wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IT Audit and Controls

Total questions: 60

Worksheet time: 29mins

Name
Class
Date
1.

Technology has impacted the business environment in three areas. What are those?

a)

the use and processing of information

b)

the control process

c)

the auditing profession

d)

IT governance

2.

All of the following are recent technologies that have and will certainly continue to revolutionize organization, except one.

a)

Enterprise Resouce Planning

b)

Cloud Computing

c)

IT Auditing

d)

Mobile Device MAnagement

3.

It allows multiple functions to access a common database-reducing storage costs and increasing consistency and accuracy of data from a single source.

(a)  

4.

It is responsible for managing and administering mobile devices provided to employee as part of their work responsibilities.

a)

Enterprise Resource Planning

b)

Mobile Device Management

c)

Human Resource Management

d)

Cloud Computing

5.

It is a system that allows remote assets "things" to interact and communicate among them and with other network systems according to Gartner Inc.

a)

Enterprise Resource Planning

b)

Mobile Device Management

c)

Cloud Computing

d)

Internet of Things

6.

List 5 challenges of Big Data.

4 lines
7.

Financial auditing encompasses all activities and responsibilities concerned with the rendering of an opinion on the fairness of financial statements.

a)

TRUE

b)

FALSE

8.

Establishes consistent guidelines for financial reporting by corporate managers.

(a)  

9.

GAAP is important because it helps maintain trust in the financial markets.

a)

TRUE

b)

FALSE

10.

Enumeration: Three Categories of Generally Accepted Auditing Standards (GAAS).

4 lines
11.

IFRS stands for (a)   .

12.

These standards created by the International Accounting Standards Board (IASB) to respond to the increasing global business environment and address the need to compare financial statements prepared in different countries.

a)

Generally Accepted Accounting Principles

b)

Generally Accepted Auditing Standards

c)

International Financial Reporting Standards

d)

International Financial Reporing Principle

13.

International Financial Reporting Standards (IFRS) were created to bring consistency and integrity to accounting standards and practices, regardless of the company or the country.

a)

TRUE

b)

FALSE

14.

IIA stands for (a)   .

15.

CAE stands for (a)   .

16.

An auditor which is essentially serves as the eyes and ears of the company’s senior leadership and board of directors

(a)  

17.

Which is NOT a duties of an auditor?

a)

Identifying shortfalls or gaps in processes

b)

Investigate fraud

c)

Assess the company’s risks and the efficacy of its risk management efforts

d)

None of the above

18.

ISACA stands for (a)   .

19.

IT auditing became an integral part of the audit function because it supports the auditor’s judgement on the quality of the information processed by computer systems.

a)

TRUE

b)

FALSE

20.

Enumeration : TSPC criteria for attestation (4)

4 lines
21.

It define as information integrity (level of confidence and trust that can be placed on the information) and service availability.

a)

Information Assurance

b)

IT Auditing

c)

IT governance

d)

Data Security

22.

A methodology that links internal auditing to an organization's overall risk assessment.

(a)  

23.

Who's responsible for identifying and managing risk?

(a)  

24.

Who provides assurance that those risks have been properly managed?

(a)  

25.

Which among these are included on things that internal auditors should do?

a)

Get management involved

b)

Ignore risk

c)

Assess risk impact and likelihood

d)

Should not understand the business

26.

The bigger the company, the bigger the audit team.

a)

True

b)

False

27.

Recognizing risks can be a daunting task.

a)

True

b)

False

28.

When we have all the risks identified, they must be sorted in various ways, according to their impact on organization.

a)

True

b)

False

29.

Strategy is not only as good as it is executed.

a)

True

b)

False

30.

Give one of the steps for effective management risk plan.

(a)  

31.

Give one of the steps for effective management risk plan.

(a)  

32.

What is one way that you can prevent

identity theft?

a)

Maxing out your credit card

b)

Throwing personal documents away without

shredding them

c)

Opening several accounts

d)

Examining bank accounts

on a regular basis

33.

What should you do if someone asks for your

password?

a)

Provide your password to your supervisor

b)

Provide your password to Help Desk

c)

Do not give your

password out to anyone

d)

Provide your password to the IT security officer

34.

True or False: An “H” drive is a computer

drive that is stored on the network and not on your local machine. If something

were to happen to your computer, data that is stored in the H drive will not be

lost.

a)

True

b)

False

35.

Which of the following is true about

phishing?

a)

Phishing is an act of catching fish for dinner.

b)

Phishing is an attempt

to acquire sensitive information such as passwords for malicious reasons.

c)

Phishing is forgetting your password and

contacting IT to reset.

d)

Phishing is a virus that will not allow you to

log onto your computer.

36.

Which of the following information is

important in protecting client’s data?

a)

Health insurance beneficiary numbers

b)

Phone numbers

c)

Zip codes

d)

All of the above

37.

Which of the following scenarios is

appropriate in protecting client’s information?

a)

Leaving printed information on top of your office

desk overnight.

b)

Storing client’s personal cell phone numbers on

a non-MHMR device.

c)

Encrypting emails

outside of the agency by typing the word “encrypt” in the subject line of your

email.

d)

Posting client information on social media.

38.

Auditor unique role is for the following expertise except for

a)

A. Determining proper audit procedure

b)

B. Provide relevant information on economic event

c)

C. Deciding the number and types of items to test evidence

d)

D. Evaluating audit results

39.

Which of the following describe the true relationship between auditor, client and external users?

a)

A. Management provides capital to external users and auditor is hired to provide report relied upon by users for assurance.

b)

B. External users rely on auditor’s report assurance to reduce information risk provided by management

c)

C. Auditor ensure report are based on management decision on the economic event to be presented to external users

d)

D. Management and auditor provide financial statement to external users

40.

The distinction between the role of auditor and accountant can be best describe as

a)

A. Accountant provide financial information for decision making while auditor determine whether the information properly reflects the economic events of the accounting period.

b)

B. Accountant must have a thorough understanding of the principles and rules to prepare financial statement while auditor rely on the theory of evidence to verify the financial statement.

c)

C. Auditor is responsible for detection and prevention of error and frauds while accountant ensure the credibility and quality dimension of financial statement.

d)

D. Auditor must possess expertise in the accumulation and interpretation of audit evidence while accountant need to be expert in understanding the principles and rules.

41.

External auditor considered reliance on internal auditor based on the evaluation of effectiveness of audit conduct by internal auditor if

a)

A. Independence of the audit team have been evaluated

b)

B. Competency and skills needed are achieved

c)

C. Recommendation from client point of view accepted

d)

D. Relevant audit tests of the internal controls and financial statement have been performed

42.

The internal auditor’s independence is most likely to be compromised when the internal audit department is responsible directly to audit committee of the board of directors.

a)

TRUE

b)

FALSE

43.

Internal and external auditor performed a different methodology in their audits.

a)

TRUE

b)

FALSE

44.

At the planning state, the auditor considered materiality at the financial statement level only

a)

TRUE

b)

FALSE

45.

Three major differences between operational and financial audit are the purpose of audit, distribution of report and inclusion of non-financial areas in operational audit.

a)

TRUE

b)

FALSE

46.

A computer is able to identify betweenone person to another through a security device called the _________

a)

User Security Object

b)

User Domain Object

c)

User Account Object

d)

User Device Object

47.

These are access privilege granted to a user account

a)

Permissions

b)

Pemisions

c)

Permirions

d)

Permisions

48.

The administrator may define user account in a way that a user is able to log on tl any system, which is a member of a domain using user account.

a)

Roaming

b)

User Rights

c)

Auditing

d)

Identification

49.

The server can track access and use it by the main user accounts.

a)

Roaming

b)

User Rights

c)

Auditing

d)

Identification

50.

In the workplace, computers are used by an individual for personal use.

a)

True

b)

False

51.

People who try to gain illegal access to a computer system.

a)

HACKERS

b)

NETWORK PERIMETER

c)

GATEWAY

d)

CYBERATTACKS

52.

The network boundary between a private user network and the internet

a)

SECURE SOCKET LAYER

b)

TWO-FACTOR AUTHENTICATION

c)

GATEWAY

d)

NETWORK PERIMETER

53.

New techniques allow criminal __________ to compromise legitimate sites to download malware to your computer.

a)

HACKERS

b)

CYBERATTACKS

c)

SECURE SOCKET LAYER

d)

TWO-FACTOR AUTHENTICATION

54.
IT _____________ is a process that provides assurance for IT and IS and helps to mitigate risks associated with use of technology.
a)
control
b)
governance
c)
risk management
d)
review
55.
An internal audit is typically conducted by auditors who work for the organization, but this task may be outsourced to other organizations.
a)
True
b)
False
56.
Which of the following components is not part of IT governance?
a)
control planning
b)
security assessment
c)
managing incident response
d)
control development
57.
Which of the following components is not part of IT compliance?
a)
IT audit
b)
security assessment
c)
control development
d)
IT compliance assessment
58.
An audit _____________ outlines the overall authority, scope and responsibilities of the audit function.
a)
exit report
b)
comprehensive report
c)
letter of intent
d)
charter
59.
The audit response verification can be obtained at the _______________ stage of an IT audit.
a)
assessment
b)
report
c)
follow-up
d)
planning
60.
The scope of an IT audit often varies, but can involve any combination of the following:
a)
organizational, compliance, application and social
b)
organizational, compliance, application and technical
c)
regional, compliance, application and technical
d)
organizational, compliance, systems and technical