Font size
S
M
L
XL
WorksheetsENTPLAN
Total questions: 105
Worksheet time: 53mins
Name
Class
Date
1.
Which of the following factors an IS auditor should primarily consider when determining the acceptable level of risk
a)
Risk acceptance is the responsibility of senior management.
b)
Risks must be identified and documented in order to perform proper analysis on them.
c)
Line management should be involved in the risk analysis because management sees risks daily that others would not recognize.
d)
All risks do not need to be eliminated for a business to be profitable.
2.
Risk can be mitigated by:
a)
Contracts and service level agreements (SLAs)
b)
Insurance
c)
Audit and certification
d)
Implementing controls
3.
Major advantage of risk-based approach for audit planning is:
a)
Use of latest technology for audit activities.
b)
Audit activity can be completed within allotted budget.
c)
Audit planning can be communicated to client in advance.
d)
Appropriate utilization of resources for high risk areas.
4.
As compared to understanding an organization's IT process from evidence directly collected, how valuable are prior audit reports as evidence?
a)
The same value.
b)
Greater value.
c)
Prior audit reports are not relevant.
d)
Lesser value.
5.
Which of the following would an IS auditor perform FIRST when planning an IS audit?
a)
Define audit deliverables.
b)
Finalize the audit scope and audit objectives.
c)
Develop the audit approach or audit strategy.
d)
Gain an understanding of the business’s objectives and purpose.
6.
While determining the appropriate level of protection for an information asset an IS auditor should primarily focus on:
a)
Cost of information asset.
b)
Result of vulnerability assessment.
c)
Owner of information asset.
d)
Criticality of information asset.
7.
Which of the following is MOST effective for implementing a control self-assessment within small business units?
a)
Data flow diagrams
b)
Informal peer reviews
c)
Process flow narratives
d)
Facilitated workshops
8.
IS Auditor identified certain threats and vulnerabilities in a business process. Next, an IS auditor should:
a)
identifies and evaluates the existing controls.
b)
identifies information assets and the underlying systems.
c)
discloses the threats and impacts to management.
d)
identify stakeholder for that business process.
9.
The decisions and actions of an IS auditor are MOST likely to affect which of the following risks?
a)
Control
b)
Inherent
c)
Business
d)
Detection
10.
When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that:
a)
business is profitable.
b)
segregation of duties to mitigate risks is in place.
c)
regularity compliance is adhered to.
d)
all the relevant vulnerabilities and threats are identified.
11.
What should the IS auditor do FIRST?
a)
Revise the audit plan to focus on risk-based auditing.
b)
Perform a survey audit of logical access controls.
c)
Begin testing controls that the IS auditor feels are most critical.
d)
Perform an IT risk assessment.
12.
In a risk-based audit planning, an IS auditor's first step is to identify:
a)
profit centre.
b)
cost centre.
c)
responsibilities of stakeholders.
d)
high-risk areas within the organization.
13.
An IS auditor should ensure that IT governance performance measures:
a)
evaluate the IT department.
b)
provide strategic IT drivers.
c)
adhere to regulatory reporting standards and definitions.
d)
evaluate the activities of IT oversight committees.
14.
Overall business risk for a particular threat can be expressed as
a)
probability of occurrence.
b)
assumption of the risk assessment team.
c)
magnitude of impact.
d)
a product of the probability and impact.
15.
Risk assessment process is:
a)
Objective.
b)
Statistical.
c)
mathematical.
d)
Subjective.
16.
Evaluation of IT risks can be done by:
a)
reviewing IT control weaknesses identified in audit reports.
b)
Trend analysis on the basis of past year losses.
c)
industry benchmark.
d)
finding threats/vulnerabilities associated with current IT assets.
17.
Most important step in a risk analysis is to identify
a)
controls
b)
Competitors
c)
Liabilities
d)
vulnerabilities
18.
Risk assessment approach is more suitable when determining the appropriate level of protection for an information asset because it ensures:
a)
a basic level of protection is applied regardless of asset value.
b)
only most sensitive information assets are protected.
c)
all information assets are protected.
d)
appropriate levels of protection are applied to information assets.
19.
The result of risk management process is used for:
a)
user acceptance testing.
b)
forecasting profit
c)
post implementation review.
d)
designing controls
20.
An IS auditor is reviewing payroll application. He identified some vulnerability in the system. What would be the next task?
a)
Report the vulnerabilities to the management immediately.
b)
Examine application development process.
c)
Recommend for new application.
d)
Identify threats and likelihood of occurrence.
21.
The approach an IS auditor should use to plan IS audit coverage should be based on:
a)
materiality.
b)
sufficiency of audit evidence.
c)
fraud monitoring.
d)
risk
22.
Absence of proper security measures represents a (n):
a)
impact
b)
threat.
c)
asset.
d)
vulnerability.
23.
The risk of an IS auditor certifying existence of proper system and procedures without using an inadequate test procedure is an example of:
a)
audit risk.
b)
inherent risk.
c)
control risk.
d)
detection risk.
24.
IS Auditor is developing a risk management program, the FIRST activity to be performed is a(n):
a)
vulnerability assessment.
b)
gap analysis.
c)
evaluation of control.
d)
identification of assets.
25.
When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that:
a)
segregation of duties to mitigate risks is in place.
b)
regularity compliance is adhered to.
c)
business is profitable.
d)
all the relevant vulnerabilities and threats are identified.
26.
Dalgona Corporation’s organization chart provides for a controller and an EDP manager, both of whom report to the financial vice-president. Internal control would not be strengthened by
a)
Providing for maintenance of input data controls by an independent control group which reports to the controller.
b)
Providing for review and distribution of computer output by an independent control group which reports to the controller.
c)
Rotating periodically among machine operators the assignments of individual applications run.
d)
Assigning the programming and operating of the computer to an independent control group which reports to the controller.
27.
_____ controls prevent and detect errors while transaction data are processed.
a)
Software
b)
Transaction
c)
Application
d)
Processing
28.
An auditor anticipates assessing control risk at a low level in a computerized environment. Under these circumstances, on which of the following activities would the auditor initially focus?
a)
Application control activities.
b)
Programmed control activities.
c)
Output control activities.
d)
General control activities.
29.
To obtain evidence that user identification and password controls are functioning as designed, an auditor would most likely
a)
Extract a random sample of processed transactions were appropriately authorized.
b)
Examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
c)
Write a computer program that simulates the logic of the client’s access control software.
d)
Attempt to sign-on to the system using invalid user identifications and passwords.
30.
An auditor who is testing EDP controls in a payroll system would most likely use test data that contain conditions such as
a)
Overtime not approved by supervisors.
b)
Deductions not authorized by employees.
c)
Payroll checks with unauthorized signatures.
d)
Time tickets with invalid job numbers.
31.
Which of the following is not among the errors that an auditor might include in the test data when auditing a client’s computer system?
a)
Illogical entries in fields whose logic is tested by programmed consistency checks.
b)
Authorized code.
c)
Differences in description of units of measure.
d)
Numeric characters in alphanumeric fields.
32.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
a)
The program tested is different from the program used throughout the year by the client.
b)
Several transactions of each type must be tested.
c)
Test data must consist of all possible valid and invalid conditions.
d)
Test data are processed by the client’s computer programs under the auditor’s control.
33.
A flowchart is most frequently used by an auditor in connection with the
a)
Performance of analytical procedures of account balances.
b)
Use of statistical sampling in performing an audit.
c)
Preparation of generalized computer audit plans.
d)
Review of the client’s internal control.
34.
An auditor most likely would test for the presence of unauthorized EDP program changes by running a
a)
Program with test data.
b)
Program that computes control totals.
c)
Check digit verification program.
d)
Source code comparison program.
35.
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses a computer system is that the auditor may
a)
Substantiate the accuracy of data through self checking digits and hash totals.
b)
Reduce the level of required tests of controls to a relatively small amount.
c)
Consider increasing the use of substantive tests of transactions in place of analytical procedures.
d)
Access information stored on computer files while having a limited understanding of the client’s hardware and software features.
36.
Which of the following computer-assisted auditing techniques processes client input data on a controlled program under the auditor’s control to test controls in the computer system?
a)
Integrated test facility.
b)
Review of program logic.
c)
Test data.
d)
Parallel simulation.
37.
Auditors usually obtain information about general and application controls through:
a)
interviews with IT personnel.
b)
reading program change requests.
c)
examination of systems documentation.
d)
all of the methods.
38.
In creating lead schedules for an audit engagement, a CPA often uses automated workpaper software. What client information is needed to begin this process?
a)
Interim financial information such as third quarter sales, net income, and inventory and receivables balances.
b)
Adjusting entry information such as deferrals and accruals, and reclassification journal entries.
c)
Specialized journal information such as the invoice and purchase order numbers of the last few sales and purchases of the year.
d)
General ledger information such as account numbers, prior year account balances, and current year unadjusted information.
39.
Which of the following would be least likely to be included in an auditor's tests of controls?
a)
observation
b)
inquiry
c)
inspection
d)
Confirmation
40.
Which of the following is not a general control?
a)
Hardware controls.
b)
Procedures for documenting, reviewing, and approving systems and programs.
c)
The plan of organization and operation of IT activity.
d)
Processing controls.
41.
Talaga Sharmaine Co. uses an online sales order processing system to process its sales transactions. Talaga Sharmaine's sales data are electronically sorted and subjected to edit checks. A direct output of the edit checks most likely would be a
a)
Printout of all user code numbers and passwords.
b)
List of all voided shipping documents.
c)
Report of all missing sales invoices.
d)
File of all rejected sales transactions.
42.
A control that relates to all parts of the IT system is called a(n):
a)
systems control.
b)
applications control.
c)
universal control.
d)
general control.
43.
Which of the following statements related to application controls is correct
a)
Application controls relate to all aspects of the IT function.
b)
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
c)
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
d)
Application controls relate to the processing of individual transactions.
44.
Auditing by testing the input and output of a computer system instead of the computer program itself will
a)
Not provide the auditor with confidence in the results of the auditing procedures.
b)
Provide the auditor with the same type of evidence as tests of application controls.
c)
Detect all program errors, regardless of the nature of the output.
d)
Not detect program errors which do not show up in the output sampled.
45.
S1: Firewalls can protect company data and software programs.
S2: Programmers should have access to transaction data.
a)
True, True
b)
False, False
c)
False, True
d)
True, False
46.
Controls which apply to a specific element of the system are called:
a)
systems controls.
b)
general controls.
c)
user controls.
d)
applications controls.
47.
Using laptop computers in auditing may affect the methods used to review the work of staff assistants because
a)
Supervisory personnel may not have an understanding of the capabilities and limitations of laptops.
b)
The generally accepted auditing standards may differ.
c)
Documenting the supervisory review may require assistance of consulting services personnel.
d)
Working paper documentation may not contain readily observable details of calculations.
48.
Computer systems are typically supported by a variety of utility software packages that are important to an auditor because they
a)
Are very versatile programs that can be used on hardware of many manufacturers.
b)
Are written specifically to enable auditors to extract and sort data.
c)
May be significant components of a client’s application programs.
d)
May enable unauthorized changes to data files if not properly controlled.
49.
Controls which are designed to assure that the information processed by the computer is authorized, complete, and accurate are called:
a)
general controls.
b)
processing controls.
c)
output controls.
d)
input controls.
50.
An auditor who wishes to capture an entity’s data as transactions are processed and continuously test the entity’s computerized information system most likely would use which of the following techniques?
a)
Integrated data check.
b)
Snapshot application.
c)
Test data generator.
d)
Embedded audit module.
51.
An example of an internal control weakness is to assign to a department supervisor the responsibility for
a)
reviewing and approving time reports for subordinate employees
b)
authorizing payroll checks for terminated employees
c)
initiating request for salary adjustments for subordinate employees
d)
distributing payroll checks to subordinate employees
52.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
a)
The program tested is different from the program used throughout the year by the client.
b)
Test data must consist of all possible valid and invalid conditions.
c)
Several transactions of each type must be tested.
d)
Test data are processed by the client’s computer programs under the auditor’s control.
53.
Squid Game Corporation has just completely computerized its billing and accounts receivable recordkeeping. You want to make maximum use of the new computer in your audit of Squid Game Corporation. Which of the following audit techniques could not be performed through a computer program?
a)
Tracing audited cash receipts to accounts receivable credits.
b)
Examining sales invoices for completeness, consistency between different items, valid conditions and reasonable mounts.
c)
Selecting on a random number basis accounts to be confirmed.
d)
Resolving differences reported by customers on confirmation requests.
54.
Audit teams can obtain evidence of the proper functioning of password access control to a computerized processing system by
a)
Selecting a random sample of the client's completed transactions to check the existence of proper authorization.
b)
Obtaining representations from the client's computer personnel that the password control prevents unauthorized entry.
c)
Writing a computer program that simulates the logic of a good password control system.
d)
Attempting to sign on to the computerized processing system with a false password.
55.
An auditor most likely would introduce test data into a computerized payroll system to test controls related to the
a)
Existence of unclaimed payroll checks held by supervisors.
b)
Early cashing of payroll checks by employees.
c)
Proper approval of overtime by supervisors.
d)
Discovery of invalid employee I.D. numbers.
56.
CIS application controls include, except
a)
Controls over processing and computer data files.
b)
Controls over output.
c)
Controls over input.
d)
Monitoring controls.
57.
Which of the following tasks could not be performed when using a generalized audit software package?
a)
Summarizing inventory turnover statistics for obsolescence analysis.
b)
Selecting inventory items for observations.
c)
Comparison of inventory test counts with perpetual records.
d)
Physical count of inventories.
58.
When an accounting application is processed by computer, an auditor cannot verify the reliable operation of programmed control procedures by
a)
Constructing a processing system for accounting applications and processing actual data from throughout the period through both the client’s program and the auditor’s program.
b)
Manually comparing detain transaction files used by an edit program to the program’s generated error listings to determine that errors were properly identified by the edit program.
c)
Periodically submitting auditor-prepared test data to the same computer process and evaluating the results.
d)
Manually performing, as of a point in time, the processing of input data and comparing the simulated results to the actual results.
59.
To obtain evidence that online access controls are properly functioning, an auditor most likely would
a)
Create checkpoints at periodic intervals after live data processing to test for unauthorized use of the system.
b)
Vouch a random sample of processed transactions to assure proper authorization.
c)
Examine the transaction log to discover whether any transactions were lost or entered twice due to a system malfunction.
d)
Enter invalid identification numbers or passwords to ascertain whether the system rejects them.
60.
When using the test data approach:
a)
application programs tested must be virtually identical to those used by employees.
b)
select data may remain in the client system after testing.
c)
test data should include only exception conditions.
d)
none of the above statements is correct.
61.
Audit teams would most likely introduce test data into a computerized payroll system to test internal controls related to the
a)
Existence of unclaimed payroll checks held by supervisors.
b)
Proper approval of overtime by supervisors.
c)
Early cashing of payroll checks by employees.
d)
Discovery of invalid employee identification numbers.
62.
Auditors often make use of computer programs that perform routine processing functions such as sorting and merging. These programs are made available by electronic data processing companies and others and are specifically referred to as
a)
User programs.
b)
Compiler programs.
c)
Supervisory programs.
d)
Utility programs.
63.
Which one of the following input validation routines is not likely to be appropriate in a real time operation?
a)
Sign check
b)
Redundant data check
c)
Field check
d)
Sequence check
64.
Which of the following procedures most likely would not be an internal control procedure designed to reduce the risk of errors in the billing process?
a)
Using computer programmed controls on the pricing and mathematical accuracy of sales invoices
b)
Matching shipping documents with approved sales orders before invoice preparation.
c)
Comparing control totals for shipping documents with corresponding totals for sales invoices
d)
Reconciling the control totals for sales invoices with the accounts receivable subsidiary ledger.
65.
An auditor using audit software probably would be least interested in which of the following fields in a computerized perpetual inventory file?
a)
Quantity sold.
b)
Date of last purchase.
c)
Warehouse location.
d)
Economic order quantity.
66.
In an automated payroll system, all employees in the finishing department were paid the rate of P75 per hour when the authorized rate was P70 per hour. Which of the following controls would have been most effective in preventing such an error?
a)
A limit test that compares the pay rates per department with the maximum rate for all employees.
b)
A review of all authorized pay rate changes by the personnel department.
c)
Access controls which would restrict the personnel department’s access to the payroll master file data.
d)
The use of batch control totals by department.
67.
Which of the following statements most likely represents a control consideration for an entity that performs its accounting using portable computing devices?
a)
Transactions are coded for account classifications before they are processed on the computer.
b)
Random errors in report printing are rare in packaged software systems.
c)
It is usually difficult to detect arithmetic errors.
d)
Unauthorized persons find it easy to access the computer and alter the data files
68.
S1: The test data approach requires the auditor to insert an audit module in the client’s application system to test transaction data specifically identified by the auditor as unusual.
S2: General controls in smaller companies are usually less effective than in more complex IT environments.
a)
True, True
b)
False, False
c)
True, False
d)
False, True
69.
Which of the following statements regarding auditor documentation of the client's system of internal control is correct?
a)
Documentation must include flowcharts
b)
No documentation is necessary although it is desirable.
c)
Documentation must include procedural write-ups
d)
No one particular form of documentation is necessary, and the extent of documentation may vary.
70.
S1: “Auditing around the computer” is acceptable only if the auditor has access to the client’s data in a machine-readable language.
S2: “Auditing around the computer” is most appropriate when the client has not maintained detailed output or source documents in a form readable by humans.
a)
False, True
b)
True, True
c)
True, False
d)
False, False
71.
Which of the following tasks could not be performed when using a generalized audit software package?
a)
Comparison of inventory test counts with perpetual records.
b)
Summarizing inventory turnover statistics for obsolescence analysis.
c)
Selecting inventory items for observations.
d)
Physical count of inventories.
72.
An example of a program in which the audit team would be most interested in testing automated application controls is a(n)
a)
Utility program.
b)
Operating system program.
c)
Data management system software.
d)
Payroll processing program.
73.
Application controls vary across the IT system. To gain an understanding of internal control for a private company, the auditor must evaluate the application controls for every:
a)
every material audit area.
b)
every audit area in which the client uses the computer.
c)
every audit area.
d)
every audit area where the auditor plans to reduce assessed control risk.
74.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
a)
Test data must consist of all possible valid and invalid conditions.
b)
Several transactions of each type must be tested.
c)
The program tested is different from the program used throughout the year by the client.
d)
Test data are processed by the client’s computer programs under the auditor’s control.
75.
An auditor would be most likely to assess control risk at the maximum level in an electronic environment with automated system-generated information when
a)
Accounts receivable records are based on many transactions and are large in dollar amount.
b)
Payables are based on many transactions and large in dollar amount.
c)
Sales orders are initiated using predetermined, automated decision rules.
d)
Fixed asset transactions are few in number, but large in dollar amount.
76.
Which of the following least likely protects critical and sensitive information from unauthorized access in a personal computer environment?
a)
Accounts receivable records are based on many transactions and are large in dollar amount.
b)
Payables are based on many transactions and large in dollar amount.
c)
Sales orders are initiated using predetermined, automated decision rules.
d)
Fixed asset transactions are few in number, but large in dollar amount.
77.
Audit teams cannot test the reliable operation of computer control procedures by
a)
Manually comparing detailed transactions that the internal auditors used to test a program to the program's actual error messages.
b)
Programming a model transaction processing system and processing actual client transactions for comparison to the output produced by theclient's program.
c)
Submitting test data at several different times for processing on the computer program the client uses for actual transaction processing.
d)
Manually reperforming actual transaction processing with comparison of results to the actual system output.
78.
Internal control over cash receipts is weakened when an employee who receives customer mail receipts also
a)
Maintains a petty cash fund
b)
Prepares initial cash receipts record
c)
Prepares bank deposit slips for all mail receipts
d)
Records credit to individual accounts receivable
79.
Which of the following is a category of general controls?
a)
Input controls.
b)
Physical and online security.
c)
Processing controls.
d)
Output controls.
80.
An auditor can use a generalized computer audit program to verify the accuracy of
a)
Data processing controls.
b)
Accounting estimates.
c)
Account classifications.
d)
Totals and sub-totals.
81.
It is a communication system that enables computer users to share computer equipment, application software, data and voice and video transmissions.
a)
Host
b)
Client
c)
File server
d)
Network
82.
In a small organization where segregation of duties (SoD) is not practical, an employee performs the function of computer operator and
application programmer. Which of the following controls should the IS auditor recommend?
a)
Access controls to prevent the operator from making program modifications
b)
Automated logging of changes to development libraries
c)
Additional staff to provide SoD
d)
Procedures that verify that only approved program changes are implemented
83.
An IS Auditor is reviewing data centre security review. Which of the following steps would an IS auditor normally perform FIRST
a)
Review screening process for hiring security staff
b)
Evaluate logical access control.
c)
Evaluate physical access control.
d)
Determine the vulnerabilities/threats to the data centre site.
84.
Which of the following control procedures most likely could prevent computer personnel from modifying programs to bypass computer controls?
a)
Participation of user department personnel in designing and approving new systems.
b)
Physical security of computer facilities in limiting access to computer equipment.
c)
Periodic management review of computer utilization reports and systems documentation.
d)
Separation of duties for computer programming and computer operations.
85.
Which of the following control procedures most likely could prevent computer personnel from modifying programs to bypass computer controls?
a)
Participation of user department personnel in designing and approving new systems.
b)
Physical security of computer facilities in limiting access to computer equipment.
c)
Periodic management review of computer utilization reports and systems documentation.
d)
Separation of duties for computer programming and computer operations.
86.
Effective internal control over purchases generally can be achieved in a well-planned organizational structure with a separate purchasing department that has
a)
the responsibility of reviewing purchase orders issued by user departments
b)
a direct reporting responsibility to the controller of the organization
c)
the ability to prepare payment vouchers based on the information of on a vendor's invoice
d)
the authority to make purchases of requisitioned materials and services
87.
All of the following are “auditing through the computer” techniques except
a)
Test-decking
b)
Automated tracking and mapping
c)
Integrated test facility
d)
Reviewing source code
88.
An entity has the following invoices in a batch:
Invoice # Product Quantity Unit price
201 F10 150 $5.00
202 G15 200 $10.00
203 H20 250 $25.00
204 K35 300 $30.00
Which of the following numbers represents the record count?
a)
900
b)
1
c)
180
d)
4
89.
Lalisa Company processes payroll transactions for schools. Mosang, CPA, is engaged to report on Lalisa's policies and procedures placed in operation as of a specific date. These policies and procedures are relevant to the schools' internal control structure, so Mosang's report will be useful in providing the schools' independent auditors with information necessary to plan their audits. Mosang's report expressing an opinion on Lalisa's policies and procedures placed in operation as of a specific date should contain a(an)
a)
Statement that Lalisa's management has disclosed to Mosang all design deficiencies of which it is aware.
b)
Opinion on the operating effectiveness of Lalisa's policies and procedures.
c)
Paragraph indicating the basis for Mosang's assessment of control risk.
d)
Description of the scope and nature of Lalisa's procedures.
90.
An auditor would least likely use computer software to
a)
Construct parallel simulations.
b)
Prepare spreadsheets.
c)
Access client data files.
d)
Assess computer control risk.
91.
Which of the following least likely protects critical and sensitive information from unauthorized access in a personal computer environment?
a)
Employing passwords.
b)
Using secret file names and hiding the files.
c)
Segregating data into files organized under separate file directories.
d)
Keeping of back up copies offsite.
92.
Which of the following is not an enhancement to internal control that will occur as a consequence of increased reliance on IT?
a)
Higher quality information is available.
b)
Computer-based controls provide opportunities to enhance separation of duties.
c)
Computer controls replace manual controls.
d)
Manual controls replace automated controls.
93.
Which of the following strategies would a CPA most likely consider in auditing an entity that processes most of its financial data only in electronic form, such as a paperless system?
a)
Verification of encrypted digital certificates used to monitor the authorization of transactions.
b)
Increased reliance on internal control activities that emphasize the segregation of duties.
c)
Extensive testing of firewall boundaries that restrict the recording of outside network traffic.
d)
Continuous monitoring and analysis of transaction processing with an embedded audit module.
94.
It is a computer program (a block of executable code) that attaches itself to a legitimate program or data file and uses its as a transport mechanism to reproduce itself without the knowledge of the user.
a)
Utility program
b)
System management program
c)
Encryption
d)
Virus
95.
After the preliminary phase of the review of a client’s computer controls, an auditor may decide not to perform tests of controls related to the controls within the computer portion of the client’s internal control. Which of the following would not be a valid reason for choosing to omit such tests?
a)
The time and dollar costs of testing exceed the time and dollar savings in substantive testing if the tests of controls show the controls to be operative.
b)
The controls duplicate operative controls existing elsewhere in the structure.
c)
There appear to be major weaknesses that would preclude reliance on the stated procedure.
d)
The controls appear adequate.
96.
Which of the following presumptions is correct about the reliability of audit evidence?
a)
Information obtained indirectly from outside sources is the most reliable audit evidence.
b)
Reliability of audit evidence refers to the amount of corroborative evidence obtained.
c)
To be reliable, audit evidence should be convincing rather than persuasive.
d)
Effective internal control provides more assurance about the reliability of audit evidence.
97.
Which of the following client information technology (IT) systems generally can be audited without examining or directly testing the IT computer programs of the system?
a)
A system that updates a few essential master files and produces no printed output other than final balances.
b)
A system that affects a number of essential master files and produces a limited output.
c)
A system that performs relatively complicated processing and produces very little detailed output.
d)
A system that performs relatively uncomplicated processes and produces detailed output.
98.
Which of the following is a computer test made to ascertain whether a given characteristic belongs to the group? (CPA Board Exam, May 2017)
a)
Echo check
b)
Limit check
c)
Parity check
d)
Validity check
99.
A customer intended to order 100 units of product CPA1022 but incorrectly ordered product CPA1023, which is not an actual product. Which of the following controls most likely would detect this error?
a)
Record count.
b)
Redundant data check.
c)
Hash total.
d)
Check digit verification/ Validity check.
100.
An audit team's approach to evaluating computerized processing systems that compares source documents to the computer output is known as auditing
a)
With the computer.
b)
Without the computer.
c)
Through the computer.
d)
Around the computer.
101.
Which of the following is not a major difference between a manual processing environment and a computerized processing environment?
a)
Random errors are more likely in a manual processing environment than a computerized processing environment.
b)
A hard copy "audit trail" is less likely to exist in a computerized processing environment than a manual processing environment.
c)
A computerized processing environment requires data to be converted into electronic format, which introduces the possibility of input errors.
d)
A computerized processing environment has an increased level of human involvement.
102.
Which of the following is not normally a removable storage media?
a)
Tapes
b)
Compact disk
c)
Diskettes
d)
Hard disk
103.
A collection of data that is shared and used by a number of different users for different purposes.
a)
Transaction file
b)
Information file
c)
Master file
d)
Database
104.
Which statement is incorrect regarding the review of general CIS controls and CIS application controls?
a)
General CIS controls that relate to some or all applications are typically interdependent controls in that their operation is often essential to the effectiveness of CIS application controls.
b)
The auditor should consider how these general CIS controls affect the CIS applications significant to the audit.
c)
Control over input, processing, data files and output may be carried out by CIS personnel,by users of the system, by a separate control group, or may be programmed into application software.
d)
It may be more efficient to review the design of the application controls before reviewing the general controls.
105.
When programs or files can be accessed from terminals, users should be required to enter a(n)
a)
Self-diagnosis test.
b)
Parity check.
c)
Echo check.
d)
Personal identification code.
Reset
