Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IT Audit KCw課程

Total questions: 67

Worksheet time: 1hrs 25mins

Name
Class
Date
1.

M01Q1. What tool do we use in the Workflow to allocate individuals with tasks and manage minimum review requirements?

a)

Atlas

b)

Briefcase

c)

Engagement Management

d)

Project Plan

2.

M01Q2. What is the name of the menu option we access in order to take us to the main area of the audit file where we begin our documentation?

a)

Advanced Capabilities

b)

Engagement Profile

c)

Atlas

d)

My Engagement

3.

M01Q3. What are the Workflow scaling options relevant to IT auditors?

a)

Less Complex Audit Workflow, International-Enhanced, AICPA, PCAOB.

b)

International-Core, International-Enhanced.

c)

Less Complex Audit Workflow, International-Core, International-Enhanced, US.

d)

Less Complex Audit Workflow, International-Core, International-Enhanced, AICPA, PCAOB.

4.

M01Q4. Compared to International-Enhanced, which of the following items are true of International-Core?

a)

The information module differs.

b)

Risks of material misstatement are not included.

c)

The IT Understanding activity screen is not used.

d)

Documentation of the precision of the control is not required.

5.

M02Q1. Which of the following best defines risks of misstatement?

a)

Risks that could result in a misstatement to the financial statements.

b)

Measurement of the level of risk attached to an assertion.

c)

Our assessment of the measurement of risk attached to assertion level risks.

d)

Risks with a significant possibility of resulting in a material misstatement to the financial statements.

6.

M02Q2. Which of the following best defines risks of material misstatement?

a)

Measurement of the level of risk attached to an assertion.

b)

Risks with a reasonable possibility of resulting in misstatements that are material to the financial statement audit.

c)

Risks with an inherent risk level of Elevated or Significant.

d)

Risks with a remote possibility of resulting in misstatements that are material to the financial statement audit.

7.

M02Q3. What are the levels of inherent risk? Select all that apply.

a)

Low

b)

Base

c)

High

d)

Significant

e)

Elevated

8.

M02Q4. Which of the following best defines ‘internal control’?

a)

The auditor’s tests to obtain reasonable assurance of over an entity’s objectives related to financial reporting, operations, and compliance with laws and regulations.

b)

Activities performed by the entity related to support the reliability of the financial statement assertions and disclosures.

c)

An entity’s processes to provide reasonable assurance over its objectives related to financial reporting, operations, and compliance with laws and regulations.

d)

An entity’s processes to address all risks of misstatement related to financial reporting, operations, and compliance with laws and regulations.

9.

M03Q1. During your audit engagements, what layers of technology do you commonly identify as relevant? Select all that apply.

a)

Application

b)

Database

c)

Operating system

d)

Network

10.

M03Q2. Based on the scenario presented, which layers would be considered relevant to risk assessment?

a)

Application, Database and Operating System.

b)

Application and Operating System.

c)

Application and Database

d)

Database and Operating System

11.

M03Q3. What areas does the engagement team document in the IT Understanding Screen?

a)

How the entity uses IT as part of financial reporting and related business processes.

b)

The entity’s IT organization.

c)

The entity’s IT policies and procedures.

d)

All of the above.

12.

M03Q4. When do we use the SSC instructions and reporting templates in KAEG?

a)

To document your evaluation of a service organization controls (SOC) report.

b)

To communicate the nature, timing and extent of procedures performed by the SSC auditor on behalf of the group engagement team and/or SSC user auditors.

c)

When a SOC report is not provided by the Service Organization.

d)

When the SSC auditor identifies issues that may require an audit response.

13.

M03Q5. Did you find it easy navigating KAEG?

a)

Yes

b)

No

14.

M03Q6. When do we involve a team member with specialization in IT in response to a cybersecurity incident?

a)

When an exception is noted during your testing of database access.

b)

If an interface from an external source does not successfully complete.

c)

When a cybersecurity incident at any layer comes to your attention during the audit.

d)

When an terminated employee retains access privileges to a financially relevant application.

15.

M04Q1. In what workflow screen/section can you add relevant process level automated controls?

a)

Section 2.2.2 IT Understanding

b)

Section 2.2.SO Service Organizations

c)

Section 3.3 Business processes

d)

Section 2.2.3 Fraud

16.

M04Q2. Which of the following are PRPs? Select all that apply.

a)

Vendor invoices with inaccurate quantities and/or pricing are recorded and paid to the vendor.

b)

Purchase orders (POs) with inaccurate coding are expensed improperly.

c)

Significant agreements contain embedded derivatives, leases, contingencies, guarantees, and/or consolidation issues that are not identified and accounted for appropriately.

d)

Expenditures are overstated.

17.

M04Q3. Identify the relevant control attributes for the following control activity: Daily interface between the Policy Administration System and Data Warehouse transferring the premium and claims data related to policies.

a)

Validation of transaction totals for sales and refunds.

b)

Validation of record counts.

c)

Messaging to operations management if errors occurred during processing.

d)

All of the above.

18.

M04Q4. How does the consistency and/or frequency of control performance commonly affect the precision of an automated control?

a)

The control is designed to operate consistently each time it is performed, however, the frequency is not routine, which indicates high precision.

b)

The control is not designed to operate consistently each time it is performed and the frequency is not routine, which indicates high precision.

c)

The control is not designed to operate consistently each time it is performed, however, the frequency is adequately routine, which indicates high precision.

d)

The control is designed to operate consistently each time it is performed and the frequency is adequately routine, which indicates high precision.

19.

M04Q5. The definition of control attributes are the specific procedures performed by the control operator that make-up the control activity and are important to the design of the control?

a)

Yes

b)

No

20.

M04Q6. What will drive most the extent of audit evidence we have to obtain when testing general IT controls?

a)

Number of GITCs identified.

b)

Frequency of the control activity.

c)

Knowledge and competence of the control owner.

d)

The higher the risk associated with the automated control to which it is linked.

21.

M04Q7. Which factors that may increase RAWTC above the inherent risk assessment are relevant to automated controls? Select all that apply.

a)

Nature of the control is complex.

b)

Control relies on the effectiveness of other controls.

c)

Deficiencies identified in prior years.

d)

Control operates infrequently.

e)

Changes to control or process in which the control operates.

22.

M04Q8. For scenario 1, what level of RAWTC did you think was appropriate?

a)

Base

b)

Elevated

c)

Significant

d)

Significant +

23.

M04Q9. For scenario 2, what level of RAWTC did you think was appropriate?

a)

Base

b)

Elevated

c)

Significant

d)

Significant +

24.

M04Q10. Has anyone ever relied on the consistent operation of automated controls without testing relevant GITCs?

a)

Yes

b)

No

25.

M04Q11. If choosing to not rely on relevant general IT controls, how would you determine the test frequency for the automated control? Select all that apply.

a)

Assessment of inherent risk for the risks of material misstatement (RMMs).

b)

Complexity of the IT environment.

c)

Nature of the control.

d)

Frequency of changes to the relevant IT layers.

e)

Risk associated with the control (RAWTC) for the automated control.

26.

M04Q12. Has anyone ever benchmarked automated controls before?

a)

Yes

b)

No

27.

M05Q1. Below are examples of RAFITs and PRPs. Which of the below examples are RAFITs. Select all that apply.

a)

The automated interest expense calculation is not programmed to result in a complete and accurate recognition of interest expense.

b)

Changes to IT system configurations do not function as intended.

c)

Sales forecasts used in the inventory reserve calculation may not adequately reflect market conditions.

d)

Logical access permissions are not revoked in a timely manner.

28.

M05Q2. Which of the following are the four layers of technology per the KAEG?

a)

Application

b)

Interface

c)

Database

d)

Operating system

e)

Server

29.

M05Q3. As shown in the previous example, would we identify the database layer as relevant to the automated control?

a)

Yes

b)

No

30.

M05Q4. For the following control, ‘Access to enter/update the Oracle standard price list is restricted to the appropriate personnel,’ what layers did you identify as relevant? Select all that apply.

a)

Oracle application

b)

Oracle database

c)

Windows 10

d)

Access security protocols

31.

M05Q5. For the same control, which of the following RAFITs did you identify as relevant to the Oracle application layer? Select all that apply.

a)

APD 1.1 – Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.

b)

APD 1.2 – Logical access permissions are granted to users and accounts (including shared or generic accounts) that are unauthorized or not commensurate with job responsibilities.

c)

APD 1.3 – Logical access permissions are not revoked in a timely manner.

d)

APD 1.4 – Logical access to users and accounts (including shared or generic accounts) that can perform privileged tasks and functions within IT systems is unauthorized or not commensurate with job responsibilities.

e)

APD 1.5 – Physical access to facilities housing IT systems and/or electronic media is unauthorized or not commensurate with job responsibilities.

32.

M05Q6. For the RAFITs identified as relevant in the previous question (APD1.1, 1.2, 1.3 and 1.4), which of the following GITCs would be relevant?

a)

Management approves the nature and extent of user access privileges for new and modified user access, including standard application profiles/roles, critical financial reporting transactions, and segregation of duties.

b)

Access for terminated or transferred users is removed or modified in a timely manner.

c)

Access is authenticated through generic user IDs and passwords for validating that users are authorized to gain access to the system.

d)

Privileged-level access (e.g. configuration, data and security administrators) is authorized and appropriately restricted.

33.

M05Q7. Which of the following considerations might you have when identifying IT systems that are used to execute GITCs? Select all that apply.

a)

Relevant GITCs that support the consistent effective operation of the automated controls.

b)

Assessment of the knowledge and competence of those performing the control activity.

c)

Identification of automated controls that entity’s management is relying on.

d)

Assessment of layers of technology and RAFITs relevant to automated GITCs identified.

e)

Assessment of the functionality of IT systems that enable GITCs.

34.

M05Q8. There are 7 categories of automated controls within KAEG. Only 4 of these categories are relevant for automated GITCs and are able to be selected in the workflow. Which of the following are relevant? Select all that apply.

a)

System access controls, including enforcing segregation of duties

b)

Edit checks

c)

Configuration of system generated reports or other data outputs

d)

System configuration controls

e)

System calculation controls

35.

M05Q9. In what screen are you able to add GITCs in the Workflow?

a)

Section 2.2 IT Understanding

b)

Section 2.2.1 RAFITs screen

c)

Section 3.3 Business processes

d)

Section CA. Control activities

36.

M05Q10. In what screen are you able to group IT layers?

a)

Section 2.2 IT Understanding

b)

Section 2.2.1 RAFITs screen

c)

Section 3.3 Business processes

d)

Section CA. Control activities

37.

M06Q1. Consider a control activity where access for terminated or transferred users is removed or modified in a timely manner.

Identify the relevant control attributes for the control activity. Select all that apply.

a)

System access of the terminated/resigned user was revoked.

b)

System access of the transferring user was revoked.

c)

System access revocation was done within 1 day after the user's termination/resignation/ transfer date, in accordance with company policies and procedures.

d)

Authorized personnel perform the quarterly user access review across IT systems to ensure revocation of access was performed as per management’s request.

38.

M06Q2. You determine the RAWTC for GITCs by considering specific factors that may indicate the general IT control is ineffective. Identify the factors that could be used to determine RAWTC. Select all that apply.

a)

The effectiveness of CERAMIC controls, especially controls that monitor other controls.

b)

The competence of the personnel performing the general IT control or monitoring its performance.

c)

The complexity of the general IT control and the significance of the judgments made about its operation.

d)

The results of the previous years’ testing of the automated control to which the general IT control supports.

e)

Whether there have been changes in the general IT control since it was previously tested.

39.

M06Q3. Fill in the blank.

For each automated control, you assess RAWTC for at least one GITC that supports the effective operation of the automated control _______.

a)

At higher than the RAWTC for the related automated control.

b)

At equal to the RAWTC for the related automated control.

c)

At equal to or higher than the RAWTC for the related automated control.

d)

At equal to or less than the RAWTC for the related automated control.

40.

M06Q4. What is an appropriate sample size for the following control?

RAWTC Assessment – Base

Population – 150

a)

5

b)

11

c)

15

d)

25

41.

M06Q5. What is an appropriate sample size for the following control?

RAWTC Assessment – Significant +

Population – 38

a)

5

b)

11

c)

15

d)

25

42.

M06Q6. When documenting the testing procedures performed for an automated control, what are the from and through dates that should be entered?

a)

The from date is the first day of the relevant financial year and the through date is the day of testing of the automated control.

b)

The from and through dates are the same and are the day of testing the automated control.

c)

The from date is the first day of the relevant financial year and the through date is the year end date.

d)

The from date is the day of testing the automated control and the through date is the year end date.

43.

M06Q7. When performing mitigating procedures in response to a GITC deficiency, where should this be documented in the Workflow?

a)

Section 2.2.SO Service Organizations

b)

Section 2.2.2 IT Understanding

c)

Section 2.1 RAFITs screen

d)

Section 2.2.5 Response to deficient GITC

44.

M06Q8. In the scenario you just documented in the Workflow, which RAFIT did the retrospective review control address?

a)

CM1 - Unapproved changes to IT system program are implemented into the production environment.

b)

CM2 - Changes to IT system program do not function as intended.

c)

CM3 - Unapproved changes to IT system configurations are implemented into the production environment.

d)

CM4 - Changes to IT system configurations do not function as intended.

e)

CM5 - Logical access to implement changes to IT system program or configurations into the production environment is unauthorized or not commensurate with job responsibilities.

45.

M07Q1. Which of the following are the first 2 steps of the process for information used in the audit? Select all that apply.

a)

Evaluate relevance

b)

Evaluate reliability

c)

Evaluate precision

d)

Identify information used in the audit

e)

Identify information used in control activities

46.

M07Q2. Which of the following is the third step in the process for information used in the audit?

a)

Evaluate relevance

b)

Evaluate reliability

c)

Evaluate resilience

d)

Evaluate repeatability

47.

M07Q3. What are appropriate audit responses for information used in substantive procedures? Select all that apply.

a)

Understand the source

b)

Direct test

c)

Design and perform substantive procedures

d)

Test entity management’s controls

48.

M07Q4. Where in the Workflow do you document the audit response for information used in substantive procedures? Select all that apply.

a)

Estimates module

b)

Information module

c)

On-screen text box

d)

Documentation within the procedure

49.

M07Q5. Entity management uses the inventory turnover report to identify potentially obsolete inventory. In this example, how is the information used in the audit?

a)

Subject of substantive procedures

b)

Perform a control activity

c)

Management estimates

d)

Perform risk assessment procedures

50.

M07Q6. What is the appropriate audit response for the inventory turnover report discussed in the last question? Select all that apply.

a)

Substantive audit procedures to evaluate the source

b)

Understand how the control operator is satisfied

c)

The control procedure addresses reliability

d)

Test management’s controls

e)

Direct test the information

51.

M07Q7. Should you activate the information module in the workflow if KPMG uses the information to select a sample for testing?

a)

Yes

b)

No

52.

M07Q8. What are some examples of controls that address data input risks for the information presented in the prior slide? Select all that apply.

a)

Purchase orders are authorized by the FC in the finance system prior to issuance to the supplier.

b)

Access to the finance system database is restricted to limited IT personnel whose access is commensurate with job responsibilities.

c)

Purchase orders can only be entered by individuals who have the purchase ledger clerk role allocated to their user account.

d)

The report is configured to extract complete and accurate information.

53.

M07Q9. The financial audit team have identified information and would like to adopt the direct testing method. The RAWTC associated with the information is Significant and there are over 250 lines of data. How many items would be tested by the financial audit team?

a)

120

b)

80

c)

60

d)

45

54.

M07Q10. The financial audit team have identified information and would like to adopt the direct testing method. The RAWTC associated with the information is Significant and there are over 250 lines of data. How many items would be tested by the financial audit team?

a)

120

b)

80

c)

60

d)

45

55.

M08Q1. Arrange the steps you perform when seeking to rely on controls within a service organization in the correct order.

a)

Arrange the steps you perform when seeking to rely on controls within a service organization in the correct order.

b)

Identify relevant controls that exist within the control objective.

c)

Determine whether all controls under each control objective are relevant.

d)

Identify the control objectives within the Service Organization Controls Report.

56.

M08Q2. Which steps do you perform when seeking to rely on controls within a service organization? Select all that apply.

a)

Document rationale for exclusion of each control under the selected control objective.

b)

Determine whether all controls under each control objective are relevant.

c)

Identify relevant controls that exist within the SOC report.

d)

Identify relevant controls that exist within the control objective.

e)

Document rationale for exclusion of each complementary user entity control (CUEC) within the Service Organization Controls Report.

57.

M08Q3. What is the first step in the process when considering relying on a SOC 2 Type II report?

a)

Evaluate if the description, test of design and operating effectiveness procedures appropriately address the user auditor's purposes.

b)

Evaluating the impact to the control environment from any control deficiencies identified.

c)

Evaluating whether the user entity designed and implemented relevant complementary user entity controls identified in the report.

d)

Evaluating the period covered by the report and the entity’s audit period.

58.

M08Q4. On which screen do IT auditors most often identify and activate service organizations?

a)

1.1.3 Audit plan

b)

SO. Service organizations -> 1. Understanding

c)

2.2 Components of internal control

d)

2.2.2 Understanding of IT

59.

M08Q5. What factors should you consider when relying on internal audit’s work? Select all that apply.

a)

Were members of the internal audit function previously employed by KPMG?

b)

Does reliance on internal audit alter the nature, timing, or extent of procedures?

c)

Do internal auditors have the adequate levels of education as well as audit and industry experience?

d)

Does the internal audit function have access to report directly to those charged with governance or an officer with appropriate authority?

e)

Does the internal audit function report findings directly to the external audit team?

60.

M08Q6. What factors should you consider when relying on internal audit’s work? Select all that apply.

a)

Were members of the internal audit function previously employed by KPMG?

b)

Does reliance on internal audit alter the nature, timing, or extent of procedures?

c)

Do internal auditors have the adequate levels of education as well as audit and industry experience?

d)

Does the internal audit function have access to report directly to those charged with governance or an officer with appropriate authority?

e)

Does the internal audit function report findings directly to the external audit team?

61.

M09Q1. Which screen in the KPMG Clara workflow do you select to generate the IT Overview Report?

a)

2.1.1 Entity and its environment

b)

2.2.2 IT Understanding

c)

1.1 Audit plan

d)

4.1 Evaluate audit results

62.

M09Q2. What is the main purpose of the IT Overview Report?

a)

To provide an understanding of the linkages between automated controls, IT layers, RAFITs and GITCs, and help identify potential gaps in linking.

b)

To provide reliable results for all GITC testing conclusions for related application controls and information.

c)

To prove that all IT application controls and information are linked to the correct GITCs and identify ineffective GITCs.

d)

To show all IT layers and GITCs that are tested and how GITC test results impact related IT application controls and information.

63.

M09Q3. What does the legend icon shown here indicate?

a)

All GITC(s) linked to this IT layer/RAFIT concluded as effective.

b)

This IT layer is linked to an automated control, but no RAFITs have been linked (no RAFITs).

c)

All GITC(s) linked to this IT layer/RAFIT not yet concluded on.

d)

No GITCs yet linked to this RAFIT.

64.

M09Q4. Which errors or discussion items did you identify in the activity? Select all that apply.

a)

Program development controls suggest a need for additional discussion over systems implementation scoping.

b)

Application controls are ineffective because they are linked to the ineffective GITC APD3 (access removals).

c)

GITC results indicate control deficiencies exist within related Service Organization Control Objectives.

d)

The RAWTC for at least one GITC does not align with the highest assessed RAWTC for application controls and should be discussed further.

e)

In the application layer, there are potential errors privileged access testing linkage to RAFITs.

65.

M10Q1. Where would you go first for functionality help if you didn’t know how to do something in the workflow?

a)

Guidance

b)

The lead in-charge senior on the financial audit team

c)

Your LM_01 Learner Workbook

d)

KPMG HELP hotline

66.

M10Q2. What icon do you select to mark a screen prepared or reviewed?

a)
b)
c)
d)
67.

M10Q3. When an item is deselected in the workflow, will the data be purged or maintained in the background?

a)

Maintained in the background

b)

Purged