Font size
S
M
L
XL
WorksheetsRevision Test1
Total questions: 155
Worksheet time: 2hrs 56mins
Name
Class
Date
1.
Which of the following is not an example of Financial Controls
a)
Authorisation
b)
Budget
c)
Sequentially pre numbered Finance documents
d)
Manned Company Gate
2.
Which of the following is/ are data management categories
a)
Access Control
b)
Backup Control
c)
Both A & B
d)
None of the above
3.
Version control Systems provides assistance to IT team with following except
a)
Repository of contents
b)
Record of previous version
c)
Maintaining Logs
d)
Quality Assurance
4.
…............ is a type of software maintenance which issues updates, patches, scalability, security enhancement etc
a)
Adaptive
b)
Perfective
c)
Preventive
d)
Proactive
e)
Corrective
5.
____________ is responsible for protection, classification, backup strategies and use of departmental information
a)
Database Administrator
b)
System Owner
c)
User Manager
d)
Data Owner
6.
What is the mitigation plan for risk associated with absence of skilled resources?
a)
Consider outsourcing or hiring skilled resources on contract
b)
Develop and implement standard coding practices
c)
Perform scope base lining
d)
Introduce change management process to evaluate and adopt changes in requirements
7.
------ are logs that are designed to record activity at system
a)
Audit Hooks
b)
Audit Trails
c)
Audit Process
d)
Audit Steps
8.
----------uses huge neural networks with many layers of processing to learn complex patterns in large amounts of data
a)
Machine Learning
b)
Natural language processing
c)
Deep Learning
d)
Computer Vision
9.
With the help of what tools, IT Auditor can plan for 100% substantive testing
a)
CAAT
b)
ERP
c)
COBIT
d)
Manual
10.
To perform IS audit IS auditor must possess a good skills set ;in reference to this identify the wrong statement<br />
a)
Should have knowledge of IT policies
b)
Should have knowledge of IT Act
c)
Should be able to understand BCP controls
d)
Must possess CA degree
11.
Which of the following uses a prototype that can be updated continually to meet changing user or business requirements?
a)
PERT
b)
Rapid application development (RAD)
c)
Function point analysis (FPA)
d)
GANTT
12.
IS auditor should review adequecy of the following proect management activities
a)
Levels of oversight by project committee
b)
risk management methods
c)
cost management
d)
process for planning and dependency management
e)
All of above
13.
A blockchain is a type of?
a)
Object
b)
Database
c)
Table
d)
View
14.
Breaking down a table to such extend that other columns in a table are dependent only on key column of the table is known as ….............
a)
Primary Key
b)
Normalisation
c)
Isolation
d)
Object
15.
Risk control matrix is developed in which step of IS audit
a)
Analysis
b)
Planning
c)
Fieldwork
d)
Reporting
16.
Which of the following is key principle of Governance and Management of Entrerprise information and Technology in COBIT
a)
Based on Conceptual Model
b)
Open and Flexible
c)
Aligned to major Standards
d)
Hoslistic Approach
17.
Which one is not a boundary control audit trail
a)
Resources requested
b)
No. of sign on attempts
c)
Authetication of information supplied
d)
Time and date of printing output
18.
Which of the following is not a type of Network Service
a)
CAN
b)
LAN
c)
SAN
d)
PAN
e)
MAN
19.
which of the following is correct
a)
IT controls is said to be a part of IT Application Controls<br />and IT General Controls
b)
IT controls is said to be product of IT Application Controls<br />and IT General Controls
c)
IS controls is said to be part of IT Application Controls<br />and IT General Controls
d)
IS controls is said to be a sum of IT Application Controls<br />and IT General Controls
20.
Disaster recovery planning addresses the
a)
technological aspect of business continuity planning.
b)
operational piece of business continuity planning.
c)
functional aspect of business continuity planning.
d)
overall coordination of business continuity planning.
21.
In how many categories information system can be classified
a)
2
b)
3
c)
4
d)
1
22.
Section-------of the (Indian) Information Technology Act, 2000 provides that a body corporate possessing, dealing or handling any sensitive personal data or information in a computer resource which it owns, controls or operates and is negligent in implementing and maintaining reasonable security practices and procedures resulting in wrongful loss or wrongful gain to any person, then such body corporate may be held liable to pay damages by way of compensation to the person so affected.
a)
Sec 7A
b)
Sec 42A
c)
Sec 43A
d)
Sec 66F
23.
Which of the following would NOT be a reason why an IS auditor would prepare a formal audit program?
a)
To structure the IS auditor's own planning
b)
To guide assistants in performing planned procedures
c)
To provide audit documentation for review reference
d)
To assess the overall risk of operations within the organization
24.
A manager of a project was not able to implement all audit recommendations by the target date. The IS auditor should:
a)
recommend that the project be halted until the issues are resolved
b)
recommend that compensating controls be implemented
c)
evaluate risks associated with the unresolved issues.
d)
recommend that the project manager reallocate test resources to resolve the issues.
25.
The control consideration while reviewing management controls in and IS System shall include
a)
Responsibility
b)
An IT Organisation Structure
c)
An IT Steering committee
d)
All of the above
26.
What is the tool used to verify that deployed resources are capable of finishing a task within the set time limit and with the expected quality level?<br />
a)
Earned value analysis
b)
Work Breakdown structure
c)
Work Package
d)
Qualitative Analysis of Risks
27.
_____________ assures the effectiveness and efficiency of operations, reliability of reporting and compliances with laws and regulations
a)
Engagement Letter
b)
Audit control framework
c)
Audit Charter
d)
Audit Universe
28.
Pick nearly most correct sequence for software reengineering
a)
Document restructing, reverse engineering, data restructuring, forward enginnering
b)
Design recovery, code structuring, reverse engineering, forward enginerring
c)
Inventory analysis, design recovery, data restrucuring, code restructuring, forward engineering
d)
Inventory analysis, document enginerring, code restructuring, reverse enginerring, data restructuring
29.
Which of the following is the role of an IS Auditor in Phase 3 (System Analysis) of SDLC
a)
Review cost justification/ benefits
b)
Review detailed requirement definition documents
c)
Verify that the management has approved the initiation and cost of the project
d)
Review existing data flow diagrams and other related specifications
30.
Audit trails is an example of
a)
Detective
b)
Application
c)
Preventive
d)
Corrective
31.
Which tool provides environment to developer for editing, simulating code, temporary storage, file management and sometimes code generation.
a)
Code Generators
b)
Developer’s Workbench
c)
Non-procedural languages
d)
Non-procedural languages
32.
…............ is a type of software maintenance which issues updates, patches, scalability, security enhancement etc
a)
Adaptive
b)
Perfective
c)
Preventive
d)
Proactive
e)
Corrective
33.
Based on Decision making MIS is
a)
Strategic Decision
b)
Tactical Decision
c)
Operational Decision
d)
None of these
34.
Who is in charge of a specific department
a)
Data Owner
b)
User Data
c)
System Owner
d)
System Administrator
35.
Which one is not objective of Audit Trail
a)
Audit Trail promote personal accountability
b)
Audit detect Unauthorized access
c)
to promote good internal control<br />
d)
Audit trail facilitate reconstruction of events
36.
Which of the following is an essential concept related to Cloud?
a)
Reliability
b)
Abstraction
c)
Productivity
d)
All of the mentioned
37.
Which of the following is not a stream of AI?
a)
Machine Learning
b)
Big Data
c)
Speech Recognition
d)
Natural language processing (NLP)
38.
Choose the correct option for change management process: i) Change advisory board ii) Request for change iii) Change Priortization iv) RFC Analysis v) Categorize
a)
i,ii,iii,iv,v
b)
i,iii,ii,iv,v
c)
ii,iv,iii,v,i
d)
ii,iii,i,iv,v
39.
Control aspect of the proposed information system is planned at
a)
Design Phase
b)
Execution phase
c)
Analysis phase
d)
None of the above
40.
…........... is known as relations in a RDBMS
a)
Rows
b)
Columns
c)
Table
d)
Tuple
41.
--------------handles multiple projects; and ensures the integrity and security of information stored in the database.
a)
User Manager
b)
Database Administrator
c)
Data Administrator
d)
Documentation Specialist
42.
Managing configuration of any computing devices and software application is --------------- charateristics
a)
statutory and compliance
b)
Scheduled and performance
c)
operational and quality
d)
operational and physical
43.
Which of the following helps in identifying stakeholders and beneficiaries of the project
a)
Project manager
b)
project sponser
c)
project charter
d)
business case
44.
---------- is not one of the objective of information system audits
a)
Data retention and storage
b)
Asset safeguarding
c)
Data integrity
d)
System effectiveness
45.
Characteristic of Gantt Charts is that it
a)
aid in scheduling project task
b)
shows activites in progress
c)
reflect resources assigned to each task
d)
B and C both
e)
All of above
46.
Which are the controls that are responsible for maintaining a chronology of the events from the time a sender dispatches a message to the time a receiver obtains the message
a)
Boundary controls
b)
Communication controls
c)
Input control
d)
Database control
47.
ITGC stands for
a)
Information Technology Governance Control
b)
Information Technology General Control
c)
Information technology Grant commission
d)
All of the above
48.
IT General control are --------- in nature
a)
supportive
b)
pervasive
c)
conservative
d)
reflective
49.
How many types of application controls
a)
One
b)
Two
c)
Three
d)
Four
50.
The PRIMARY purpose of a business impact analysis (BIA) is to:
a)
provide a plan for resuming operations after a disaster
b)
identify the events that could impact the continuity of an organization's operations
c)
publicize the commitment of the organization to physical and logical security
d)
provide the framework for an effective disaster recovery plan (DRP).
51.
System is broken into small components and each component is developed and delivered to client. The development method is
a)
Spiral
b)
Agile
c)
Prototype
d)
Incremental
52.
The first question to ask in application software review is
a)
What does the application software do
b)
Who are users
c)
Who are IS auditor
d)
Who are founder
53.
How many categories of application control are :
a)
Four
b)
Five
c)
Six
d)
Seven
54.
Which of the following is a practice that should be incorporated into the plan for testing disaster recovery procedures?
a)
Invite client participation.
b)
Involve all technical staff.
c)
Rotate recovery managers
d)
Install locally stored backup.
55.
Which of the following category of application control ensures access to authorized users only
a)
Input Control
b)
Boundary Control
c)
Processing control
d)
Existence Control
56.
SOC usually do not share space with IT DEPARTMENT OR DATA CENTRE
a)
true
b)
false
57.
Which of the following is a requirement to be considered with respect to cloud computing and sourcing options?
a)
The development team needs to define backup procedures
b)
Client needs to be tested for all known browsers
c)
Evaluation of vendors for acquisition of tools and software
d)
Developers to test their code before releasing to testing team
58.
Processed data is stored at Output level ; which of the following leve; of control ensure access to only authorised users
a)
Input Control
b)
Output Control
c)
Boundary Control
d)
Database control
59.
Which application control address the data entry screen design
a)
Boundary controls
b)
Input Control
c)
Processing control
d)
Data file Controls
60.
Which catrgory of Application control perform validation checks to identify errors
a)
Input Control
b)
Processing control
c)
Coutput control
d)
Boundary control
61.
Benefit of IT asset management except
a)
Proper Risk mangement
b)
Asset Tracking
c)
not dealing with asset life cycle
d)
proper audit
62.
The GREATEST challenge in outsourcing data processing is
a)
Data confidentiality
b)
Distance
c)
Data integrity
d)
Cost
63.
In banking sector,to disseminate and foster the sharing of relevant and actionable threat information among membersto ensure continued confidence,is objective of
a)
CERT-IN
b)
CERT-CC
c)
IB-CART
d)
SEIM
64.
Which of the following is not a output control
a)
Retention control
b)
Spooling
c)
Exception report
d)
Control over printing
65.
Which of the following is logic of SIEM
a)
Agents
b)
SIEM Core
c)
SOC
d)
All of the above
66.
Allowing application programmers to directly patch or change code in production programs increases risk of fraud. True or false?
a)
true
b)
false
67.
While reviewing the Application software if situation arise where documentation is not available or is not updated then IS Auditor
a)
should not conduct the audit
b)
should outsource the audit
c)
should obtain technical information about the design and architecture of system
d)
none of above
68.
All actions on the data by Super-User should be
a)
Logged
b)
Verified by data owner
c)
both a and b
d)
none of above
69.
How auditor verify errors and exceptions are handled and corrected in application software
a)
by verifying are these circumstances properly authorized
b)
Does it capture the userid and time stamp for all transactions
c)
Are the exception and critical activities are logged for independent review
d)
All of the above
70.
An organization is implementing an enterprise resource planning (ERP) application to meet its business objectives. Of the following, who is PRIMARILY responsible for overseeing the project in order to ensure that it is progressing in accordance with the project plan and that it will deliver the expected results?
a)
Project sponsor
b)
System development project team
c)
Project steering committee
d)
User project team
71.
In which of the organisations ,project manager has only staff funtion without formal management authority
a)
Projectile organisation
b)
Funtional organisation
c)
Matrix organisation
d)
All of the above
72.
Example of compliance testing of control where sampling could be consider except
a)
Re-performance of a complex calculation
b)
User access right
c)
Follow up on exception
d)
Program change control procedure
73.
Data analytics can be effective for an IS Auditor in :
a)
Planning phase
b)
Fieldwork phase
c)
both a and b
d)
none of above
74.
The Objectives of IS controls includes the Principle of Security. Which if the following is not a part of this Principle of Security?
a)
Confidentiality
b)
Integrity
c)
Availability
d)
Reliability
75.
Business Intelligence handle ------- data
a)
Structured
b)
Unstructured
c)
both a and b
d)
none of above
76.
Function/'s of SIEM agents are
a)
Collects logs for which they are configured
b)
Filter out events based on pre set criteria
c)
Normalisation of log
d)
All of the above
77.
An AI technique that allows computers to understand associations and relationships between objects and events is called
a)
Heuristic processing
b)
Cognitive science
c)
Relative symbolism
d)
Pattern matching
78.
Business application system/software is designed to support a specificorganisational service, function or process, such as inventory management, payroll, market analysis or e-commerce. What is the goal of such a business application?
a)
To enhance the targets and goals of an organisation
b)
To deal with problems relating to business processes
c)
To enhance quality of services
d)
To turn data into information
79.
……...... Consists of all the risk areas that could be subject to audit, resulting in a list of posssible audit engagement that could be performed
a)
Audit Charter
b)
Audit List
c)
Audit Universe
d)
Audit Catalogue
80.
As accounting system is subject to mismanagement, error or fraud, The most direct way to combat these potential problem is
a)
to buy a costly software
b)
to buy a software from reputed organisation
c)
to implement and maintain a strong system of internal control<br />
d)
All of the above
81.
Substantive testing verifies the
a)
intigrity of actual processing
b)
design effectiveness and control effectiveness of control
c)
evidence gathering for testing
d)
All of the above
82.
The decision-making environment of an<br />Middle level manager can be characterized as:
a)
Structured
b)
Semi-structured
c)
Unstructured
d)
None of these
83.
Which of the following is a weakness of the spiral model?
a)
It is criticized to be Inflexible, slow, costly, and cumbersome due to significant structure and tight controls.
b)
Approval process and control are not formal
c)
Sometimes there are no firm deadlines, cycles continue till requirements are clearly identified
d)
Problems may arise pertaining to system architecture because not all requirements are gathered up front for the entire software life cycle.
84.
What is the role of an IS Auditor in the testing phase of SDLC?
a)
Review the test plan for completeness and correctness
b)
Ensure test plans, test data nd test results are maintained for reference
c)
Verify that the system has been installed according to the organisation's change control procedures
d)
Review programmed procedure used for scheduling and running the system along with the system parameters are used in executing the production schedule
85.
Allowing application programmers to directly patch or change code in production programs increases risk of fraud. True or false?
a)
true
b)
false
86.
Programming languages used in AI
a)
Python
b)
R, Java
c)
Prolog,Lisp
d)
All of the above
87.
With respect to System testing, what is the objective of performance testing?
a)
To assess how well the application is able to recover from crashes, hardware failures and other similar problems
b)
To determine that an Information System protects data and maintains functionality as intended.
c)
to determine the stability of a given system or entity based on the requirements
d)
to assess various parameters like response time, speed of processing, effectiveness use of a resources (RAM, CPU etc.), network, etc.
88.
Catagories of Commercial vaults may be
a)
Underground vaults
b)
Free-standing dedicated vaults
c)
Free-standing dedicated vaults
d)
All of the above
89.
……..is group of projects and /or time bound tasks that are linked together through common objectives
a)
Portfolio
b)
Program
c)
project planning
d)
All of the above
90.
The MOST important reason for an IS auditor to obtain sufficient and appropriate audit evidence is to:
a)
comply with regulatory requirements
b)
provide a basis for drawing reasonable conclusions
c)
ensure complete audit coverage
d)
perform the audit according to the defined scope
91.
Which of the following would normally be the MOST reliable evidence for an auditor?
a)
A confirmation letter received from a third party verifying an account balance
b)
Assurance from line management that an application is working as designed
c)
Trend data obtained from World Wide Web (Internet) source
d)
Ratio analysts developed by the IS auditor from reports supplied by line management
92.
An IS auditor usually places more reliance on evidence directly collected. What is an example of such evidence
a)
Evidence collected through personal observation
b)
Evidence collected through systems logs provided by the organization's security administration
c)
Evidence collected through surveys collected from internal staff
d)
Evidence collected through transaction reports provided by the organization's IT administration
93.
project management process begins with
a)
Project charter
b)
Business case
c)
Project sponser
d)
project manager
94.
Which of the following is MOST important to have in a disaster recovery plan?
a)
Backup of compiled object programs
b)
Reciprocal processing agreement
c)
Phone contact list
d)
Supply of special forms
95.
What kind of decision is undertaken by management with the help of Executive Support System
a)
Operational Decisions
b)
Tactical Decisions
c)
Strategic Decisions
d)
Management Decisions
96.
the most successful project manger usually
a)
are from big management universities
b)
has experience of working as an assitant in the project office to full fledged project manger level along with experience received from formal education
c)
these people are technical experts and has knowledge of the relevant field
d)
Have good experience as a functional manager before appointed as project manager
97.
Adequate documentation of the phases of SDLC process are required which consist of
a)
availability of clearly defined objectives on what is to be accomplished during each phase
b)
key deliverables of each phase with project personnel assigned direct responsibilities for these deliverables
c)
a project schedule with highkighted dates for the completion of the key delivarables
d)
A and B both
e)
All A, B and C
98.
Which Operating Team collects data about information systems and threats, conducts business impact analysis, and creates contingency plans for incident response, disaster recovery, business continuity?
a)
Contingency Planning Team
b)
Incident Response Team
c)
Disaster Recovery Team
d)
Disaster Recovery Team
99.
Waterfall approch is suitable if
a)
Project team is less experienced
b)
Project manager is less experienced
c)
Project team composition is not stable due to employee turnover
d)
all of above
e)
both a and b
100.
Who first proposed a blockchain-like protocol?
a)
Stuart Haber
b)
W. Scott Stornetta
c)
David Chaum
d)
Dave Bayer
101.
Which audit technique provides the BEST evidence of the segregation of duties in an IS department?
a)
Discussion with management
b)
Review of the organization chart
c)
Observation and interviews
d)
Testing of user access rights
102.
In an audit of an inventory application, which approach would provide the BEST evidence that purchase orders are valid?
a)
Testing whether inappropriate personnel can change application parameters
b)
Tracing purchase orders to a computer listing
c)
C. Comparing receiving reports to purchase order details
d)
Reviewing the application documentation
103.
When performing investigation, in regard to the evidence gathered, an IS auditor should be MOST concerned with
a)
analysis.
b)
evaluation.
c)
preservation.
d)
disclosure.
104.
an objects data are referred to as its -------------
a)
attributes
b)
methods
c)
templates
d)
class
105.
In this strategy, implementation can be staged with conversion to the new system taking place gradually.
a)
Phased Changeover
b)
Abrupt Changeover
c)
Pilot Changeover
d)
Parallel Changeover
106.
The MOST important reason for an IS auditor to obtain sufficient and appropriate audit evidence is to:
a)
comply with regulatory requirements.
b)
provide a basis for drawing reasonable conclusions.
c)
ensure complete audit coverage.
d)
perform the audit according to the defined scope.
107.
As compared to understanding an organization's IT process from evidence directly collected, how valuable are prior audit reports as evidence
a)
The same value
b)
Greater value
c)
Lesser value.
d)
Prior audit reports are not relevant.
108.
Some things to consider when determining what reportable findings should be are
a)
How many findings there are and how long the report would be if all findings were included
b)
The materiality of the findings in relevance to the audit objectives and management's tolerance for risk
c)
How the recommendations will affect the process and future audit work
d)
Whether the test samples were sufficient to support the conclusions
109.
Based on processing requirement EIS is
a)
Explicit knowlede
b)
information
c)
Tacit knowlede
d)
Basic data
110.
Evidence loses its value in legal proceedings in the absence of _
a)
Recency of information
b)
Validation by the I.T. dept. of the police
c)
Professional maintenance of the chain of custody
d)
Authenticated hard copies
111.
Blockchains store data in the form of?
a)
Line
b)
Circle
c)
Block
d)
Rhombus
112.
Which are the 4 domains of Management Objective
a)
APO, BAI,DSS & MEA
b)
APO, BAI, MIS & MEA
c)
APO, MIS, DSS & MEA
d)
APO, BAI, DSS & MIS
113.
What are Test working papers in IS Audit Documentation
a)
Draft of the final IS audit report prepared for the Board of Directors
b)
Those prepared or obtained as a result of compliance/testing procedures
c)
Draft of the preliminary IS audit report submitted to senior management for comments
d)
IS audit team’s answers to test questions on the auditee’s business & environment
114.
What are the characteristics of a very well coded application program?
a)
Good coding standards, Accuracy and Speed
b)
Reliability, Robustness, Accuracy, Efficiency, Usability, Readability
c)
Flexibility, Speed, Coding Standards
d)
Reliability, Flexibility and Speed
115.
Which is the ICAI standard on auditing which deals with the Auditor’s responsibility to prepare audit documentation for financial statements ?
a)
SA 500
b)
SA 580
c)
SA 230
d)
SA 1205
116.
Audit evidence in IS Audit _
a)
Excludes IS Auditor observations, notes from interviews etc
b)
Is not subject to the usual audit rules of sufficiency & competency
c)
Is information substantiating alignment with objectives & supporting audit conclusions
d)
That which would stand scrutiny in a court of law
117.
Which of the following methods of results analysis, during the testing of the business continuity plan (BCP), provides the BEST assurance that the plan is workable?
a)
Quantitatively measuring the results of the test
b)
Measurement of accuracy
c)
Elapsed time for completion of prescribed tasks
d)
Evaluation of the observed test results
118.
Which is the ISACA standard relating to use of services of external experts
a)
1206
b)
230
c)
1205
d)
500
119.
What does Work Breakdown Structure (WBS) represent?
a)
The project in terms of manageable and controllable units of work
b)
Detailed specifications with objectives
c)
Assigned responsibilities and deadlines
d)
Work documents containing the start and finish dates
120.
The business case is a key element of the decision making process throughout the life cycle of project. What information does a business case provide to an organisation?
a)
decide whether the SDLC project should be undertaken
b)
Explore solutions and make a recommendation
c)
Develop a new application system
d)
Outline and calculate of benefits
121.
Which of the following is not a scope of SIEM
a)
Conduct research and analysis
b)
Collect Logs
c)
Nos. of correlated files to be stored
d)
Kind of reports to be provided
122.
which among the following is correct with regards to Audit Risk (AR)
a)
AR = IR + CR + DR
b)
AR = IR + CR * DR
c)
AR = IR + CR * DR
d)
AR = IR * CR * DR
123.
You have been engaged as a Consultant to carry out IS Audit of a large organization. What is the first step you would take while commencing your work ?
a)
Commence auditing of the financials
b)
List all the software and hardware used in the organization
c)
Peruse financials for the previous three years
d)
Identify all risks present in the IT environment of the organization
124.
----------- defines the processes of setting up activities for establishing a business continuity capability and the ongoing management and maintenance of business continuity capability.
a)
BCM (Business Continuity Management) Policy
b)
BCP Manual
c)
DRP Manual
d)
None of the above
125.
Which of the following is a collection of related,structured activities or tasks that produce a specific service or product for a particular customer or customers
a)
Business Case
b)
Audit trail
c)
Business Process
d)
Audit charter
126.
Managing IT risk of the enterprise starts with defining
a)
IT Risk
b)
Risk Management
c)
Audit universe
d)
Risk Universe
127.
For effective risk assessment, auditors should ideally supplement the regular risk assessment procedures with ______________
a)
Observation, inspection & analytical procedures
b)
Interviews with client's competitors
c)
Intensive analysis of historical data
d)
Interviews with client's suppliers
128.
Breaking down a table to such extend that other columns in a table are dependent only on key column of the table is known as ….............
a)
Primary Key
b)
Normalisation
c)
Isolation
d)
Object
129.
....is a team of experts in organisation,industry,state or country,that monitor alerts and declare incidents
a)
SOC
b)
SIEM
c)
CERT
d)
All of the above
130.
What is the intent of SDLC?
a)
To process data of relevant business processes
b)
To enhance the targets and goals of an organisation
c)
To improve the quality of services
d)
To examine a business situation and improve it
131.
Which of the following are one of the KEY Areas that should be covered during an IS Audit of Application software ?
a)
List of authorised users of the software
b)
Adherence to business rules in the flow & processing accuracy
c)
Validity of software licence
d)
Cost of the software & availability of cheaper alternatives
132.
which of the level provides advaned trouble shooting
a)
Level 4
b)
Level 3
c)
Lever 2
d)
Level 1
133.
What are some of the key reasons for establishing controls and auditing in a computerized environment ?
a)
Computers are more prone to make errors in handling subjective big data
b)
There is more scope for fraud & error in a computerized environment
c)
Data may be entered into the system without supporting documents
d)
There is no choice since most operations are computerized
134.
Which of the following is not a type of entity in DBMS
a)
Name
b)
Place
c)
People
d)
Object
e)
Concept
135.
Objective of IS audit process is to evaluate the adequacy of internal controls with regard to both specific computer program and data processing environment
a)
true
b)
false
136.
Who of the following would approve or reject Major changes in cofi guration
a)
Management
b)
Change control Board
c)
User
d)
System Administrator
137.
What is the correct order of Disaster Recovery Phases? A.Disaster Assessment, B.Disaster Recovery Activation, C.Alternate Site/Data Centre Rebuild D.Return to primary site
a)
ABCD
b)
CABD
c)
ADBC
d)
ACBD
138.
Monitering team of SOC,after qualifiying alert as incident,send declared incident to
a)
Incident Resopnse Team
b)
Team of Investigators
c)
Cyber Security Team
d)
Both A and B
139.
What are Substantive tests ?
a)
Tests which validate the internal controls exercised over financial transactions
b)
Tests which are done only by choice, if required, rather than by default
c)
Tests to evaluate the integrity of individual transactions, data, etc.
d)
Tests which are not used for checking for monetary errors affecting financial parameters
140.
When storing data archives offsite, what must be done to ensure data completeness
a)
Data must be normalized
b)
Data must be validated
c)
Data must be parallel-tested
d)
Data must be synchronized
141.
In IS Audit, Operational Effectiveness ______________
a)
Refers to effectiveness of the organization's operations
b)
Refers to effectiveness of the IS Audit
c)
Refers to actual performance of the Control in IT environment
d)
Refers to achievements in line with overall organizational strategy
142.
In IS audit, for manual controls, documented evidence substantiating control performance as per design is ______________
a)
Through physical records created when the controls have been operated
b)
Through appropriate reports and screen shots from the system
c)
Through records of interviews with operational staff
d)
Through software trail of the various components of the control process
143.
As SOC handle enormous data,to create insightful metrics and performance measures, it uses
a)
Data analytics
b)
Artificial Intelligence
c)
Robotics
d)
IOT
144.
Which is the tool used in IS audit for assessing the proper level of controls ?
a)
ISACA method 230
b)
Random sampling of transactions
c)
A control matrix, comparing known types of errors with known type of controls
d)
ICAI guidelines on the appropriate level of controls
145.
Who uses six sigma technique for improving the performance of business operations
a)
User Manager
b)
Process owner
c)
Data Owner
d)
System Owner
146.
The types of Disaster classifications generally used in the BCP manual are<br />
a)
Incident, Minor Disaster, Major Disaster
b)
Problem,Minor disaster, major disaster,Catastropic disaster
c)
Problem,Minor disaster,Catastropic disaster
d)
Incident, Major disaster,Catastropic Disaster
147.
Which of the following is the GREATEST risk when implementing a data warehouse?
a)
increased response time on the production system
b)
Access controls that are not adequate to prevent data modification
c)
Data duplication
d)
Data that is not updated or curren
148.
Which of the following is a program evaluation review technique that considers different scenarios for planning and control projects?
a)
Function Point Analysis (FPA)
b)
GANTT
c)
Rapid Application Development (RAD)
d)
PERT
149.
Which of the following is the MOST critical and contributes the greatest to the quality of data in a data warehouse?
a)
Accuracy of the source data
b)
Credibility of the data source
c)
Accuracy of the extraction process
d)
Accuracy of the data transformation
150.
How is a product for which software is available and can be implemented without customisation classified as?
a)
Generic products without customisation
b)
Commercial product with customisation
c)
Outsourced development
d)
Commercial product without customisation
151.
Management and administration of metadata repository and data administration tools are entrusted to the -------------
a)
Database Administrator
b)
Data Administrator
c)
Documentation Specialist
d)
User Manager
152.
Which of the following is an implementation risk within the process of decision support systems?
a)
Management control
b)
Semistructured dimensions
c)
inability to specify purpose and usage patterns
d)
Changes in decision processes
153.
Which of the following would be the MOST significant audit finding when reviewing a point-of-sale (POS) system?
a)
invoices recorded on the POS system are manually entered into an accounting application
b)
An optical scanner is not used to read bar codes for the generation of sales invoices
c)
Frequent power outages occur, resulting in the manual preparation of invoices
d)
Customer credit card information is stored unencrypted on the local POS system
154.
What is the primary objective of a control self-assessment (CSA) program
a)
Enhancement of the audit responsibility
b)
Elimination of the audit responsibility
c)
Replacement of the audit responsibility
d)
Integrity of the audit responsibilit
155.
Which Operating team is the first team to arrive during the outbreak of an incident?
a)
Incident Response Team
b)
Disaster Recovery Team:
c)
Both of the above
d)
None of the above
Reset
