WorksheetsGITC Training - Day 1
Total questions: 10
Worksheet time: 3mins
What is material misstatement?
An error in financial transactions
An error in system configurations
A misstatement, if material individually or in combination with other misstatements, causes the financial statements not to be presented fairly in conformity with the applicable financial reporting framework. Risk that the financial statements are materially misstated
A failure in controls when testing the design and/or operating effectiveness of controls for financial reporting
Which one is NOT included as Area of IT Controls?
Access Security
System Change Control
Data Center and Network Operation
Design and Operating Effectiveness
Which of the following answers is included as Risk Arising from IT?
Inappropriate changes are made to application systems or programs that contain relevant automated controls (i.e., configurable settings, automated algorithms, automated calculations, and automated data extraction) and/or report logic.
Use of the work of others
IT Environment and Governance
Automated Controls
Why do we evaluate the design of a control?
To make sure that we understand the design of the control
To make sure that we put the design in our workpapers properly
To determine if a deficiency in design exists
To see if there are other controls that might meet our needs for testing
Which of the following is a cyber breach?
A companies network administrator accounts are compromised and ransomware implemented and executed within the network causing the company to be locked out of systems.
An employee's laptop is stolen out of their car while parked at their house
One of the IT personnel lost their hard disk that contains company's data
A server was down because of a power failure
Which of the following is a risk arising from IT?
Substantive procedures alone are not enough
Design of controls
Operating Effectiveness
Users have access privileges beyond those necessary to perform their assigned duties, which may create improper segregation of duties.
Which of the following planning phase is not for auditors and IT Specialists to work together to determine the audit scope for the IT specialists?
Auditors verify that all IT Specialist workpapers were received and archive accordingly
Identify relevant applications
Identify system generated reports and linkage to GITCs
Identify automated controls
Why do we perform walkthroughs?
To test the systems are running as intended
To test management’s process to identify relevant controls
To obtain an understanding about relevant controls and how transactions are processed
To determine if a deficiency in design exists
Which of the following activities is NOT a way to understanding likely sources of misstatement?
Obtain detailed control procedure description
Process flow diagrams
Walkthroughs
Design and Operating Effectiveness of controls
What is ICFR?
A nonprofit corporation to oversee the audits of public companies & other issuers to protect the interests of investors & further the public interest in the preparation of informative, accurate and independent audit reports.
Internal Control over Financial Reporting has been required for public companies and included as part of issuer audits for more than a decade
Professional standards for the auditing of financial information
A framework created by ISACA for information technology (IT) management and IT governance
