Font size
S
M
L
XL
WorksheetsEntplan Finals
Total questions: 120
Worksheet time: 3hrs 0mins
Name
Class
Date
1.
Auditing by testing the input and output of a computer system instead of the computer program itself will
a)
Not provide the auditor with confidence in the results of the auditing procedures.
b)
Detect all program errors, regardless of the nature of the output.
c)
Provide the auditor with the same type of evidence as tests of application controls.
d)
Not detect program errors which do not show up in the output sampled.
2.
Which of the following statements related to application controls is correct?
a)
Application controls relate to the processing of individual transactions.
b)
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
c)
Application controls relate to all aspects of the IT function.
d)
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
3.
Which of the following is not among the errors that an auditor might include in the test data when auditing a client’s computer system?
a)
Numeric characters in alphanumeric fields.
b)
Differences in description of units of measure.
c)
Authorized code.
d)
Illogical entries in fields whose logic is tested by programmed consistency checks.
4.
Dalgona Corporation’s organization chart provides for a controller and an EDP manager, both of whom report to the financial vice-president. Internal control would not be strengthened by
a)
Providing for maintenance of input data controls by an independent control group which reports to the controller.
b)
Providing for review and distribution of computer output by an independent control group which reports to the controller.
c)
Assigning the programming and operating of the computer to an independent control group which reports to the controller.
d)
Rotating periodically among machine operators the assignments of individual application run.
5.
Controls which apply to a specific element of the system are called:
a)
user controls.
b)
applications controls.
c)
general controls.
d)
systems controls.
6.
An auditor anticipates assessing control risk at a low level in a computerized environment. Under these circumstances, on which of the following activities would the auditor initially focus?
a)
General control activities.
b)
Programmed control activities.
c)
Output control activities.
d)
Application control activities.
7.
A control that relates to all parts of the IT system is called a(n):
a)
universal control.
b)
general control.
c)
applications control.
d)
systems control.
8.
Talaga Sharmaine Co. uses an online sales order processing system to process its sales transactions. Talaga Sharmaine's sales data are electronically sorted and subjected to edit checks. A direct output of the edit checks most likely would be a
a)
File of all rejected sales transactions.
b)
Printout of all user code numbers and passwords.
c)
List of all voided shipping documents.
d)
Report of all missing sales invoices.
9.
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses an EDP system is that the auditor may:
a)
Access information stored on computer files while having a limited understanding of the client's hardware and software features.
b)
Consider increasing the use of substantive tests of transactions in place of analytical procedures.
c)
Reduce the level of required tests of controls to a relatively small amount.
d)
Substantiate the accuracy of data through self-checking digits and hash totals.
10.
Which of the following is not a benefit of using IT-based controls?
a)
Ability to replace manual controls with computer-based controls.
b)
Ability to process large volumes of transactions.
c)
Over-reliance on computer-generated reports.
d)
Reduction in misstatements due to consistent processing of transactions.
11.
An auditor who is testing EDP controls in a payroll system would most likely use test data that contain conditions such as
a)
Time tickets with invalid job numbers.
b)
Deductions not authorized by employees.
c)
Overtime not approved by supervisors.
d)
Payroll checks with unauthorized signatures.
12.
A weakness in internal control over according retirement of equipment may cause an auditor to
a)
reviews the subsidiary ledger to ascertain whether depreciation was taken on each item of equipment during the year
b)
inspects certain items of equipment in the plant and trace those items to the accounting records
c)
trace additions to the other assets account to search for equipment that is still on hand but no longer being used
d)
selects certain items of equipment from the accounting records and locate them in the plant
13.
To determine that user ID and password controls are functioning, an auditor would most likely:
a)
write a computer program that simulates the logic of the client’s access control software.
b)
extract a random sample of processed transactions and ensure that the transactions were appropriately authorized.
c)
attempt to sign on to the system using invalid user identifications and passwords.
d)
examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
14.
An auditor most likely would test for the presence of unauthorized computer program changes by running a
a)
Check digit verification program.
b)
Program that computes control totals.
c)
Source code comparison program.
d)
Program with test data.
15.
Auditors usually obtain information about general and application controls through:
a)
reading program change requests.
b)
all of the methods.
c)
examination of systems documentation.
d)
interviews with IT personnel.
16.
In a properly designed internal control system, the same employee most likely would much vendor’s invoices with receiving reports and also
a)
reconciles the accounts payable ledger
b)
compute the calculations and vendors' invoices
c)
posts the detailed accounts payable records
d)
canceled vendor’s invoices after payment
17.
Which of the following statements related to application controls is correct?
a)
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
b)
Application controls relate to all aspects of the IT function.
c)
Application controls relate to the processing of individual transactions.
d)
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
18.
In creating lead schedules for an audit engagement, a CPA often uses automated workpaper software. What client information is needed to begin this process?
a)
Specialized journal information such as the invoice and purchase order numbers of the last few sales and purchases of the year.
b)
General ledger information such as account numbers, prior year account balances, and current year unadjusted information.
c)
Interim financial information such as third quarter sales, net income, and inventory and receivables balances.
d)
Adjusting entry information such as deferrals and accruals, and reclassification journal entries.
19.
Using laptop computers in auditing may affect the methods used to review the work of staff assistants because
a)
Working paper documentation may not contain readily observable details of calculations.
b)
Supervisory personnel may not have an understanding of the capabilities and limitations of laptops.
c)
The generally accepted auditing standards may differ.
d)
Documenting the supervisory review may require assistance of consulting services personnel.
20.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
a)
The program tested is different from the program used throughout the year by the client.
b)
Several transactions of each type must be tested.
c)
Test data must consist of all possible valid and invalid conditions.
d)
Test data are processed by the client’s computer programs under the auditor’s control.
21.
S1: Firewalls can protect company data and software programs.
S2: Programmers should have access to transaction data.
a)
False, False
b)
True, True
c)
False, True
d)
True, False
22.
An auditor most likely would test for the presence of unauthorized EDP program changes by running a
a)
Source code comparison program.
b)
Check digit verification program.
c)
Program that computes control totals.
d)
Program with test data.
23.
Computer systems are typically supported by a variety of utility software packages that are important to an auditor because they
a)
Are very versatile programs that can be used on hardware of many manufacturers.
b)
Are written specifically to enable auditors to extract and sort data.
c)
May be significant components of a client’s application programs.
d)
May enable unauthorized changes to data files if not properly controlled.
24.
______ controls prevent and detect errors while transaction data are processed.
a)
Processing
b)
Software
c)
Transaction
d)
Application
25.
Controls which are designed to assure that the information processed by the computer is authorized, complete, and accurate are called:
a)
general controls.
b)
output controls.
c)
processing controls.
d)
input controls.
26.
Squid Game Corporation has just completely computerized its billing and accounts receivable recordkeeping. You want to make maximum use of the new computer in your audit of Squid Game Corporation. Which of the following audit techniques could not be performed through a computer program?
a)
Resolving differences reported by customers on confirmation requests.
b)
Examining sales invoices for completeness, consistency between different items, valid conditions and reasonable mounts.
c)
Selecting on a random number basis accounts to be confirmed.
d)
Tracing audited cash receipts to accounts receivable credits.
27.
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses a computer system is that the auditor may
a)
Substantiate the accuracy of data through self checking digits and hash totals.
b)
Reduce the level of required tests of controls to a relatively small amount.
c)
Consider increasing the use of substantive tests of transactions in place of analytical procedures.
d)
Access information stored on computer files while having a limited understanding of the client’s hardware and software features.
28.
Which of the following computer-assisted auditing techniques processes client input data on a controlled program under the auditor’s control to test controls in the computer system?
a)
Integrated test facility.
b)
Review of program logic.
c)
Test data.
d)
Parallel simulation.
29.
Which of the following client information technology (IT) systems generally can be audited without examining or directly testing the IT computer programs of the system?
a)
A system that updates a few essential master files and produces no printed output other than final balances.
b)
A system that performs relatively uncomplicated processes and produces detailed output.
c)
A system that performs relatively complicated processing and produces very little detailed output.
d)
A system that affects a number of essential master files and produces a limited output.
30.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
a)
Test data are processed by the client’s computer programs under the auditor’s control.
b)
Several transactions of each type must be tested.
c)
Test data must consist of all possible valid and invalid conditions.
d)
The program tested is different from the program used throughout the year by the client.
31.
S1: “Auditing around the computer” is acceptable only if the auditor has access to the client’s data in a machine-readable language.
S2: “Auditing around the computer” is most appropriate when the client has not maintained detailed output or source documents in a form readable by humans.
a)
True, True
b)
True, False
c)
False, False
d)
False, True
32.
System characteristics that may result from the nature of CIS processing include, except
a)
Lack of visible transaction trail.
b)
Absence of input documents.
c)
Lack of visible output.
d)
Difficulty of access to data and computer programs.
33.
A numerical field appended to an identification number that serves as an input control is a(n)
a)
Check digit.
b)
Hash total.
c)
Valid character test.
d)
Batch total.
34.
Controls which are designed to assure that the information processed by the computer is authorized, complete, and accurate are called:
a)
input controls.
b)
output controls.
c)
processing controls.
d)
general controls.
35.
Which of the following computer-assisted auditing techniques processes client input data on a controlled program under the auditor’s control to test controls in the computer system?
a)
Integrated test facility.
b)
Review of program logic.
c)
Test data.
d)
Parallel simulation.
36.
Which of the following is a category of general controls?
a)
Input controls.
b)
Processing controls.
c)
Physical and online security.
d)
Output controls.
37.
A flowchart is most frequently used by an auditor in connection with the
a)
Performance of analytical procedures of account balances.
b)
Use of statistical sampling in performing an audit.
c)
Review of the client’s internal control.
d)
Preparation of generalized computer audit plans.
38.
Auditing by testing the input and output of a computer system instead of the computer program itself will
a)
Not provide the auditor with confidence in the results of the auditing procedures.
b)
Provide the auditor with the same type of evidence as tests of application controls.
c)
Not detect program errors which do not show up in the output sampled.
d)
Detect all program errors, regardless of the nature of the output.
39.
A weakness in internal control over according retirement of equipment may cause an auditor to
a)
inspects certain items of equipment in the plant and trace those items to the accounting records
b)
selects certain items of equipment from the accounting records and locate them in the plant
c)
reviews the subsidiary ledger to ascertain whether depreciation was taken on each item of equipment during the year
d)
trace additions to the other assets account to search for equipment that is still on hand but no longer being used
40.
To obtain evidence that online access controls are properly functioning, an auditor most likely would
a)
Examine the transaction log to discover whether any transactions were lost or entered twice due to a system malfunction.
b)
Vouch a random sample of processed transactions to assure proper authorization.
c)
Enter invalid identification numbers or passwords to ascertain whether the system rejects them.
d)
Create checkpoints at periodic intervals after live data processing to test for unauthorized use of the system.
41.
Which one of the following input validation routines is not likely to be appropriate in a real time operation?
a)
Sequence check
b)
Field check
c)
Sign check
d)
Redundant data check
42.
Auditors usually obtain information about general and application controls through:
a)
interviews with IT personnel.
b)
all of the methods.
c)
reading program change requests.
d)
examination of systems documentation.
43.
Which of the following is not an application control?
a)
Separation of duties between computer programmer and operators.
b)
Preprocessing authorization of sales transactions.
c)
Reasonableness test for unit selling price of sale.
d)
Post-processing review of sales transactions by the sales department.
44.
After the preliminary phase of the review of a client’s computer controls, an auditor may decide not to perform tests of controls related to the controls within the computer portion of the client’s internal control. Which of the following would not be a valid reason for choosing to omit such tests?
a)
The controls duplicate operative controls existing elsewhere in the structure.
b)
The controls appear adequate.
c)
There appear to be major weaknesses that would preclude reliance on the stated procedure.
d)
The time and dollar costs of testing exceed the time and dollar savings in substantive testing if the tests of controls show the controls to be operative.
45.
An example of a program in which the audit team would be most interested in testing automated application controls is a(n)
a)
Operating system program.
b)
Utility program.
c)
Data management system software.
d)
Payroll processing program.
46.
Lalisa Company processes payroll transactions for schools. Mosang, CPA, is engaged to report on Lalisa's policies and procedures placed in operation as of a specific date. These policies and procedures are relevant to the schools' internal control structure, so Mosang's report will be useful in providing the schools' independent auditors with information necessary to plan their audits. Mosang's report expressing an opinion on Lalisa's policies and procedures placed in operation as of a specific date should contain a(an)
a)
Description of the scope and nature of Lalisa's procedures.
b)
Opinion on the operating effectiveness of Lalisa's policies and procedures.
c)
Statement that Lalisa's management has disclosed to Mosang all design deficiencies of which it is aware.
d)
Paragraph indicating the basis for Mosang's assessment of control risk.
47.
An organization performs a daily backup of critical data and software files and stores the backup tapes at an offsite location. The backup tapes are used to restore the files in case of a disruption. This is an example of a:
a)
corrective control.
b)
detective control.
c)
management control.
d)
preventive control.
48.
An audit team's approach to evaluating computerized processing systems that compares source documents to the computer output is known as auditing
a)
Without the computer.
b)
With the computer.
c)
Around the computer.
d)
Through the computer.
49.
Computer systems are typically supported by a variety of utility software packages that are important to an auditor because they
a)
Are written specifically to enable auditors to extract and sort data.
b)
May be significant components of a client’s application programs.
c)
May enable unauthorized changes to data files if not properly controlled.
d)
Are very versatile programs that can be used on hardware of many manufacturers.
50.
An auditor using audit software probably would be least interested in which of the following fields in a computerized perpetual inventory file?
a)
Quantity sold.
b)
Economic order quantity.
c)
Warehouse location.
d)
Date of last purchase.
51.
Which of the following is a computer test made to ascertain whether a given characteristic belongs to the group? (CPA Board Exam, May 2017)
a)
Validity check
b)
Limit check
c)
Echo check
d)
Parity check
52.
Audit teams would most likely introduce test data into a computerized payroll system to test internal controls related to the
a)
Existence of unclaimed payroll checks held by supervisors.
b)
Proper approval of overtime by supervisors.
c)
Discovery of invalid employee identification numbers.
d)
Early cashing of payroll checks by employees.
53.
Which of the following client information technology (IT) systems generally can be audited without examining or directly testing the IT computer programs of the system?
a)
A system that updates a few essential master files and produces no printed output other than final balances.
b)
A system that performs relatively uncomplicated processes and produces detailed output.
c)
A system that performs relatively complicated processing and produces very little detailed output.
d)
A system that affects a number of essential master files and produces a limited output.
54.
Effective internal control over purchases generally can be achieved in a well-planned organizational structure with a separate purchasing department that has
a)
the responsibility of reviewing purchase orders issued by user departments
b)
a direct reporting responsibility to the controller of the organization
c)
the authority to make purchases of requisitioned materials and services
d)
the ability to prepare payment vouchers based on the information of on a vendor's invoice
55.
To obtain evidence that user identification and password control procedures are functioning as designed, an auditor would most likely
a)
Extract a random sample of processed transactions and ensure that the transactions were appropriately authorized.
b)
Examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
c)
Attempt to sign on to the system using invalid user identifications and passwords.
d)
Write a computer program that simulates the logic of the client’s access control software.
56.
An auditor most likely would introduce test data into a computerized payroll system to test internal controls related to the
a)
Proper approval of overtime by supervisors.
b)
Early cashing of payroll checks by employees.
c)
Discovery of invalid employee I.D. numbers.
d)
Existence of unclaimed payroll checks held by supervisors.
57.
Dalgona Corporation’s organization chart provides for a controller and an EDP manager, both of whom report to the financial vice-president. Internal control would not be strengthened by
a)
Assigning the programming and operating of the computer to an independent control group which reports to the controller.
b)
Providing for review and distribution of computer output by an independent control group which reports to the controller.
c)
Rotating periodically among machine operators the assignments of individual application run.
d)
Providing for maintenance of input data controls by an independent control group which reports to the controller.
58.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
a)
Several transactions of each type must be tested.
b)
The program tested is different from the program used throughout the year by the client.
c)
Test data must consist of all possible valid and invalid conditions.
d)
Test data are processed by the client’s computer programs under the auditor’s control.
59.
Using laptop computers in auditing may affect the methods used to review the work of staff assistants because
a)
Supervisory personnel may not have an understanding of the capabilities and limitations of laptops.
b)
Documenting the supervisory review may require assistance of consulting services personnel.
c)
Working paper documentation may not contain readily observable details of calculations.
d)
The generally accepted auditing standards may differ.
60.
Each of the following automated application controls is designed to ensure that the input of individual transactions and data is accurate except
a)
Check digits.
b)
Sequence tests.
c)
Limit and reasonableness tests.
d)
Valid sign tests.
61.
Computer systems are typically supported by a variety of utility software packages that are important to an auditor because they
a)
May enable unauthorized changes to data files if not properly controlled.
b)
May be significant components of a client’s application programs.
c)
Are written specifically to enable auditors to extract and sort data.
d)
Are very versatile programs that can be used on hardware of many manufacturers.
62.
When using test data, why are audit teams required to prepare only one transaction to test each computer processing alternative?
a)
The risk of misstatement is typically lower in a computerized processing environment.
b)
Audit teams generally perform more extensive substantive testing in a computerized processing environment, resulting in less need to test processing controls.
c)
The speed and efficiency of the computer results in reduced sample sizes.
d)
In a computerized processing environment, each transaction is handled in an identical manner.
63.
When programs or files can be accessed from terminals, users should be required to enter a(n)
a)
Parity check.
b)
Self-diagnosis test.
c)
Personal identification code.
d)
Echo check.
64.
Which of the following statements most likely represents a control consideration for an entity that performs its accounting using portable computing devices?
a)
Random errors in report printing are rare in packaged software systems.
b)
Transactions are coded for account classifications before they are processed on the computer.
c)
It is usually difficult to detect arithmetic errors.
d)
Unauthorized persons find it easy to access the computer and alter the data files.
65.
Which of the following is not among the errors that an auditor might include in the test data when auditing a client’s computer system?
a)
Numeric characters in alphanumeric fields.
b)
Illogical entries in fields whose logic is tested by programmed consistency checks.
c)
Differences in description of units of measure.
d)
Authorized code.
66.
Which of the following would be least likely to be included in an auditor's tests of controls?
a)
confirmation
b)
inspection
c)
observation
d)
inquiry
67.
Audit teams can obtain evidence of the proper functioning of password access control to a computerized processing system by
a)
Selecting a random sample of the client's completed transactions to check the existence of proper authorization.
b)
Attempting to sign on to the computerized processing system with a false password.
c)
Obtaining representations from the client's computer personnel that the password control prevents unauthorized entry.
d)
Writing a computer program that simulates the logic of a good password control system.
68.
An auditor who wishes to capture an entity’s data as transactions are processed and continuously test the entity’s computerized information system most likely would use which of the following techniques?
a)
Test data generator.
b)
Embedded audit module.
c)
Snapshot application.
d)
Integrated data check.
69.
The effect of a database system on the accounting system and the associated risks will least likely depend on:
a)
The CIS application controls.
b)
The extent to which databases are being used by accounting applications.
c)
The type and significance of financial transactions being processed.
d)
The nature of the database, the Database Management System (DBMS), the database administration tasks and the applications.
70.
An auditor would least likely use computer software to
a)
Construct parallel simulations.
b)
Prepare spreadsheets.
c)
Access client data files.
d)
Assess computer control risk.
71.
Which of the following methods of testing application controls utilizes a generalized audit software package prepared by the auditors?
a)
Parallel simulation.
b)
Exception report tests.
c)
Integrated testing facility approach.
d)
Test data approach.
72.
An auditor would be most likely to assess control risk at the maximum level in an electronic environment with automated system-generated information when
a)
Sales orders are initiated using predetermined, automated decision rules.
b)
Payables are based on many transactions and large in dollar amount.
c)
Accounts receivable records are based on many transactions and are large in dollar amount.
d)
Fixed asset transactions are few in number, but large in dollar amount.
73.
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses an EDP system is that the auditor may:
a)
Reduce the level of required tests of controls to a relatively small amount.
b)
Substantiate the accuracy of data through self-checking digits and hash totals.
c)
Consider increasing the use of substantive tests of transactions in place of analytical procedures.
d)
Access information stored on computer files while having a limited understanding of the client's hardware and software features.
74.
Reliability of audit evidence refers to the amount of corroborative evidence obtained.
a)
Reliability of audit evidence refers to the amount of corroborative evidence obtained.
b)
Effective internal control provides more assurance about the reliability of audit evidence.
c)
Information obtained indirectly from outside sources is the most reliable audit evidence.
d)
To be reliable, audit evidence should be convincing rather than persuasive.
75.
Which of the following computer-assisted auditing techniques allows fictitious and real transactions to be processed together without client operating personnel being aware of the testing process?
a)
Input controls matrix.
b)
Data entry monitor.
c)
Parallel simulation.
d)
Integrated test facility.
76.
Rocelle Corporation has numerous customers. A customer file is kept on disk storage. Each customer file contains name, address, credit limit, and account balance. The auditor wishes to test this file to determine whether credit limits are being exceeded. The best procedure for the auditor to follow would be to
a)
Develop test data that would cause some account balances to exceed the credit limit and determine if the system properly detects such situations.
b)
Request a printout of a sample of account balances so they can be individually checked against the credit limits.
c)
Develop a program to compare credit limits with account balances and print out the details of any account with a balance exceeding its credit limit.
d)
Request a printout of all account balances so they can be manually checked against the credit limits.
77.
Which of the following is not a major reason why an accounting audit trail should be maintained for a computer system?
a)
Monitoring purposes.
b)
Query answering.
c)
Analytical procedures.
d)
Deterrent to irregularities.
78.
S1: Firewalls can protect company data and software programs.
S2: Programmers should have access to transaction data.
a)
False, True
b)
True, True
c)
False, False
d)
True, False
79.
An auditor would most likely be concerned with which of the following controls in a distributed data processing system?
a)
Hardware controls.
b)
Access controls.
c)
Systems documentation controls.
d)
Disaster recovery controls.
80.
To determine that user ID and password controls are functioning, an auditor would most likely:
a)
extract a random sample of processed transactions and ensure that the transactions were appropriately authorized.
b)
write a computer program that simulates the logic of the client’s access control software.
c)
attempt to sign on to the system using invalid user identifications and passwords.
d)
examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
81.
Auditing by testing the input and output of a computer system instead of the computer program itself will
a)
Provide the auditor with the same type of evidence as tests of application controls.
b)
Not detect program errors which do not show up in the output sampled.
c)
Not provide the auditor with confidence in the results of the auditing procedures.
d)
Detect all program errors, regardless of the nature of the output.
82.
Which of the following least likely protects critical and sensitive information from unauthorized access in a personal computer environment?
a)
Keeping of back up copies offsite.
b)
Using secret file names and hiding the files.
c)
Employing passwords.
d)
Segregating data into files organized under separate file directories.
83.
Which of the following controls most likely would ensure that an organization can reconstruct its financial records?
a)
Personnel who are independent of data input perform parallel simulations.
b)
Hardware controls are built into the computer by the computer manufacturer.
c)
System flowcharts provide accurate descriptions of computer operations.
d)
Backup files are stored in a location separate from original copies.
84.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
a)
Test data are processed by the client’s computer programs under the auditor’s control.
b)
The program tested is different from the program used throughout the year by the client.
c)
Several transactions of each type must be tested.
d)
Test data must consist of all possible valid and invalid conditions.
85.
Which of the following statements regarding auditor documentation of the client's system of internal control is correct?
a)
No documentation is necessary although it is desirable.
b)
No one particular form of documentation is necessary, and the extent of documentation may vary.
c)
Documentation must include procedural write-ups
d)
Documentation must include flowcharts
86.
When using the test data approach:
a)
select data may remain in the client system after testing.
b)
none of the above statements is correct.
c)
test data should include only exception conditions.
d)
application programs tested must be virtually identical to those used by employees.
87.
S1: The test data approach requires the auditor to insert an audit module in the client’s application system to test transaction data specifically identified by the auditor as unusual.
S2: General controls in smaller companies are usually less effective than in more complex IT environments.
a)
False, True
b)
True, False
c)
False, False
d)
True, True
88.
Controls which apply to a specific element of the system are called:
a)
user controls.
b)
systems controls.
c)
applications controls.
d)
general controls.
89.
Which of the following statements related to application controls is correct?
a)
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
b)
Application controls relate to all aspects of the IT function.
c)
Application controls relate to the processing of individual transactions.
d)
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
90.
A control that relates to all parts of the IT system is called a(n):
a)
applications control.
b)
general control.
c)
universal control.
d)
systems control.
91.
The result of risk management process is used for:
a)
forecasting profit
b)
designing controls
c)
user acceptance testing.
d)
post implementation review.
92.
An IS auditor is reviewing payroll application. He identified some vulnerability in the system. What would be the next task?
a)
Examine application development process.
b)
Recommend for new application.
c)
Report the vulnerabilities to the management immediately.
d)
Identify threats and likelihood of occurrence.
93.
When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that:
a)
all the relevant vulnerabilities and threats are identified.
b)
regularity compliance is adhered to.
c)
segregation of duties to mitigate risks is in place.
d)
business is profitable.
94.
What should the IS auditor do FIRST?
a)
Perform an IT risk assessment.
b)
Begin testing controls that the IS auditor feels are most critical.
c)
Perform a survey audit of logical access controls.
d)
Revise the audit plan to focus on risk-based auditing.
95.
In a risk-based audit planning, an IS auditor's first step is to identify:
a)
cost centre.
b)
high-risk areas within the organization.
c)
profit centre.
d)
responsibilities of stakeholders.
96.
The decisions and actions of an IS auditor are MOST likely to affect which of the following risks?
a)
Control
b)
Detection
c)
Inherent
d)
Business
97.
Which of the following would an IS auditor perform FIRST when planning an IS audit?
a)
Develop the audit approach or audit strategy.
b)
Define audit deliverables.
c)
Finalize the audit scope and audit objectives.
d)
Gain an understanding of the business’s objectives and purpose.
98.
Risk assessment approach is more suitable when determining the appropriate level of protection for an information asset because it ensures:
a)
only most sensitive information assets are protected.
b)
appropriate levels of protection are applied to information assets.
c)
a basic level of protection is applied regardless of asset value.
d)
all information assets are protected.
99.
Risk assessment process is:
a)
subjective.
b)
mathematical.
c)
objective.
d)
statistical.
100.
While determining the appropriate level of protection for an information asset an IS auditor should primarily focus on:
a)
Result of vulnerability assessment.
b)
Cost of information asset.
c)
Criticality of information asset.
d)
Owner of information asset.
101.
Evaluation of IT risks can be done by:
a)
industry benchmark.
b)
reviewing IT control weaknesses identified in audit reports.
c)
finding threats/vulnerabilities associated with current IT assets.
d)
Trend analysis on the basis of past year losses.
102.
The decisions and actions of an IS auditor are MOST likely to affect which of the following risks?
a)
Control
b)
Business
c)
Detection
d)
Inherent
103.
Absence of proper security measures represents a (n):
a)
impact.
b)
asset.
c)
threat.
d)
vulnerability.
104.
An IS Auditor is reviewing data centre security review. Which of the following steps would an IS auditor normally perform FIRST:
a)
Determine the vulnerabilities/threats to the data centre site.
b)
Review screening process for hiring security staff
c)
Evaluate logical access control.
d)
Evaluate physical access control.
105.
While determining the appropriate level of protection for an information asset an IS auditor should primarily focus on:
a)
Criticality of information asset.
b)
Result of vulnerability assessment.
c)
Owner of information asset.
d)
Cost of information asset.
106.
An IS auditor should ensure that IT governance performance measures:
a)
evaluate the IT department.
b)
evaluate the activities of IT oversight committees.
c)
provide strategic IT drivers.
d)
adhere to regulatory reporting standards and definitions.
107.
Which of the following factors an IS auditor should primarily consider when determining the acceptable level of risk:
a)
Line management should be involved in the risk analysis because management sees risks daily that others would not recognize.
b)
Risks must be identified and documented in order to perform proper analysis on them.
c)
All risks do not need to be eliminated for a business to be profitable.
d)
Risk acceptance is the responsibility of senior management.
108.
Major advantage of risk-based approach for audit planning is:
a)
Audit activity can be completed within allotted budget.
b)
Appropriate utilization of resources for high risk areas.
c)
Use of latest technology for audit activities.
d)
Audit planning can be communicated to client in advance.
109.
Which of the following is MOST effective for implementing a control self-assessment within small business units?
a)
Process flow narratives
b)
Facilitated workshops
c)
Data flow diagrams
d)
Informal peer reviews
110.
Risk can be mitigated by:
a)
Contracts and service level agreements (SLAs)
b)
Audit and certification
c)
Insurance
d)
Implementing controls
111.
As compared to understanding an organization's IT process from evidence directly collected, how valuable are prior audit reports as evidence?
a)
The same value.
b)
Greater value.
c)
Prior audit reports are not relevant.
d)
Lesser value.
112.
IS Auditor identified certain threats and vulnerabilities in a business process. Next, an IS auditor should:
a)
identifies information assets and the underlying systems.
b)
identifies and evaluates the existing controls.
c)
identify stakeholder for that business process.
d)
discloses the threats and impacts to management.
113.
Overall business risk for a particular threat can be expressed as:
a)
probability of occurrence.
b)
assumption of the risk assessment team.
c)
magnitude of impact.
d)
a product of the probability and impact.
114.
The approach an IS auditor should use to plan IS audit coverage should be based on:
a)
materiality.
b)
fraud monitoring.
c)
risk.
d)
sufficiency of audit evidence.
115.
Overall business risk for a particular threat can be expressed as:
a)
magnitude of impact.
b)
assumption of the risk assessment team.
c)
probability of occurrence.
d)
a product of the probability and impact.
116.
The risk of an IS auditor certifying existence of proper system and procedures without using an inadequate test procedure is an example of:
a)
control risk.
b)
inherent risk.
c)
audit risk.
d)
detection risk.
117.
When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that:
a)
regularity compliance is adhered to.
b)
all the relevant vulnerabilities and threats are identified.
c)
business is profitable.
d)
segregation of duties to mitigate risks is in place.
118.
In a small organization where segregation of duties (SoD) is not practical, an employee performs the function of computer operator and application programmer. Which of the following controls should the IS auditor recommend?
a)
Access controls to prevent the operator from making program modifications
b)
Additional staff to provide SoD
c)
Procedures that verify that only approved program changes are implemented
d)
Automated logging of changes to development libraries
119.
Most important step in a risk analysis is to identify:
a)
liabilities.
b)
competitors.
c)
vulnerabilities.
d)
controls.
120.
IS Auditor is developing a risk management program, the FIRST activity to be performed is a(n):
a)
evaluation of control.
b)
vulnerability assessment.
c)
gap analysis.
d)
identification of assets.
Reset
