Font size
WorksheetsIT Audit and Controls
Total questions: 60
Worksheet time: 29mins
Technology has impacted the business environment in three areas. What are those?
the use and processing of information
the control process
the auditing profession
IT governance
All of the following are recent technologies that have and will certainly continue to revolutionize organization, except one.
Enterprise Resouce Planning
Cloud Computing
IT Auditing
Mobile Device MAnagement
It allows multiple functions to access a common database-reducing storage costs and increasing consistency and accuracy of data from a single source.
(a)
It is responsible for managing and administering mobile devices provided to employee as part of their work responsibilities.
Enterprise Resource Planning
Mobile Device Management
Human Resource Management
Cloud Computing
It is a system that allows remote assets "things" to interact and communicate among them and with other network systems according to Gartner Inc.
Enterprise Resource Planning
Mobile Device Management
Cloud Computing
Internet of Things
List 5 challenges of Big Data.
Financial auditing encompasses all activities and responsibilities concerned with the rendering of an opinion on the fairness of financial statements.
TRUE
FALSE
Establishes consistent guidelines for financial reporting by corporate managers.
(a)
GAAP is important because it helps maintain trust in the financial markets.
TRUE
FALSE
Enumeration: Three Categories of Generally Accepted Auditing Standards (GAAS).
IFRS stands for (a) .
These standards created by the International Accounting Standards Board (IASB) to respond to the increasing global business environment and address the need to compare financial statements prepared in different countries.
Generally Accepted Accounting Principles
Generally Accepted Auditing Standards
International Financial Reporting Standards
International Financial Reporing Principle
International Financial Reporting Standards (IFRS) were created to bring consistency and integrity to accounting standards and practices, regardless of the company or the country.
TRUE
FALSE
IIA stands for (a) .
CAE stands for (a) .
An auditor which is essentially serves as the eyes and ears of the company’s senior leadership and board of directors
(a)
Which is NOT a duties of an auditor?
Identifying shortfalls or gaps in processes
Investigate fraud
Assess the company’s risks and the efficacy of its risk management efforts
None of the above
ISACA stands for (a) .
IT auditing became an integral part of the audit function because it supports the auditor’s judgement on the quality of the information processed by computer systems.
TRUE
FALSE
Enumeration : TSPC criteria for attestation (4)
It define as information integrity (level of confidence and trust that can be placed on the information) and service availability.
Information Assurance
IT Auditing
IT governance
Data Security
A methodology that links internal auditing to an organization's overall risk assessment.
(a)
Who's responsible for identifying and managing risk?
(a)
Who provides assurance that those risks have been properly managed?
(a)
Which among these are included on things that internal auditors should do?
Get management involved
Ignore risk
Assess risk impact and likelihood
Should not understand the business
The bigger the company, the bigger the audit team.
True
False
Recognizing risks can be a daunting task.
True
False
When we have all the risks identified, they must be sorted in various ways, according to their impact on organization.
True
False
Strategy is not only as good as it is executed.
True
False
Give one of the steps for effective management risk plan.
(a)
Give one of the steps for effective management risk plan.
(a)
What is one way that you can prevent
identity theft?
Maxing out your credit card
Throwing personal documents away without
shredding them
Opening several accounts
Examining bank accounts
on a regular basis
What should you do if someone asks for your
password?
Provide your password to your supervisor
Provide your password to Help Desk
Do not give your
password out to anyone
Provide your password to the IT security officer
True or False: An “H” drive is a computer
drive that is stored on the network and not on your local machine. If something
were to happen to your computer, data that is stored in the H drive will not be
lost.
True
False
Which of the following is true about
phishing?
Phishing is an act of catching fish for dinner.
Phishing is an attempt
to acquire sensitive information such as passwords for malicious reasons.
Phishing is forgetting your password and
contacting IT to reset.
Phishing is a virus that will not allow you to
log onto your computer.
Which of the following information is
important in protecting client’s data?
Health insurance beneficiary numbers
Phone numbers
Zip codes
All of the above
Which of the following scenarios is
appropriate in protecting client’s information?
Leaving printed information on top of your office
desk overnight.
Storing client’s personal cell phone numbers on
a non-MHMR device.
Encrypting emails
outside of the agency by typing the word “encrypt” in the subject line of your
email.
Posting client information on social media.
Auditor unique role is for the following expertise except for
A. Determining proper audit procedure
B. Provide relevant information on economic event
C. Deciding the number and types of items to test evidence
D. Evaluating audit results
Which of the following describe the true relationship between auditor, client and external users?
A. Management provides capital to external users and auditor is hired to provide report relied upon by users for assurance.
B. External users rely on auditor’s report assurance to reduce information risk provided by management
C. Auditor ensure report are based on management decision on the economic event to be presented to external users
D. Management and auditor provide financial statement to external users
The distinction between the role of auditor and accountant can be best describe as
A. Accountant provide financial information for decision making while auditor determine whether the information properly reflects the economic events of the accounting period.
B. Accountant must have a thorough understanding of the principles and rules to prepare financial statement while auditor rely on the theory of evidence to verify the financial statement.
C. Auditor is responsible for detection and prevention of error and frauds while accountant ensure the credibility and quality dimension of financial statement.
D. Auditor must possess expertise in the accumulation and interpretation of audit evidence while accountant need to be expert in understanding the principles and rules.
External auditor considered reliance on internal auditor based on the evaluation of effectiveness of audit conduct by internal auditor if
A. Independence of the audit team have been evaluated
B. Competency and skills needed are achieved
C. Recommendation from client point of view accepted
D. Relevant audit tests of the internal controls and financial statement have been performed
The internal auditor’s independence is most likely to be compromised when the internal audit department is responsible directly to audit committee of the board of directors.
TRUE
FALSE
Internal and external auditor performed a different methodology in their audits.
TRUE
FALSE
At the planning state, the auditor considered materiality at the financial statement level only
TRUE
FALSE
Three major differences between operational and financial audit are the purpose of audit, distribution of report and inclusion of non-financial areas in operational audit.
TRUE
FALSE
A computer is able to identify betweenone person to another through a security device called the _________
User Security Object
User Domain Object
User Account Object
User Device Object
These are access privilege granted to a user account
Permissions
Pemisions
Permirions
Permisions
The administrator may define user account in a way that a user is able to log on tl any system, which is a member of a domain using user account.
Roaming
User Rights
Auditing
Identification
The server can track access and use it by the main user accounts.
Roaming
User Rights
Auditing
Identification
In the workplace, computers are used by an individual for personal use.
True
False
People who try to gain illegal access to a computer system.
HACKERS
NETWORK PERIMETER
GATEWAY
CYBERATTACKS
The network boundary between a private user network and the internet
SECURE SOCKET LAYER
TWO-FACTOR AUTHENTICATION
GATEWAY
NETWORK PERIMETER
New techniques allow criminal __________ to compromise legitimate sites to download malware to your computer.
HACKERS
CYBERATTACKS
SECURE SOCKET LAYER
TWO-FACTOR AUTHENTICATION
