WorksheetsM05_RAFITs and layers of technology
Total questions: 10
Worksheet time: 16mins
M05Q1. Below are examples of RAFITs and PRPs. Which of the below examples are RAFITs. Select all that apply.
The automated interest expense calculation is not programmed to result in a complete and accurate recognition of interest expense.
Changes to IT system configurations do not function as intended.
Sales forecasts used in the inventory reserve calculation may not adequately reflect market conditions.
Logical access permissions are not revoked in a timely manner.
M05Q2. Which of the following are the four layers of technology per the KAEG?
A. Application
B. Interface
C. Database
D. Operating system
F. Network
M05Q3. As shown in the previous example, would we identify the database layer as relevant to the automated control?
Yes
No
M05Q4. For the following control, ‘Access to enter/update the Oracle standard price list is restricted to the appropriate personnel,’ what layers did you identify as relevant? Select all that apply.
Oracle application
Oracle database
Windows 10
Access security protocols
M05Q5. For the same control, which of the following RAFITs did you identify as relevant to the Oracle application layer? Select all that apply.
APD 1.1 – Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.
APD 1.2 – Logical access permissions are granted to users and accounts (including shared or generic accounts) that are unauthorized or not commensurate with job responsibilities.
APD 1.3 – Logical access permissions are not revoked in a timely manner.
APD 1.4 – Logical access to users and accounts (including shared or generic accounts) that can perform privileged tasks and functions within IT systems is unauthorized or not commensurate with job responsibilities.
APD 1.5 – Physical access to facilities housing IT systems and/or electronic media is unauthorized or not commensurate with job responsibilities.
M05Q6. For the RAFITs identified as relevant in the previous question (APD1.1, 1.2, 1.3 and 1.4), which of the following GITCs would be relevant?
Management approves the nature and extent of user access privileges for new and modified user access, including standard application profiles/roles, critical financial reporting transactions, and segregation of duties.
Access for terminated or transferred users is removed or modified in a timely manner.
Access is authenticated through generic user IDs and passwords for validating that users are authorized to gain access to the system.
Privileged-level access (e.g. configuration, data and security administrators) is authorized and appropriately restricted.
M05Q7. Which of the following considerations might you have when identifying IT systems that are used to execute GITCs? Select all that apply.
Relevant GITCs that support the consistent effective operation of the automated controls.
Assessment of the knowledge and competence of those performing the control activity.
Identification of automated controls that entity’s management is relying on.
Assessment of layers of technology and RAFITs relevant to automated GITCs identified.
Assessment of the functionality of IT systems that enable GITCs.
M05Q8. There are 7 categories of automated controls within KAEG. Only 4 of these categories are relevant for automated GITCs and are able to be selected in the workflow. Which of the following are relevant? Select all that apply.
A. System access controls, including enforcing segregation of duties
C. Configuration of system generated reports or other data outputs
D. System configuration controls
F. Interface controls
G. Other
M05Q9. In what screen are you able to add GITCs in the Workflow?
Section 2.2 IT Understanding
Section 2.2.1 RAFITs screen
Section 3.3 Business processes
Section CA. Control activities
M05Q10. In what screen are you able to group IT layers?
Section 2.2 IT Understanding
Section 2.2.1 RAFITs screen
Section 3.3 Business processes
Section CA. Control activities
