wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ENTPLAN 105

Total questions: 105

Worksheet time: 53mins

Name
Class
Date
1.

An IT environment requires the use of supercomputers in processing financial information to exist.

a)

TRUE

b)

FALSE

2.

The IT environment still exists even if it is being outsourced by the organization from a third-party vendor.

a)

TRUE

b)

FALSE

3.

The CPU cannot operate without the support of a solid-state memory known as random access memory (RAM).

a)

TRUE

b)

FALSE

4.

E-commerce allows the conduct of electronic business transactions over the public internet as compared to an electronic data interchange (EDI) that is a non-internet based private network.

a)

TRUE

b)

FALSE

5.

Application software are programs designed for specific purposes and may work independently without the operating system.

a)

TRUE

b)

FALSE

6.

One of the disadvantages of a database system is the lack of data synchronization which leads to multiple versions of the same file.


a)

TRUE

b)

FALSE

7.

Cloud accounting software offers greater flexibility to its users as financial information is hosted offline which is accessible through an internet browser.

a)

TRUE

b)

FALSE

8.

Under a complex IT environment, transactions are initiated and produced in an electronic format which results to physical visibility of transaction trails.

a)

TRUE

b)

FALSE

9.

Through Online or Real-time (OLRT) processing, a large volume of data collected over time is now processed at the same time.

a)

TRUE

b)

FALSE

10.

Due to the high level of complexity of IT environments of large organizations, reliance on complex IT controls is not adopted.

a)

TRUE

b)

FALSE

11.

For good internal control, programmers should not be given access to complete program documentation for the programs they work on.

a)

TRUE

b)

FALSE

12.

Distributive data processing eliminates the need for data security.

a)

TRUE

b)

FALSE

13.

Most advanced computer systems do not have audit trails.

a)

TRUE

b)

FALSE

14.

Auditors usually begin their consideration of IT systems with tests of application controls.

a)

TRUE

b)

FALSE

15.

Generalized audit software may be used for substantive tests or for tests of controls.

a)

TRUE

b)

FALSE

16.

Auditing around the computer is a more appropriate approach to audit simple IT environments.

a)

TRUE

b)

FALSE

17.

When evaluating IT controls, it is suggested to evaluate application controls first as these are vital to complete and accurate financial reporting.

a)

TRUE

b)

FALSE

18.

Monitoring the IT environment may executed either through predetermined performance measures or through separate evaluations.

a)

TRUE

b)

FALSE

19.

Data encryption secures information through an algorithm known as a cipher which converts data into characters unreadable by humans, called ciphertext.

a)

TRUE

b)

FALSE

20.

System software controls are IT application controls over the effective selection, acquisition, implementation, and maintenance of system software.

a)

TRUE

b)

FALSE

21.

Due to the rapid changes in the IT environment of entities, the overall objective and scope of the auditor also changed to address these advancements.


a)

TRUE

b)

FALSE

22.

The understanding required over a company's information system is confined to the aspects of such system relating to information disclosed in the financial statements which are found within the general and subsidiary ledgers.

a)

TRUE

b)

FALSE

23.

When the work of an IT specialist is required for purposes of the audit, the auditor shall assess the adequacy of such work and whether the specialist is competent, capable, and objective.

a)

TRUE

b)

FALSE

24.

Under the black-box approach, the internal structures or workings of the system are ignored.

a)

TRUE

b)

FALSE

25.

CAATs are widely used as they provide detailed analysis of system configurations and workings while saving time and cost.

a)

TRUE

b)

FALSE

26.

Test data utilizes the client system to process both valid and invalid transactions that allows the auditor to check if controls are functioning effectively.

a)

TRUE

b)

FALSE

27.

Parallel simulation uses the client system to process data prepared by the auditor for comparison to the auditor's expected outcome.

a)

TRUE

b)

FALSE

28.

System control audit review file (SCARF) are audit software modules in a host application system that allows for continuous monitoring and data collection stored in a special audit file called SCARF master files.

a)

TRUE

b)

FALSE

29.

Generalized audit software may be used to execute tests of controls over IT and manual controls but not for substantive testing.

a)

TRUE

b)

FALSE

30.

Expertise in the specific features and functions of computerized audit tools is required to effectively perform auditing with the computer.

a)

TRUE

b)

FALSE

31.

An IT environment least likely affects

a)

The procedures followed by the auditor in obtaining a sufficient understanding of the accounting and internal control systems.

b)

The consideration of inherent risk and control risk through which the auditor arrives at the risk assessment.

c)

The auditor's design and performance of tests of control and substantive procedures appropriate to meet the audit objective.

d)

The overall objective and scope of an audit.

32.

An IT environment

a)

Consists of the policies and procedures that the entity implements and the IT infrastructure (hardware, operating systems, etc.) and application software that it uses to support business operations and achieve business strategies.

b)

Exists when a computer of any type or size is involved in the processing by the entity of financial information of significance to the audit, whether that computer is operated by the entity or by a third party.

c)

Is the electronic transmission of documents between organizations in a machine-readable form.

d)

A communications network that serves users within a confined geographical area.

33.

Which of the following statements is not correct?

a)

The overall objective and scope of an audit do not change in an IT environment

b)

When computers or IT are introduced, the basic concept of evidence accumulation remains the same

c)

Most IT rely extensively on the same type of procedures for control that are used in manual processing system

d)

The specific methods appropriate for implementing the basic auditing concepts do not change, as systems become more complex

34.

Which of the following characteristics distinguishes computer processing from manual processing?

a)

Computer processing virtually eliminates the occurrence of computational error normally associated with manual processing.

b)

Errors or fraud in computer processing will be detected soon after their occurrences.

c)

The potential of systematic error is ordinarily greater in manual processing than in computerized processing.

d)

Most computer systems are designed so that transaction trails useful for audit purposes do not exist.

35.

The development of CIS will generally result in design and procedural characteristics that are different from those found in manual systems. These different design and procedural aspects of CIS include, except:

a)

Consistency of performance.

b)

Programmed control procedures.

c)

Vulnerability of data and program storage media

d)

Multiple transaction update of multiple computer files or databases.

36.

RIAN, Inc. recently switched from a manual accounting system to a computerized accounting system. The system supports online, real-time processing in a networked environment and six employees have been granted access to various parts of the system in order to perform their jobs. Relative to the manual system, ABC can expect to see:

a)

That functions that had previously been spread across employees have been combined.

b)

An increase in the incidence of clerical errors.

c)

A decrease in the incidence of systemic errors.

d)

A decrease in the need for access controls to the accounting records.

37.

A manufacturing company that wanted to be able to place material orders more efficiently most likely would utilize which of the following?

a)

Electronic check presentment

b)

Automated clearinghouse

c)

Electronic data interchange

d)

Electronic funds transfer

38.

Audit objectives in the Electronic Data Interchange (EDI) environment include all of the following except

a)

A complete audit trail of EDI transactions is maintained

b)

All EDI transactions are authorized

c)

Backup procedures are in place and functioning properly

d)

Unauthorized trading partners cannot gain access to database records

39.

What controls are designed to ensure that an organization's computer-based control environment is stable and well managed?

a)

General controls

b)

Detective controls

c)

Application controls

d)

Preventive controls

40.

General controls relate to all computer activities and application controls relate to specific tasks. General controls include

a)

Controls designed to assure that all data submitted for processing has been properly authorized

b)

Controls designed to assure the accuracy of the processing results

c)

Controls for documenting and approving software and changes to software

d)

Controls that relate to the correction and resubmission of data that were initially incorrect

41.

The primary objective of security software is to

a)

Control access to information system resources.

b)

Restrict access to prevent installation of unauthorized utility software.

c)

Detect the presence of viruses.

d)

Monitor the separation of duties within applications.

42.

Preventing someone with sufficient technical skill from circumventing security procedures and making changes to production programs is best accomplished by

a)

Reviewing report of jobs completed

b)

Comparing production programs with independently controlled copies

c)

Running test data periodically

d)

Providing suitable segregation of duties

43.

Which of the following is not a purpose of an auditor's attempt to understand internal control when a client processes accounting information by computer?

a)

Determine the extent to which the computer is used in significant accounting applications.

b)

Understand the flow of transactions in the system.

c)

Comprehend the basic structure of accounting control.

d)

Identify the controls that can be relied on when designing substantive tests of details.

44.

Which of the following is likely to be of least importance to an auditor when assessing control risk in a company that processes data by computer?

a)

The segregation of duties within the computer department.

b)

The control over source documents.

c)

The documentation maintained for accounting applications.

d)

The cost-benefit ratio of data processing operations.

45.

RIEL Corporation has numerous customers. A customer file is kept on disk. Each customer file contains the name, address, credit limit, and account balance. The auditor wishes to test this file to determine whether credit limits are being exceeded. The best procedure for the auditor to follow would be to

a)

Develop test data that would cause some account balances to exceed the credit limit and determine if the system properly detects such situations.

b)

Develop a program to compare credit limits with account balances and print out the details of any account with a balance exceeding its credit limit.

c)

Request a printout of all account balances so they can be manually checked against the credit limits.

d)

Request a printout of a sample of account balances so they can be individually checked against the credit limits.

46.

in considering a client's internal control structure in a computer environment, the auditor will encounter general controls and application controls. Which of the following is an application control? A. Organization charts. C. Systems flowcharts. B. Hash total. D. Control over program changes.

a)

Organization charts.

b)

Hash total.

c)

Systems flowcharts

d)

Control over program changes.

47.

MS Windows, Ubuntu and Mac OS are examples of A. Application software. C. Database management systems. B. Generalized audit software. D. Operating software.

a)

Application software.

b)

Generalized audit software.

c)

Database management systems.

d)

Operating software.

48.

When software or files can be accessed from on-line servers, users should be required to enter A. A parity check. C. A self-diagnosis test. B. A personal identification code. D. An echo check.

a)

A parity check.

b)

A personal identification code.

c)

A self-diagnosis test.

d)

An echo check.

49.

A control feature requires the computer to send signals to the printer to activate the print mechanism for each character. The print mechanism, just prior to printing, sends a signal back to the computer verifying that the proper print position has been activated. This type of hardware control is referred to as a/an

a)

Echo check.

b)

Validity check.

c)

Signal check.

d)

Check digit.

50.

Which of the following is a software component of a computer system?

a)

The operating system.

b)

The storage unit.

c)

The display monitor.

d)

The optical scanner.

51.

An example of an access control is a:

a)

Check digit.

b)

Password

c)

Test facility.

d)

Read only memory.

52.

End-user computing is most likely to occur on which of the following types of computers?

a)

Mainframe

b)

Macrocomputers.

c)

Personal computers

d)

Personal reference assistants

53.

If a control total were to be computed on each of the following data items, which would best be identified as a hash total for a payroll computer application?

a)

Net pay

b)

Department numbers

c)

Hours worked

d)

Total debits and total credit

54.

Online computer system uses workstation or terminals that are located either locally or at remote sites. There are two types of workstations: general purpose terminals and special purpose terminals. General purpose terminals include the following, except A. Basic keyboard and monitor C. Point of sale devices B. Intelligent terminal D. Personal computers

a)

Basic keyboard and monitor

b)

Intelligent terminal

c)

Point of sale devices

d)

Personal computers

55.

The grandfather-father-son approach to providing protection for important computer files is a concept that is most often found in

a)

On-line, real-time systems

b)

Punched-card systems

c)

Magnetic tape systems

d)

Magnetic drum systems

56.

What type of computer system is characterized by data that are assembled from more than one location and records that are updated immediately?

a)

Microcomputer system

b)

Minicomputer system

c)

Batch processing system

d)

On-line-real-time system

57.

A collection of data that is shared and used by a number of different users for different purposes.

a)

Database

b)

Information file

c)

Master file

d)

Transaction file

58.

It is a communication system that enables computer users to share computer equipment, application software, data and voice and video transmissions.

a)

Network

b)

File server

c)

Host

d)

Client

59.

Which of the following is least likely a characteristic of Wide Area Network (WAN)?

a)

Created to connect two or more geographically separated LANs.

b)

Typically involves one or more long-distance providers, such as a telephone company to provide the connections.

c)

WAN connections tend to be faster than LAN.

d)

Usually more expensive than LAN.

60.

Gateway is

a)

A hardware and software solution that enables communications between two dissimilar networking systems or protocols.

b)

A device that forwards frames based on destination addresses.

c)

A device that connects and passes packets between two network segments that use the same communication protocol.

d)

A device that regenerates and retransmits the signal on a network.

61.

An auditor would least likely use computer software to

a)

Prepare spreadsheets

b)

Access client data files

c)

Assess computer control risk

d)

Construct parallel simulations

62.

Which of the following would an auditor would most likely use in obtaining an understanding of internal control?

a)

Program listings

b)

Record counts

c)

Record layouts

d)

System flowcharts

63.

Which of the following is not a major reason for maintaining an audit trail for a computer system?

a)

Deterrent to fraud

b)

Monitoring purposes

c)

Analytical procedures

d)

Query answering

64.

When obtaining an understanding of the significance and complexity of the IT environment, the auditor may use automated tools and techniques. Examples of procedures that may be performed include (choose the exception): A. Perform risk assessment procedures on large volumes of data including for analysis, recalculations, reperformance or reconciliations. Perform analytical procedures. C. Observe or inspect, in particular assets, for example through the use of remote observation tools. D. Design of further audit procedures.

a)

Perform risk assessment procedures on large volumes of data including for analysis, recalculations, reperformance or reconciliations.

b)

Perform analytical procedures.

c)

Observe or inspect, in particular assets, for example through the use of remote observation tools.

d)

Design of further audit procedures.

65.

Evaluate the following clients as the approach you will take in understanding (or testing) the system: I. Airline company; system is always online II. Law firm; processing is by batch A. white box; white box C. brown box; white box B. black box; black box D. white box; black box

a)

white box; white box

b)

black box; black box

c)

brown box; white box

d)

white box; black box

66.

If the inherent risk due to information technology is high, which approach must an auditor undertake

a)

Auditing around the computer

b)

Auditing through the computer

c)

Auditing with the computer

d)

Auditing by the computer

67.

The primary objective of procedures performed to obtain an understanding of internal control is to provide an auditor with

a)

Evidential matter to use in reducing detection risk.

b)

Knowledge necessary to plan the audit.

c)

A basis from which to modify tests of controls.

d)

Information necessary to prepare flowcharts.

68.

Auditing by testing the input and output of a computer system-i.e., auditing "around" the computer-instead of the computer software itself will

a)

Not detect program errors that do not appear in the output sampled.

b)

Detect all program errors, regardless of the nature of the output.

c)

Provide the auditor with the same type of evidence.

d)

Not provide the auditor with confidence in the results of the auditing procedures.

69.

Which of the following statements most likely represents a disadvantage for an entity that maintains computer data files rather than manual files?

a)

It's usually more difficult to detect transposition errors.

b)

Transactions are usually authorized before they are executed and recorded.

c)

It's usually easier for unauthorized persons to access and alter the files.

d)

Random error is more common when similar transactions are processed in different ways.

70.

Which of the following statements best describes a weakness often associated with computers? A. Computer equipment is more subject to systems error than manual processing is subject to human error. B. Computer equipment processes and records similar transactions in a similar manner. C. Control activities for detecting invalid and unusual transactions are less effective than manual control activities. D. Functions that would normally be separated in a manual system are combined in a computer system.

a)

Computer equipment is more subject to systems error than manual processing is subject to human error.

b)

Computer equipment processes and records similar transactions in a similar manner.

c)

Control activities for detecting invalid and unusual transactions are less effective than manual control activities.

d)

Functions that would normally be separated in a manual system are combined in a computer system.

71.

Which of the following procedures would an entity most likely include in its disaster recovery plan?

a)

Convert all data from external formats to an internal company format.

b)

Maintain a program to prevent illegal activity.

c)

Develop an auxiliary power supply to provide uninterrupted electricity.

d)

Store duplicate copies of files in a location away from the computer center.

72.

Which of the following is a password security problem?

a)

Users are assigned passwords when accounts are created, but do not change them.

b)

Users have accounts on several systems with different passwords.

c)

Users copy their passwords on note paper, which is kept in their wallets.

d)

Users select passwords that are not listed in any online dictionary.

73.

Which of the following personnel is responsible for the proper functioning of the security features built into the operating system?

a)

The systems programmer.

b)

The application programmer.

c)

The computer operator.

d)

The telecommunications specialist.

74.

Which of the following computer related employees should not be allowed access to program listings of application programs?

a)

The systems analyst.

b)

The programmer.

c)

The operator.

d)

The librarian.

75.

15. Which of the following would the auditors consider to be a weakness in an IT system?

a)

Operators have access to terminals.

b)

Programmers are allowed access to the file library.

c)

Reprocessing of exceptions detected by the computer is handled by a data control group.

d)

More than one employee is present when the computer facility is in use.

76.

The advent of personal computers has resulted in a(n):

a)

Decentralization of data processing activities.

b)

Increased concern over the accuracy of computerized processing.

c)

Decrease in the number of local area networks.

d)

Increase for general computer control activities.

77.

Assume that an auditor estimated that 10,000 checks were issued during the accounting period. If an application control that performs a limit check for each check request is to be subjected to the auditor's test-data approach, the sample should include:

a)

Approximately 1,000 test items.

b)

A number of test items determined by the auditor to be sufficient under the circumstances.

c)

A number of test items determined by the auditor's reference to the appropriate sampling tables.

d)

One transaction.

78.

3. Accounting functions that are normally considered incompatible in a manual system are often combined by computer software. This necessitates an application control that prevents unapproved

a)

Access to the computer library.

b)

Revisions to existing software.

c)

Usage of software.

d)

Testing of modified software.

79.

An auditor's consideration of a company's computer control activities has disclosed the following four circumstances. Indicate which circumstance constitutes a significant deficiency in internal control.

a)

Computer operators do not have access to the complete software support documentation.

b)

Computer operators are closely supervised by programmers.

c)

Programmers are not authorized to operate computers.

d)

Only one generation of backup files is stored in an off-premises

80.

In a computer system, hardware controls are designed to A. Arrange data in a logical sequence for processing. B. Correct errors in software. C. Monitor and detect errors in source documents. D. Detect and control errors arising from use of equipment.

a)

Arrange data in a logical sequence for processing.

b)

Correct errors in software.

c)

Monitor and detect errors in source documents.

d)

Detect and control errors arising from use of equipment.

81.

Which of the following is an example of general computer control? A. Input validation checks. C. Operations manual. B. Control total. D. Generalized audit software.

a)

Input validation checks.

b)

Control total.

c)

Operations manual.

d)

Generalized audit software.

82.

Which of the following would be least likely to be considered a desirable attribute of a database management system?

a)

Data redundancy.

b)

Quick response to users' request for information.

c)

Control of users' identification numbers and passwords.

d)

Logging of terminal activity.

83.

General controls over IT systems are typically tested using:

a)

Generalized audit software.

b)

Observation, inspection, and inquiry.

c)

Program analysis techniques.

d)

Test data.

84.

Which of the following is not a distinctive characteristic of advanced IT systems?

a)

Data communication.

b)

Integrated database.

c)

Batch processing of transactions.

d)

Distributive data processing.

85.

The best method of achieving internal control over advanced IT systems is through the use of:

a)

Batch controls.

b)

Controls written into the computer system.

c)

Equipment controls.

d)

Documentation controls.

86.

In a client/server environment, the "client" is most likely to be the:

a)

Supplier of the computer system.

b)

Computers of various users.

c)

Computer that contains the networks software and provides services to a server.

d)

Database administrator.

87.

Auditing through the computer is most likely to be used when:

a)

Input transactions are batched and system logic is straightforward.

b)

Processing primarily consists of sorting the input data and updating the master file sequentially.

c)

Processing is primarily on line and updating is real-time.

d)

Outputs are in hard copy form.

88.

Which of the following computer system risks would be increased by the installation of a database system?

a)

Programming errors.

b)

Data entry errors.

c)

Improper data access.

d)

Loss of power.

89.

Auditing by testing the input and output of a computer system instead of the computer program itself will:

a)

Not detect program errors which do not show up in the output sampled.

b)

Detect all program errors, regardless of the nature of the output.

c)

Provide the auditors with the same type of evidence.

d)

Not provide the auditors with the confidence in the results of the auditing procedures.

90.

Which of the following is true of generalized audit software?

a)

They can be used only in auditing on-line computer systems.

b)

They can be used on any computer without modification.

c)

They each have their own characteristics, which the auditor must carefully consider before using in a given audit situation.

d)

They enable the auditor to perform all manual compliance test procedures less expensively.

91.

1. Evaluate the following statements related to parallel simulation:

I. Parallel simulation is less costly to perform compared to test data approach

II. Parallel simulation uses the client's system with fictitious transactions

a)

True, False

b)

False, True

c)

True, True

d)

False, False

92.

Which of the following is not an example of a computer-assisted audit technique?

a)

Integrated test data.

b)

Audit modules.

c)

Disk operating systems.

d)

Audit hooks.

93.

What encryption method is used when RSA and DES are used together? A. Data envelope C. Data packet B. Digital envelope D. Digital packet

a)

Data envelope

b)

Digital envelope

c)

Data packet

d)

Digital packet

94.

Which of the following methods of testing application controls utilizes software prepared by the auditors and applied to the client's data?

a)

Parallel simulation.

b)

Integrated test facility.

c)

Test data.

d)

Exception report tests.

95.

The test-data method is used by auditors to test the A. Accuracy of input data. B. Validity of the output. C. Procedures contained within the program. D. Normalcy of distribution of test data.

a)

Accuracy of input data.

b)

Validity of the output.

c)

Procedures contained within the program.

d)

Normalcy of distribution of test data.

96.

Which is true about test data approach?

a)

The test deck must include all possible scenarios, regardless of materiality

b)

The test deck must include scenarios of particular audit concern

c)

Base case system evaluation is not particularly useful when subsequent application changes are made

d)

No invalid date must be included in the test deck as this might the client's data integrity

97.

An auditor most likely would introduce test data into a computerized payroll system to test controls related to the A. Existence of unclaimed payroll checks held by supervisors. B. Early cashing of payroll checks by employees. C. Discovery of invalid employee I.D. numbers. D. Proper approval of overtime by supervisors.

a)

Existence of unclaimed payroll checks held by supervisors.

b)

Early cashing of payroll checks by employees.

c)

Discovery of invalid employee I.D. numbers.

d)

Proper approval of overtime by supervisors.

98.

Evaluate the following statements related to integrated test facility (ITF): I. IT audit modules can discriminate between ITF and production transactions Il. In IT dummy master files integrated with legitimate records A. True, False C. True, True B. False, True D. False, False

a)

True, False

b)

False, True

c)

True, True

d)

False, False

99.

The test-data method is used by auditors to test the

a)

Accuracy of input data.

b)

Validity of the output.

c)

Procedures contained within the program.

d)

Normalcy of distribution of test data.

100.

Parallel simulation programs used by the auditors for testing programs:

a)

Must simulate all functions of the production computer-application system.

b)

Cannot be developed with the aid of generalized audit software.

c)

Can use live data or test data.

d)

Is generally restricted to data base environments.

101.

Which of the following testing techniques is more commonly used by internal auditors than by independent auditors?

a)

Integrated test facilities.

b)

Test data.

c)

Controlled programs.

d)

Tagging and tracing transactions.

102.

Which of the following testing techniques minimizes the possibility that the auditors will contaminate a client's financial records?

a)

Test data.

b)

Integrated test facilities.

c)

Integrated test facilities.

d)

Tagging and tracing transactions.

103.

An auditor who wishes to capture an entity's data as transactions are processed and continuously test the entity's computerized information system most likely would use which of the following techniques?

a)

Snapshot application.

b)

Embedded audit module.

c)

Integrated data check.

d)

Test data generator.

104.

A log, usually created by an embedded audit module, used to collect information for subsequent review and analysis.

a)

Audit hooks

b)

Extended records

c)

Systems control audit review files

d)

Transaction tagging

105.

This technique in essence "takes a picture" of the status of program execution, intermediate results, or transaction data at specified processing points in the program processing. This technique helps an auditor to analyze the processing logic of specific programs

a)

Audit hooks

b)

Snapshot

c)

Systems control audit review files

d)

Transaction tagging