initiation
In-house development
System strategy
commercial pakages
Which of the following does not include in the six Activities that distinguish an effective system development life cycle
System authorization
technical design
maintenance and support
user specification
It stores program, retrieves programs, deletes obsolete program and document program changes
Source Program Libray Management System
Database Management System
System Development Cycle System
None of the choices
This refers to a comprehensive statement of all actions to be taken before, during, and after the disaster
Disaster Recovery Plan
Back-Up Recovery Plan
Second Site Back-Up Plan
Hot Site
