NEW
Font size
WorksheetsMSTIP - IT audit and control - Midterm Exam
Total questions: 55
Worksheet time: 55mins
Statement 1: Spreadsheets or database software may be used as an audit planning tool to develop an audit universe.
Statement 2: Spreadsheets or database software may also be used for risk assessment and preparation of audit schedules.
Statement 1 is correct.
Statement 2 is correct.
Both statements are correct.
Both statements are incorrect.
Statement 1: Data sharing and communication of audit procedures and results between auditors of the same team are made possible with the use of word processing, spreadsheet and presentation tools, among others.
Statement 2: Electronic connectivity not only allows auditors to communicate but also provides access for audit clients to exchange information.
Statement 1 is correct.
Statement 2 is correct.
Both statements are correct.
Both statements are incorrect.
Statement 1: An advantage of having a central data repository for auditors is that it enables the saving and availability of past audit planning and documentation procedures such as risk assessment, audit schedules and budget data.
Statement 2: Database applications allows consolidation of data that can be used for future decision making by top management, for example analysis of audit budget vs actual, trend reports, etc.
Statement 1 is correct.
Statement 2 is correct.
Both statements are correct.
Both statements are incorrect.
Use of generalized audit software makes it possible to perform required functions directly on application files. Audit softwares can be used to:
1. Analyze and compare files
2. Conduct random samples
3. Prepare confirmation letters
4. Validation computations
5. Select specific records for examination
1,2,3 and 4
1,2,3 and 5
1,3,4, and 5
2,3,4 and 5
1,2,3, 4 and 5
Statement 1: Information systems auditor cannot help determine compliance with a particular procedure for operational and financial auditors.
Statement 2: When an information systems auditor reviews the spreadsheets to understand the flow of a process and whether it provides a correct output from the input, (s)he needs to check the accuracy of formulas used.
Statement 1 is correct.
Statement 2 is correct.
Both statements are correct.
Both statements are incorrect.
Auditors use spreadsheets for analyzing data and forming opinions. Spreadsheets are even used or relied on by management for decision making. Which is not a risk that is associated with poor spreadsheet design?
Lack of reliability
Lack of auditability
Lack of modifiability
Lack of users
This is a built-in test environment within a system that allows testing of the process for accuracy or reliability.
Integrated test facility
Parallel simulation
Transaction tagging
Test data
The following are problem areas in a processing cycle that an audit staff needs to identify:
1. Redundant processing of data
2. Bottlenecks that delay processing
3. Points in the operating cycle where there is lack of review of output reports
1, 2 and 3
1 and 2 only
1 and 3 only
2 and 3 only
The following is an example of a career path for an IT auditor. Find the correct sequence.
1. Senior IT auditor
2. IT audit manager
3. Director of IT audit
4. IT audit staff
5. IT audit trainee
5,4,2,1,3
4,5,2,1,3
5,4,1,3,2
5,4,1,2,3
4,5,1,2,3
This refers to all training, certification and education that a worker needs to succeed in his or her career.
Counseling and feedback
Performance assessment
Training
Career path planning
Professional development
Which is not true about evaluating IT audit performance?
Evaluating IT audits is an on-going process to ensure audit quality.
In evaluating audit performance, the managers must be concerned with high scores or high performance.
On the basis of evaluation, managers should develop training plans to improve the IT audit methodologies.
There should be conducted a training for the staff in proper use of audit techniques and tools.
____________ is an integral part of the audit function because it supports the auditor’s judgment on the quality of computer system.
Internal audit
Compliance audit
Financial audit
IT audit
External audit
The following are types of IT audits.
1. Organizational IT audit
2. Technical IT audit
3. Application IT audit
4. Compliance IT audit
1,2,3,4
1,2,3
2,3,4
1,3,4
1,2,4
____________ is defined as information integrity, the level of confidence and trust that can be placed on the information, and service availability.
Information system audit
Information assurance
Information security
IT infrastructure
If CPA is for accountancy graduates, what is the certification applicable to IT auditors?
CIA
CISA
CFE
CMA
This is an area of work or career opportunity where the focus of work is on advising organizations on how to best use information technology in achieving their business objectives.
Public accounting
Private industry
Management consultancy
Academe
Effective IT governance can improve organizational performance by
1. Ensuring decisions and investments are aligned with organizational objectives
2. Establishing a framework for managing IT to deliver value to the organization
3. Ensuring adequate internal controls and regulatory compliance
1,2, and 3
1 and 2 only
1 and 3 only
2 and 3 only
The Board and senior management should be reminded of the value of IT. And that whenever a business process is automated, the effect to the organization is
Higher IT costs, higher business costs
Higher IT costs, higher revenue
Lower IT costs, higher revenue
Lower IT costs, lower business costs
This provides an overall picture of IT performance aligned to the objectives of the organization. Its is developed by listing the objectives of IT and establishing measurements that track performance against objectives.
Enterprise risk management
Corporate governance
Balance scorecard
Metric management
IT governance is a relatively new subset of corporate governance that focuses on the management and assessment of strategic IT resources. The key objectives of IT governance are to reduce risk and ensure that investments in IT resources add value to the organization.
True
False
Identify the missing words in the following sentence. The purpose of the [?] is to ensure that the organization continually co-creates value with all stakeholders in line with the organization's objectives.
‘Focus on value’ guiding principle
Four dimensions of service management
Service value system
‘Service request management’ practice
Which guiding principle describes the importance of doing something, instead of spending a long time analyzing different options?
Optimize and automate
Start where you are
Focus on value
Progress iteratively with feedback
Which guiding principle is PRIMARILY concerned with consumer's revenue and growth?
Progress iteratively with feedback
Optimize and automate
Keep it simple and practical
Focus on value
Which value chain activity ensures people understand the organization's vision?
Improve
Plan
Deliver and support
Obtain/Build
Which value chain activity includes presenting workarounds to users via a service portal?
Plan
Improve
Engage
Obtain/Build
Which value chain activity communicates the current status of all four dimensions of service management?
Engage
Improve
Obtain/build
Plan
Which guiding principle emphasizes the need to understand the flow of work in progress, identify bottlenecks, and uncover waste?
Focus on value
Collaborate and promote visibility
Think and work holistically
Keep it simple and practical
What is the starting point for optimization?
Securing stakeholder engagement
Understanding the vision and objectives of the organization
Determining where the most positive impact would be
Standardizing practices and services
Governance is the means by which an organization accomplishes two specific goals. One is to direct the organization. According to ITIL 4, what is the second objective of governance?
Optimization
Orchestration
Automation
Control
According to ITIL 4, using the SVS, what do all components and activities of the organization specifically work together to co-create?
Value
Customer retention
Profit
Growth
Which component is specifically a value output of the service value system?
New markets pursued
Reduced efficiency
Resistance to change
Increased costs and risks
Which term describes sets of organizational resources designed for performing work or accomplishing an objective?
Principles
Governance
Practices
Opportunities
Which ITIL concept describes governance
The seven guiding principles
The four dimensions of service management
The service value chain
The service value system
Which describes the nature of the guiding principles?
A guiding principle can guide an organization in all circumstances
Each guiding principle mandates specific actions and decisions
An organization will select one of the principles to adopt
Guiding principles describe the processes that all organizations must adopt
Which is a key consideration for the guiding principle 'keep it simple and practical'?
Try to create a solution for every exception
Understand how each element contributes to value creation
Ignore conflicting objectives of different stakeholders
Start with a complex solution, then simplify
1.Which of the following best describes COBIT?
A.COBIT is a framework for the governance and management of enterprise information and technology.
A.COBIT is a full description of the whole IT environment of an enterprise.
A.COBIT is a framework to organize business processes.
2. What is the primary difference between Governance System Principles and Governance Framework Principles?
Governance System Principles focus on stakeholder needs while Governance Framework Principles focus on Information and Technology (I&T) needs.
Governance System Principles and Governance Framework Principles are the same thing in COBIT 2019.
Governance System Principles describe the core requirements for a governance system while Governance Framework Principles focus on building that governance system.
3. “A governance system should be customized to the enterprise’s needs, using a set of design factors as parameters to customize and prioritize the governance system components” is an example of which Governance System Principle?
Tailored to enterprise needs
Open and flexible
Goals cascade
4. A governance or management objective always relates to _____ and a series of related components of other types to help achieve the objective.
compliance requirements
one process
one governance framework principle
5. Which of the following is NOT a component of the governance system?
Enterprise size
Organizational structures
Information
6. ______________ are factors that can influence the design of an enterprise’s governance system and position it for success in the use of I&T.
Components of the governance system
Alignment goals
Design factors
7. Which of the following is a design factor for a governance system that supports prioritization of management objectives based on prioritization of enterprise goals?
Balanced scorecard
Holistic approach
Risk Profile
8. Governance ________ are factors that, individually and collectively, contribute to the good operations of the enterprise’s governance system over I&T and were known as enablers in COBIT 5.
components
goals
practices
9. Which two levels of involvement does COBIT 2019 identify within the updated RACI chart?
Consulted and informed
Responsible and accountable
Ownership and delegated
10. Which Governance or Management Objective has the following purpose statement?
“Realize defined project outcomes and reduce the risk of unexpected delays, costs and value erosion by improving communications to and involvement of business and end users. Ensure the value and quality of project deliverables and maximize their contribution to the defined programs and investment portfolio.”
BAI11 Managed Projects
BAI02 Managed Requirements Definition
APO09 Managed Service Agreements
What is risk identification?
The process of identifying and documenting potential risks that could affect a project or organization.
The process of transferring risks to another party.
The process of ignoring potential risks and focusing only on current issues.
The process of mitigating risks that have already occurred.
Why is risk identification important in risk management?
To increase the likelihood of project success.
To identify potential risks and hazards that may affect a project or organization.
To ignore potential risks and hazards that may affect a project or organization.
To save time and resources in risk management activities.
What are the common methods used for risk identification?
probability analysis, risk mapping, expert judgment
root cause analysis, risk matrix, scenario analysis
delphi technique, fault tree analysis, sensitivity analysis
brainstorming, checklists, interviews, and SWOT analysis
What is the purpose of risk identification?
To ignore potential risks.
To eliminate all risks.
To identify and assess potential risks.
To transfer all risks to another party.
What are the key steps involved in risk identification?
Identify potential risks, analyze and assess the risks, prioritize the risks, and document the risks.
Identify potential risks, analyze and assess the rewards, prioritize the risks, and document the risks.
Identify potential rewards, analyze and assess the risks, prioritize the risks, and document the risks.
Identify potential risks, analyze and assess the risks, prioritize the rewards, and document the risks.
What are the benefits of conducting risk identification?
Decreased project success, lack of stakeholder engagement, and ineffective decision-making.
Limited project scope, reduced team collaboration, and increased project risks.
Increased project costs, delayed timelines, and decreased stakeholder satisfaction.
The benefits of conducting risk identification include proactive planning, mitigation strategies, improved decision-making, resource allocation, and project success.
What are the challenges faced during the risk identification process?
Lack of data, subjective judgments, incomplete information, and biases.
Lack of expertise, time constraints, lack of stakeholder involvement, and conflicting priorities.
Limited resources, lack of communication, lack of risk awareness, and resistance to change.
Inconsistent risk assessment criteria, lack of risk management framework, lack of risk identification tools, and poor risk reporting.
How can risk identification help in decision-making?
By ignoring potential risks and blindly choosing a course of action.
By wasting time and resources on unnecessary analysis.
By increasing the likelihood of making the wrong decision.
By identifying potential risks and uncertainties associated with different options or courses of action.
What are the limitations of risk identification?
Overemphasis on certain risks, failure to consider external factors, lack of risk management framework
Ineffective communication, resistance to change, lack of stakeholder involvement
Limited knowledge or experience, biases and assumptions, lack of data or information, time constraints, and difficulty in predicting future events.
Lack of resources, conflicting priorities, inadequate tools or techniques
What are some examples of risks that can be identified in a business environment?
market risks
cybersecurity risks
human resources risks
financial risks, operational risks, strategic risks, compliance risks, and reputational risks
