wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

MSTIP - IT audit and control - Midterm Exam

Total questions: 55

Worksheet time: 55mins

Name
Class
Date
1.

Statement 1: Spreadsheets or database software may be used as an audit planning tool to develop an audit universe.


Statement 2: Spreadsheets or database software may also be used for risk assessment and preparation of audit schedules.

a)

Statement 1 is correct.

b)

Statement 2 is correct.

c)

Both statements are correct.

d)

Both statements are incorrect.

2.

Statement 1: Data sharing and communication of audit procedures and results between auditors of the same team are made possible with the use of word processing, spreadsheet and presentation tools, among others.


Statement 2: Electronic connectivity not only allows auditors to communicate but also provides access for audit clients to exchange information.

a)

Statement 1 is correct.

b)

Statement 2 is correct.

c)

Both statements are correct.

d)

Both statements are incorrect.

3.

Statement 1: An advantage of having a central data repository for auditors is that it enables the saving and availability of past audit planning and documentation procedures such as risk assessment, audit schedules and budget data.


Statement 2: Database applications allows consolidation of data that can be used for future decision making by top management, for example analysis of audit budget vs actual, trend reports, etc.

a)

Statement 1 is correct.

b)

Statement 2 is correct.

c)

Both statements are correct.

d)

Both statements are incorrect.

4.

Use of generalized audit software makes it possible to perform required functions directly on application files. Audit softwares can be used to:


1. Analyze and compare files

2. Conduct random samples

3. Prepare confirmation letters

4. Validation computations

5. Select specific records for examination

a)

1,2,3 and 4

b)

1,2,3 and 5

c)

1,3,4, and 5

d)

2,3,4 and 5

e)

1,2,3, 4 and 5

5.

Statement 1: Information systems auditor cannot help determine compliance with a particular procedure for operational and financial auditors.


Statement 2: When an information systems auditor reviews the spreadsheets to understand the flow of a process and whether it provides a correct output from the input, (s)he needs to check the accuracy of formulas used.

a)

Statement 1 is correct.

b)

Statement 2 is correct.

c)

Both statements are correct.

d)

Both statements are incorrect.

6.

Auditors use spreadsheets for analyzing data and forming opinions. Spreadsheets are even used or relied on by management for decision making. Which is not a risk that is associated with poor spreadsheet design?

a)

Lack of reliability

b)

Lack of auditability

c)

Lack of modifiability

d)

Lack of users

7.

This is a built-in test environment within a system that allows testing of the process for accuracy or reliability.

a)

Integrated test facility

b)

Parallel simulation

c)

Transaction tagging

d)

Test data

8.

The following are problem areas in a processing cycle that an audit staff needs to identify:


1. Redundant processing of data

2. Bottlenecks that delay processing

3. Points in the operating cycle where there is lack of review of output reports

a)

1, 2 and 3

b)

1 and 2 only

c)

1 and 3 only

d)

2 and 3 only

9.

The following is an example of a career path for an IT auditor. Find the correct sequence.


1. Senior IT auditor

2. IT audit manager

3. Director of IT audit

4. IT audit staff

5. IT audit trainee

a)

5,4,2,1,3

b)

4,5,2,1,3

c)

5,4,1,3,2

d)

5,4,1,2,3

e)

4,5,1,2,3

10.

This refers to all training, certification and education that a worker needs to succeed in his or her career.

a)

Counseling and feedback

b)

Performance assessment

c)

Training

d)

Career path planning

e)

Professional development

11.

Which is not true about evaluating IT audit performance?

a)

Evaluating IT audits is an on-going process to ensure audit quality.

b)

In evaluating audit performance, the managers must be concerned with high scores or high performance.

c)

On the basis of evaluation, managers should develop training plans to improve the IT audit methodologies.

d)

There should be conducted a training for the staff in proper use of audit techniques and tools.

12.

____________ is an integral part of the audit function because it supports the auditor’s judgment on the quality of computer system.

a)

Internal audit

b)

Compliance audit

c)

Financial audit

d)

IT audit

e)

External audit

13.

The following are types of IT audits.


1. Organizational IT audit

2. Technical IT audit

3. Application IT audit

4. Compliance IT audit

a)

1,2,3,4

b)

1,2,3

c)

2,3,4

d)

1,3,4

e)

1,2,4

14.

____________ is defined as information integrity, the level of confidence and trust that can be placed on the information, and service availability.

a)

Information system audit

b)

Information assurance

c)

Information security

d)

IT infrastructure

15.

If CPA is for accountancy graduates, what is the certification applicable to IT auditors?

a)

CIA

b)

CISA

c)

CFE

d)

CMA

16.

This is an area of work or career opportunity where the focus of work is on advising organizations on how to best use information technology in achieving their business objectives.

a)

Public accounting

b)

Private industry

c)

Management consultancy

d)

Academe

17.

Effective IT governance can improve organizational performance by


1. Ensuring decisions and investments are aligned with organizational objectives

2. Establishing a framework for managing IT to deliver value to the organization

3. Ensuring adequate internal controls and regulatory compliance

a)

1,2, and 3

b)

1 and 2 only

c)

1 and 3 only

d)

2 and 3 only

18.

The Board and senior management should be reminded of the value of IT. And that whenever a business process is automated, the effect to the organization is

a)

Higher IT costs, higher business costs

b)

Higher IT costs, higher revenue

c)

Lower IT costs, higher revenue

d)

Lower IT costs, lower business costs

19.

This provides an overall picture of IT performance aligned to the objectives of the organization. Its is developed by listing the objectives of IT and establishing measurements that track performance against objectives.

a)

Enterprise risk management

b)

Corporate governance

c)

Balance scorecard

d)

Metric management

20.

IT governance is a relatively new subset of corporate governance that focuses on the management and assessment of strategic IT resources. The key objectives of IT governance are to reduce risk and ensure that investments in IT resources add value to the organization.

a)

True

b)

False

21.

Identify the missing words in the following sentence. The purpose of the [?] is to ensure that the organization continually co-creates value with all stakeholders in line with the organization's objectives.

a)

‘Focus on value’ guiding principle

b)

Four dimensions of service management

c)

Service value system

d)

‘Service request management’ practice

22.

Which guiding principle describes the importance of doing something, instead of spending a long time analyzing different options?

a)

Optimize and automate

b)

Start where you are

c)

Focus on value

d)

Progress iteratively with feedback

23.

Which guiding principle is PRIMARILY concerned with consumer's revenue and growth?

a)

Progress iteratively with feedback

b)

Optimize and automate

c)

Keep it simple and practical

d)

Focus on value

24.

Which value chain activity ensures people understand the organization's vision?

a)

Improve

b)

Plan

c)

Deliver and support

d)

Obtain/Build

25.

Which value chain activity includes presenting workarounds to users via a service portal?

a)

Plan

b)

Improve

c)

Engage

d)

Obtain/Build

26.

Which value chain activity communicates the current status of all four dimensions of service management?

a)

Engage

b)

Improve

c)

Obtain/build

d)

Plan

27.

Which guiding principle emphasizes the need to understand the flow of work in progress, identify bottlenecks, and uncover waste?

a)

Focus on value

b)

Collaborate and promote visibility

c)

Think and work holistically

d)

Keep it simple and practical

28.

What is the starting point for optimization?

a)

Securing stakeholder engagement

b)

Understanding the vision and objectives of the organization

c)

Determining where the most positive impact would be

d)

Standardizing practices and services

29.

Governance is the means by which an organization accomplishes two specific goals. One is to direct the organization. According to ITIL 4, what is the second objective of governance?

a)

Optimization

b)

Orchestration

c)

Automation

d)

Control

30.

According to ITIL 4, using the SVS, what do all components and activities of the organization specifically work together to co-create?

a)

Value

b)

Customer retention

c)

Profit

d)

Growth

31.

Which component is specifically a value output of the service value system?

a)

New markets pursued

b)

Reduced efficiency

c)

Resistance to change

d)

Increased costs and risks

32.

Which term describes sets of organizational resources designed for performing work or accomplishing an objective?

a)

Principles

b)

Governance

c)

Practices

d)

Opportunities

33.

Which ITIL concept describes governance

a)

The seven guiding principles

b)

The four dimensions of service management

c)

The service value chain

d)

The service value system

34.

Which describes the nature of the guiding principles?

a)

A guiding principle can guide an organization in all circumstances

b)

Each guiding principle mandates specific actions and decisions

c)

An organization will select one of the principles to adopt

d)

Guiding principles describe the processes that all organizations must adopt

35.

Which is a key consideration for the guiding principle 'keep it simple and practical'?

a)

Try to create a solution for every exception

b)

Understand how each element contributes to value creation

c)

Ignore conflicting objectives of different stakeholders

d)

Start with a complex solution, then simplify

36.

1.Which of the following best describes COBIT?

a)

A.COBIT is a framework for the governance and management of enterprise information and technology.

b)

A.COBIT is a full description of the whole IT environment of an enterprise.

c)

A.COBIT is a framework to organize business processes.

37.

2. What is the primary difference between Governance System Principles and Governance Framework Principles?

a)

Governance System Principles focus on stakeholder needs while Governance Framework Principles focus on Information and Technology (I&T) needs.

b)

Governance System Principles and Governance Framework Principles are the same thing in COBIT 2019.

c)

Governance System Principles describe the core requirements for a governance system while Governance Framework Principles focus on building that governance system.

38.

3. “A governance system should be customized to the enterprise’s needs, using a set of design factors as parameters to customize and prioritize the governance system components” is an example of which Governance System Principle?

a)

Tailored to enterprise needs

b)

Open and flexible

c)

Goals cascade

39.

4. A governance or management objective always relates to _____ and a series of related components of other types to help achieve the objective.

a)

compliance requirements

b)

one process

c)

one governance framework principle

40.

5. Which of the following is NOT a component of the governance system?

a)

Enterprise size

b)

Organizational structures

c)

Information

41.

6. ______________ are factors that can influence the design of an enterprise’s governance system and position it for success in the use of I&T.

a)

Components of the governance system

b)

Alignment goals

c)

Design factors

42.

7. Which of the following is a design factor for a governance system that supports prioritization of management objectives based on prioritization of enterprise goals?

a)

Balanced scorecard

b)

Holistic approach

c)

Risk Profile

43.

8. Governance ________ are factors that, individually and collectively, contribute to the good operations of the enterprise’s governance system over I&T and were known as enablers in COBIT 5.

a)

components

b)

goals

c)

practices

44.

9. Which two levels of involvement does COBIT 2019 identify within the updated RACI chart?

a)

Consulted and informed

b)

Responsible and accountable

c)

Ownership and delegated

45.

10. Which Governance or Management Objective has the following purpose statement?

“Realize defined project outcomes and reduce the risk of unexpected delays, costs and value erosion by improving communications to and involvement of business and end users. Ensure the value and quality of project deliverables and maximize their contribution to the defined programs and investment portfolio.”

a)

BAI11 Managed Projects

b)

BAI02 Managed Requirements Definition

c)

APO09 Managed Service Agreements

46.

What is risk identification?

a)

The process of identifying and documenting potential risks that could affect a project or organization.

b)

The process of transferring risks to another party.

c)

The process of ignoring potential risks and focusing only on current issues.

d)

The process of mitigating risks that have already occurred.

47.

Why is risk identification important in risk management?

a)

To increase the likelihood of project success.

b)

To identify potential risks and hazards that may affect a project or organization.

c)

To ignore potential risks and hazards that may affect a project or organization.

d)

To save time and resources in risk management activities.

48.

What are the common methods used for risk identification?

a)

probability analysis, risk mapping, expert judgment

b)

root cause analysis, risk matrix, scenario analysis

c)

delphi technique, fault tree analysis, sensitivity analysis

d)

brainstorming, checklists, interviews, and SWOT analysis

49.

What is the purpose of risk identification?

a)

To ignore potential risks.

b)

To eliminate all risks.

c)

To identify and assess potential risks.

d)

To transfer all risks to another party.

50.

What are the key steps involved in risk identification?

a)

Identify potential risks, analyze and assess the risks, prioritize the risks, and document the risks.

b)

Identify potential risks, analyze and assess the rewards, prioritize the risks, and document the risks.

c)

Identify potential rewards, analyze and assess the risks, prioritize the risks, and document the risks.

d)

Identify potential risks, analyze and assess the risks, prioritize the rewards, and document the risks.

51.

What are the benefits of conducting risk identification?

a)

Decreased project success, lack of stakeholder engagement, and ineffective decision-making.

b)

Limited project scope, reduced team collaboration, and increased project risks.

c)

Increased project costs, delayed timelines, and decreased stakeholder satisfaction.

d)

The benefits of conducting risk identification include proactive planning, mitigation strategies, improved decision-making, resource allocation, and project success.

52.

What are the challenges faced during the risk identification process?

a)

Lack of data, subjective judgments, incomplete information, and biases.

b)

Lack of expertise, time constraints, lack of stakeholder involvement, and conflicting priorities.

c)

Limited resources, lack of communication, lack of risk awareness, and resistance to change.

d)

Inconsistent risk assessment criteria, lack of risk management framework, lack of risk identification tools, and poor risk reporting.

53.

How can risk identification help in decision-making?

a)

By ignoring potential risks and blindly choosing a course of action.

b)

By wasting time and resources on unnecessary analysis.

c)

By increasing the likelihood of making the wrong decision.

d)

By identifying potential risks and uncertainties associated with different options or courses of action.

54.

What are the limitations of risk identification?

a)

Overemphasis on certain risks, failure to consider external factors, lack of risk management framework

b)

Ineffective communication, resistance to change, lack of stakeholder involvement

c)

Limited knowledge or experience, biases and assumptions, lack of data or information, time constraints, and difficulty in predicting future events.

d)

Lack of resources, conflicting priorities, inadequate tools or techniques

55.

What are some examples of risks that can be identified in a business environment?

a)

market risks

b)

cybersecurity risks

c)

human resources risks

d)

financial risks, operational risks, strategic risks, compliance risks, and reputational risks