Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Group 3 - International Audit

Total questions: 50

Worksheet time: 25mins

Name
Class
Date
1.

1. Which is not the purpose of Risk analysis?

a)

A. It supports risk based audit decisions

b)

B. Assists the Auditor in determining Audit objectives

c)

C. Ensures absolute safety during the Audit

d)

D. Assists the Auditor in identifying risks and threats

2.

2. Which term best describes the difference between the sample and the population in the sampling process?

a)

A. Precision

b)

B. Tolerable error rate

c)

C. Level of Risk

d)

D. Analytical Data

3.

3. Name one of the purposes of creating Business Continuity Plan

a)

A. To maximise the number of decisions made during an incident

b)

B. To minimise decisions needed during a crisis

c)

C. To lower business insurance premiums

d)

D. To provide guidance for federal regulations

4.

4. Failing to prevent or detect a material error would represent which type of risk?

a)

A. Overall Audit Risk

b)

B. Detection Risk

c)

C. Inherent Risk

d)

D. Control Risk

5.

5. Which is one of the bigger concerns regarding asset disposal?

a)

A. Residual Asset Value

b)

B. Employees taking disposed property home

c)

C. Standing data

d)

D. Environmental Regulations

6.

6. Who should issue ogranisational policies?

a)

A. Policies should originate from the bottom and move upto the middle management level for approval

b)

B. The policy should be issued in accordance with the approved standards by the middle management level

c)

C. Policy can be issued by any level of management based on a case to case basis

d)

D. The policy should be signed and enforced by the highest level of management

7.

7. A program check that ensures data entered by a data entry operator is

complete is an example of a

a)

A. Detective Control

b)

B. Preventive Control

c)

C. Corrective Control

d)

D. Redundancy Control

8.

8. What is the primary objective in problem escalation?

a)

A. Improve customer satisfaction

b)

B. Optimise the number of skilled personnel

c)

C. Ensure the correct response

d)

D. Prove that the IT staff is competent

9.

9. Which of the following is LEAST important when Auditors review Internal Controls?

a)

A. The existence of an Audit Committee in the Organisation

b)

B. The Organisational structure and the Management style used by the Organisation

c)

C. The existence of a Budgeting System

d)

D. The number of Personnel working for the Organisation

10.

10. What is the best example of why plan testing is important?

a)

A. To prove the plan worked the first time

b)

B. To find the correct problems

c)

C. To show the team that is not pulling their own weight

d)

D. To verify that everyone shows up at the recovery site

11.

11. Continuity planners can create plans without the business impact analysis (BIA) process because

a)

A. Business Impact Analysis is not required

b)

B. Management already dictated all the key processes to be used

c)

C. Not possible, critical processes continuously changes

d)

D. Risk assessment is acceptable

12.

12. What are the three competing demands to be addressed by the Project Management?

a)

A. Scope, Authority and Availability of Resources

b)

B. Time, Cost and Scope

c)

C. Requirements, Authority and Responsibility

d)

D. Authority, Organisational Culture and Scope

13.

13. How should management act to best deal with emergency changes?

a)

A. Emergency changes can not be made without advanced testing

b)

B. All changes should still undergo review

c)

C. The changes control process does not apply to emergency conditions

d)

D. Emergency changes are not allowed under any condition

14.

14. Which is the following is not an objective of a control?

a)

A. Reduce expected losses from irregularities

b)

B. Reduce the probability of an error occurring

c)

C. Reduce the amount of loss if an occurs

d)

D. Provide for all the failures and to ensure that business is protected fully from such failures

15.

15. IT audit is the process of collecting and evaluating evidence to determine

a)

A. Whether a computer system safeguards assets

b)

B. Whether maintains data integrity

c)

C. Whether allows organisational goals to be achieved effectively and uses resources efficiently

d)

D. All of the above

16.

16. The objectives of IT audit include:

a)

A. Ensures asset safeguarding

b)

B. Ensures that the attributes of data or information are maintained

c)

C. Both (a) and (b)

d)

D. None of the above

17.

17. Which is not an attribute of data or information

a)

A. Compliance

b)

B. Integrity

c)

C. Confidentiality

d)

D. Technology

18.

18. Which among the following does not encompass organisational management controls within the information processing facility (IPF) and management controls within the information processing facility (IPF)

a)

A. Sound human resource policies and management practices

b)

B. Methods to assess effective and efficient operations.

c)

C. The regulatory framework within which the business is carried out

d)

D. Separation of duties within the information processing environment

19.

19. The essential aspect to be understood about the organisation subject to IT audit is

a)

A. Organisation's business and its strategic goals and objectives

b)

B. The number of operating units / locations and their geographic dispersion

c)

C. Major pending projects in progress

d)

D. All of the above

20.

20. While understanding the type of software used in the organisation the IT auditor has to

a)

A. See the policy decision on developing software inhouse or to buy commercial products.

b)

B. Collect details of operating systems, application system and database management system

c)

C. Collect information relating to network architecture and technology to establish connectivity.

d)

D. All of the above

21.

21. The security goals of the organisation does not cover

a)

A. Confidentiality

b)

B. Probability and impact of occurrence

c)

C. Availability

d)

D. Integrity

22.

22. Find out the incorrect statement with reference to Risk assessment

a)

A. The detailed audit is needed where the risk assessment is low and the risk management is high

b)

B. An independent assessment is necessary whether threats have been countered / guarded against effectively and economically

c)

C. The assessment of the soundness of IT system will necessarily have to study the policies and process of risk management

d)

D. None of the above

23.

23.Consider the following statement and find out the correct one w.r.t. IT audit

a)

A. In inherent risk there is an assumption that there are related internal controls.

b)

B. In control risk errors will not be prevented or detected and corrected by the internal control system.

c)

C. The control risk associated with computerised data validation procedures is ordinarily high.

d)

D. None of the above

24.

24. What is the characteristic of detective control

a)

A. Minimise the impact of a threat

b)

B. Use controls that detect and report the occurrence of an error, omission or malicious act.

c)

C. Detect problems before they occur

d)

D. None of the above

25.

25. Which among the following is not characteristic of "preventive control'

a)

A. Monitor both operation and imports

b)

B. Prevent error, omission or malicious act from occurring

c)

C. Correct errors from occurring

d)

D. None of the above

26.

26. IT access is not controlled or regulated though password it indicates

a)

A. Poor security control

b)

B. High risk of the system getting hacked

c)

C. High risk of the system getting breached

d)

D. All of the above

27.

27.Basic risk areas which the external  auditor may come across when reviewing internal audit's work include

a)

A. Availability of sufficient resources, in terms of finance, staff and skills required

b)

B. Involvement of intemal audit with IT system and under development

c)

C. Management not required to act on internal audit's recommendations

d)

D. None of the above

28.

28. Which is the common audit objectives for an IT audit

a)

A. Review of the security of the IT system

b)

B. Evaluation of the performance of a system

c)

C. Examination of the system development process and the procedures followed at various stages involved

d)

D. All of the above.

29.

29. Failing to detect a material error would represent which type of risk?

a)

A. Overall Audit Risk

b)

B. Detection Risk

c)

C. Inherent Risk

d)

D. Control Risk

30.

30. Which is one of the bigger concerns regarding asset disposal?

a)

A. Residual Asset Value

b)

B. Employees taking disposed property home

c)

C. Standing data

d)

D. Environmental Regulations

31.

31. Audit Trail is an example of.... control

a)

A. Detective

b)

B. Application

c)

C. Preventive

d)

D. Correction

32.

32. Which one is not a Boundary control audit trail:

a)

A. Resources requested

b)

B. No of sign on attempts

c)

C. Authentication of information supplied

d)

D. Time and date of printing output

33.

33. Which among the following is not a compliance test as related to IT environment

a)

A. Determining whether passwords are changed periodically.

b)

B. Determining whether systems logs are reviewed

c)

C. Determining whether program changes are authorised.

d)

D. Reconciling account balances

34.

34. Which among the following is not a limitation in IT Audit

a)

A. Data used not from production environment

b)

B. If these is only production environment and audit could not test dummy data

c)

C. "Read only Access" given to audit

d)

D. None of the above

35.

35. The type of audit evidence which the auditor should consider using in IT audit includes

a)

A. Observed process and existence of physical items

b)

B. Documentary audit evidence excluding electronic records

c)

C. Analysis excluding IT enabled analysis

d)

D. None of the above

36.

36. What is the commonly used example of generalised software?

a)

A.CAAT

b)

B.IDEA

c)

C.COBIT

d)

D.None of the above

37.

37. A higher risk of system violation happens where

a)

A. The audit module is not operational

b)

B. The audit module has been disabled

c)

C. The audit module is not periodically reviewed

d)

D. All of the above

38.

38. In which type of IT Audit Auditor ensure that it management has developed a controlled environment for information processing

a)

A. System and Application

b)

B.System development

c)

C. Information processing facility

d)

D. Management of IT and Enterprise Architecture

39.

39. Which among the following is true as to Audit Reporting

a)

A. Normal reporting format is not adhered to in the case of IT Audit

b)

B. In IT audit, the base of the focus is the system

c)

C. In IT audit the audience for the report should normally be ignored

d)

D. None of the above

40.

40. In case of outsourcing IT activities the IT auditor should

a)

A. Review the policies and procedures which ensure the security of the financial data

b)

B. Obtain a copy of the contract to determine if adequate controls have been

c)

C. Ensure that audit needs are taken into account and included in the contracts specified

d)

D. All of the above

41.

41. What is the characteristic of 'detective control'

a)

A. Minimise the impact of a threat

b)

B. Use controls that detect and report the occurrence of an error, omission or malicious act.

c)

C. Detect problems before they occur

d)

D. None of the above

42.

42. Which one is not a continuous audit technique

a)

A. Continuous ans intermittent simulation

b)

B. SCRAF

c)

C. Cobit

d)

D. Snapshot

43.

43. Which among the following is true as to Audit Reporting

a)

A. Normal reporting format is not adhered to in the case of IT Andit

b)

B. In IT audit, the base of the focus is the system

c)

C. In IT audit the audience for the report should normally be ignored

d)

D. None of the above

44.

44. The conclusions of the IT audit report does not include

a)

A. Sweeping conclusions regarding absence of controls and risks

b)

B. A mismatch between hardware procurement and software development in the absence of IT policy

c)

C. Haphazard development which cannot be ascribed to lack of IT policy

d)

D. All of the above

45.

45. With the help of what tools, IT auditor can plan for 100% substantive testing

a)

A. CAATS tools

b)

B. CMM (Software)

c)

C. COBIT

d)

D. None of the above

46.

46. The reason for management's failure to use information properly is

a)

A. Failure to identify significant information

b)

B. Failure to interpret the meaning and value of the acquired information

c)

C. Failure to communicate information to the decision maker

d)

D. All of the above

47.

47. Find out the incorrect statement

a)

A. Distributed networks may decrease the risk of data inconsistencies

b)

B. Application software developed inhouse may have lower inherent risk than vendor supplied software

c)

C. Peripheral access devices or system interfaces can increase inherent risk

d)

D. None of the above

48.

48. Categories of general control do not include

a)

A. Logical access controls

b)

B. Acquisition and program change controls

c)

C. Control over standing data and master files

d)

D. None of the above

49.

49. Application controls includes

a)

A. IT operational controls

b)

B. Control over processing

c)

C. Physical controls

d)

D. None of the above

50.

50. What legal protection is available to prevent theft illegal copying of software

a)

A. Computer misuse legislation

b)

B. Data protection and privacy legislation

c)

C. Copyright laws

d)

D. None of the above