NEW
Font size
WorksheetsEntplan Mastery Drill
Total questions: 60
Worksheet time: 30mins
S1: Firewalls can protect company data and software programs.
S2: Programmers should have access to transaction data.
False, True
True, True
True, False
False, False
Computer systems are typically supported by a variety of utility software packages that are important to an auditor because they
Are written specifically to enable auditors to extract and sort data.
May enable unauthorized changes to data files if not properly controlled.
Are very versatile programs that can be used on hardware of many manufacturers.
May be significant components of a client’s application programs.
An example of an internal control weakness is to assign to a department supervisor the responsibility for
distributing payroll checks to subordinate employees
authorizing payroll checks for terminated employees
reviewing and approving time reports for subordinate employees
initiating request for salary adjustments for subordinate employees
Which of the following statements related to application controls is correct?
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
Application controls relate to the processing of individual transactions.
Application controls relate to all aspects of the IT function.
To obtain evidence that user identification and password controls are functioning as designed, an auditor would most likely
Write a computer program that simulates the logic of the client’s access control software.
Attempt to sign-on to the system using invalid user identifications and passwords.
Examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
Extract a random sample of processed transactions were appropriately authorized.
To obtain evidence that online access controls are properly functioning, an auditor most likely would
Vouch a random sample of processed transactions to assure proper authorization.
Examine the transaction log to discover whether any transactions were lost or entered twice due to a system malfunction.
Enter invalid identification numbers or passwords to ascertain whether the system rejects them.
Create checkpoints at periodic intervals after live data processing to test for unauthorized use of the system.
An auditor most likely would test for the presence of unauthorized computer program changes by running a
Source code comparison program.
Program with test data.
Check digit verification program.
Program that computes control totals.
Which of the following is not among the errors that an auditor might include in the test data when auditing a client’s computer system?
Differences in description of units of measure.
Illogical entries in fields whose logic is tested by programmed consistency checks.
Authorized code.
Numeric characters in alphanumeric fields.
Which of the following would be least likely to be included in an auditor's tests of controls?
inquiry
inspection
observation
confirmation
Talaga Sharmaine Co. uses an online sales order processing system to process its sales transactions. Talaga Sharmaine's sales data are electronically sorted and subjected to edit checks. A direct output of the edit checks most likely would be a
File of all rejected sales transactions.
List of all voided shipping documents.
Report of all missing sales invoices.
Printout of all user code numbers and passwords.
A flowchart is most frequently used by an auditor in connection with the
Performance of analytical procedures of account balances.
Preparation of generalized computer audit plans.
Use of statistical sampling in performing an audit.
Review of the client’s internal control.
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses a computer system is that the auditor may
Access information stored on computer files while having a limited understanding of the client’s hardware and software features.
Consider increasing the use of substantive tests of transactions in place of analytical procedures
Reduce the level of required tests of controls to a relatively small amount.
Substantiate the accuracy of data through self checking digits and hash totals.
Which of the following statements related to application controls is correct?
Application controls relate to all aspects of the IT function.
Application controls relate to the processing of individual transactions.
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
Auditors usually obtain information about general and application controls through:
interviews with IT personnel.
reading program change requests.
examination of systems documentation.
all of the methods.
A weakness in internal control over according retirement of equipment may cause an auditor to
selects certain items of equipment from the accounting records and locate them in the plan
inspects certain items of equipment in the plant and trace those items to the accounting records
reviews the subsidiary ledger to ascertain whether depreciation was taken on each item of equipment during the year
trace additions to the other assets account to search for equipment that is still on hand but no longer being used
An auditor anticipates assessing control risk at a low level in a computerized environment. Under these circumstances, on which of the following activities would the auditor initially focus?
Programmed control activities.
Output control activities.
Application control activities.
General control activities.
Which of the following computer-assisted auditing techniques processes client input data on a controlled program under the auditor’s control to test controls in the computer system?
Parallel simulation.
Review of program logic.
Test data.
Integrated test facility.
In a properly designed internal control system, the same employee most likely would much vendor’s invoices with receiving reports and also
canceled vendor’s invoices after payment
posts the detailed accounts payable records
reconciles the accounts payable ledger
compute the calculations and vendors' invoices
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses an EDP system is that the auditor may:
Consider increasing the use of substantive tests of transactions in place of analytical procedures.
Reduce the level of required tests of controls to a relatively small amount.
Access information stored on computer files while having a limited understanding of the client's hardware and software features.
Substantiate the accuracy of data through self-checking digits and hash totals.
Which of the following client information technology (IT) systems generally can be audited without examining or directly testing the IT computer programs of the system?
A system that performs relatively complicated processing and produces very little detailed output.
A system that updates a few essential master files and produces no printed output other than final balances.
A system that affects a number of essential master files and produces a limited output.
A system that performs relatively uncomplicated processes and produces detailed output.
A control that relates to all parts of the IT system is called a(n):
applications control.
universal control.
systems control.
general control
Auditors often make use of computer programs that perform routine processing functions such as sorting and merging. These programs are made available by electronic data processing companies and others and are specifically referred to as
User programs.
Compiler programs.
Utility programs.
Supervisory programs.
An auditor who is testing EDP controls in a payroll system would most likely use test data that contain conditions such as
Overtime not approved by supervisors.
Payroll checks with unauthorized signatures.
Deductions not authorized by employees.
Time tickets with invalid job numbers.
An auditor who wishes to capture an entity’s data as transactions are processed and continuously test the entity’s computerized information system most likely would use which of the following techniques?
Integrated data check.
Snapshot application.
Embedded audit module.
Test data generator.
In creating lead schedules for an audit engagement, a CPA often uses automated workpaper software. What client information is needed to begin this process?
General ledger information such as account numbers, prior year account balances, and current year unadjusted information.
Interim financial information such as third quarter sales, net income, and inventory and receivables balances.
Adjusting entry information such as deferrals and accruals, and reclassification journal entries.
Specialized journal information such as the invoice and purchase order numbers of the last few sales and purchases of the year.
Controls which are designed to assure that the information processed by the computer is authorized, complete, and accurate are called:
output controls.
input controls.
processing controls.
general controls.
______ controls prevent and detect errors while transaction data are processed.
Processing
Transaction
Software
Application
To determine that user ID and password controls are functioning, an auditor would most likely:
examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
write a computer program that simulates the logic of the client’s access control software.
attempt to sign on to the system using invalid user identifications and passwords.
extract a random sample of processed transactions and ensure that the transactions were appropriately authorized
Which of the following is not a benefit of using IT-based controls?
Over-reliance on computer-generated reports.
Reduction in misstatements due to consistent processing of transactions.
Ability to process large volumes of transactions.
Ability to replace manual controls with computer-based controls.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
Test data must consist of all possible valid and invalid conditions.
Test data are processed by the client’s computer programs under the auditor’s control.
Several transactions of each type must be tested
The program tested is different from the program used throughout the year by the client.
IS Auditor identified certain threats and vulnerabilities in a business process. Next, an IS auditor should:
discloses the threats and impacts to management.
identifies information assets and the underlying systems.
identify stakeholder for that business process.
identifies and evaluates the existing controls.
Overall business risk for a particular threat can be expressed as:
magnitude of impact.
assumption of the risk assessment team.
probability of occurrence.
a product of the probability and impact.
Overall business risk for a particular threat can be expressed as:
assumption of the risk assessment team.
probability of occurrence.
a product of the probability and impact.
magnitude of impact
The result of risk management process is used for:
user acceptance testing.
post implementation review.
forecasting profit
designing controls
The decisions and actions of an IS auditor are MOST likely to affect which of the following risks?
Inherent
Business
Detection
Control
The approach an IS auditor should use to plan IS audit coverage should be based on:
sufficiency of audit evidence.
risk.
fraud monitoring.
materiality.
Most important step in a risk analysis is to identify:
competitors.
vulnerabilities.
liabilities.
controls.
In a small organization where segregation of duties (SoD) is not practical, an employee performs the function of computer operator and
application programmer. Which of the following controls should the IS auditor recommend?
Access controls to prevent the operator from making program modifications
Procedures that verify that only approved program changes are implemented
Automated logging of changes to development libraries
Additional staff to provide SoD
What should the IS auditor do FIRST?
Perform an IT risk assessment.
Revise the audit plan to focus on risk-based auditing.
Perform a survey audit of logical access controls.
Begin testing controls that the IS auditor feels are most critical.
Absence of proper security measures represents a (n):
impact.
vulnerability.
asset.
threat.
Which of the following is MOST effective for implementing a control self-assessment within small business units?
Informal peer reviews
Data flow diagrams
Process flow narratives
Facilitated workshops
Risk assessment approach is more suitable when determining the appropriate level of protection for an information asset because it ensures:
appropriate levels of protection are applied to information assets.
only most sensitive information assets are protected.
a basic level of protection is applied regardless of asset value.
all information assets are protected.
Which of the following would an IS auditor perform FIRST when planning an IS audit?
Define audit deliverables.
Develop the audit approach or audit strategy.
Gain an understanding of the business’s objectives and purpose.
Finalize the audit scope and audit objectives.
An IS auditor should ensure that IT governance performance measures:
adhere to regulatory reporting standards and definitions.
evaluate the IT department.
provide strategic IT drivers.
evaluate the activities of IT oversight committees.
Risk can be mitigated by:
Contracts and service level agreements (SLAs)
Implementing controls
Insurance
Audit and certification
While determining the appropriate level of protection for an information asset an IS auditor should primarily focus on:
Owner of information asset.
Result of vulnerability assessment.
Cost of information asset.
Criticality of information asset.
Evaluation of IT risks can be done by:
Trend analysis on the basis of past year losses.
reviewing IT control weaknesses identified in audit reports.
industry benchmark.
finding threats/vulnerabilities associated with current IT assets.
The decisions and actions of an IS auditor are MOST likely to affect which of the following risks?
Detection
Inherent
Control
Business
An IS Auditor is reviewing data centre security review. Which of the following steps would an IS auditor normally perform FIRST:
Review screening process for hiring security staff
Evaluate logical access control.
Evaluate physical access control.
Determine the vulnerabilities/threats to the data centre site.
As compared to understanding an organization's IT process from evidence directly collected, how valuable are prior audit reports as evidence?
The same value.
Lesser value.
Greater value.
Prior audit reports are not relevant.
While determining the appropriate level of protection for an information asset an IS auditor should primarily focus on:
Owner of information asset.
Criticality of information asset.
Result of vulnerability assessment.
Cost of information asset.
Major advantage of risk-based approach for audit planning is:
Appropriate utilization of resources for high risk areas.
Use of latest technology for audit activities.
Audit planning can be communicated to client in advance.
Audit activity can be completed within allotted budget.
When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that:
all the relevant vulnerabilities and threats are identified.
regularity compliance is adhered to.
segregation of duties to mitigate risks is in place.
business is profitable.
Risk assessment process is:
subjective.
mathematical.
objective.
statistical.
IS Auditor is developing a risk management program, the FIRST activity to be performed is a(n):
vulnerability assessment.
identification of assets.
gap analysis.
evaluation of control.
An IS auditor is reviewing payroll application. He identified some vulnerability in the system. What would be the next task?
Identify threats and likelihood of occurrence.
Recommend for new application.
Examine application development process.
Report the vulnerabilities to the management immediately.
When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that:
segregation of duties to mitigate risks is in place.
all the relevant vulnerabilities and threats are identified.
business is profitable.
regularity compliance is adhered to.
The risk of an IS auditor certifying existence of proper system and procedures without using an inadequate test procedure is an example of:
inherent risk.
detection risk.
control risk.
audit risk.
Which of the following factors an IS auditor should primarily consider when determining the acceptable level of risk
Risk acceptance is the responsibility of senior management.
All risks do not need to be eliminated for a business to be profitable.
Line management should be involved in the risk analysis because management sees risks daily that others would not recognize.
Risks must be identified and documented in order to perform proper analysis on them.
In a risk-based audit planning, an IS auditor's first step is to identify:
profit centre.
cost centre.
responsibilities of stakeholders.
high-risk areas within the organization.
