Worksheetsauauua
Total questions: 77
Worksheet time: 39mins
Controls which are designed to assure that the information processed by the computer is authorized, complete, and accurate are called:
input controls.
output controls.
processing controls
general controls.
A numerical field appended to an identification number that serves as an input control is a(n)
Hash total.
Valid character test.
Batch total.
Check digit.
Which statement is incorrect regarding the review of general CIS controls and CIS application controls?
Control over input, processing, data files and output may be carried out by CIS personnel,by users of the system, by a separate control group, or may be programmed into application software.
General CIS controls that relate to some or all applications are typically interdependent controls in that their operation is often essential to the effectiveness of CIS application controls.
The auditor should consider how these general CIS controls affect the CIS applications significant to the audit.
It may be more efficient to review the design of the application controls before reviewing the general controls.
Which of the following methods of testing application controls utilizes a generalized audit software package prepared by the auditors?
Parallel simulation.
Integrated testing facility approach.
Exception report tests.
Test data approach.
Effective internal control over purchases generally can be achieved in a well-planned organizational structure with a separate purchasing department that has
the ability to prepare payment vouchers based on the information of on a vendor's invoice
the authority to make purchases of requisitioned materials and services
a direct reporting responsibility to the controller of the organization
the responsibility of reviewing purchase orders issued by user departments
the ability to prepare payment vouchers based on the information of on a vendor's invoice
Which of the following is not normally a removable storage media?
Tapes
Diskettes
Hard disk
Compact disk
Which of the following computer-assisted auditing techniques allows fictitious and real transactions to be processed together without client operating personnel being aware of the testing process?
Input controls matrix.
Integrated test facility.
Data entry monitor.
Parallel simulation.
Dominic Corp. has changed from a system of recording time worked on clock cards to a computerized payroll system in which employees record time in and out with magnetic cards. The computer system automatically updates all payroll records. Because of this change
The potential for payroll-related fraud is diminished.
Part of the audit trail is altered.
Transactions must be processed in batches.
A generalized computer audit program must be used.
Audit teams cannot test the reliable operation of computer control procedures by submitting test data at several different times for processing on the computer program the client uses for actual transaction processing.
Programming a model transaction processing system and processing actual client transactions for comparison to the output produced by theclient's program.
Submitting test data at several different times for processing on the computer program the client uses for actual transaction processing.
Manually comparing detailed transactions that the internal auditors used to test a program to the program's actual error messages.
Manually reperforming actual transaction processing with comparison of results to the actual system output.
Which of the following statements related to application controls is correct?
Application controls relate to the processing of individual transactions.
Application controls relate to all aspects of the IT function.
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
After the preliminary phase of the review of a client’s computer controls, an auditor may decide not to perform tests of controls related to the controls within the computer portion of the client’s internal control. Which of the following would not be a valid reason for choosing to omit such tests?
The time and dollar costs of testing exceed the time and dollar savings in substantive testing if the tests of controls show the controls to be operative.
The controls duplicate operative controls existing elsewhere in the structure.
There appear to be major weaknesses that would preclude reliance on the stated procedure.
The controls appear adequate.
Which of the following is not a benefit of using IT-based controls?
Ability to process large volumes of transactions.
Ability to replace manual controls with computer-based controls.
Over-reliance on computer-generated reports.
Reduction in misstatements due to consistent processing of transactions.
An entity has the following invoices in a batch:
Invoice # Product Quantity Unit price
201 F10 150 $5.00
202 G15 200 $10.00
203 H20 250 $25.00
204 K35 300 $30.00
Which of the following numbers represents the record count?
900
1
810
4
Which of the following statements regarding auditor documentation of the client's system of internal control is correct?
No one particular form of documentation is necessary, and the extent of documentation may vary.
Documentation must include flowcharts
Documentation must include procedural write-ups
No documentation is necessary although it is desirable.
Dalgona Corporation’s organization chart provides for a controller and an EDP manager, both of whom report to the financial vice-president. Internal control would not be strengthened by
Rotating periodically among machine operators the assignments of individual application run.
Providing for maintenance of input data controls by an independent control group which reports to the controller.
Providing for review and distribution of computer output by an independent control group which reports to the controller.
Assigning the programming and operating of the computer to an independent control group which reports to the controller.
An auditor most likely would introduce test data into a computerized payroll system to test internal controls related to the
Proper approval of overtime by supervisors.
Early cashing of payroll checks by employees.
Existence of unclaimed payroll checks held by supervisors.
Discovery of invalid employee I.D. numbers.
Which of the following is correct concerning batch processing of transactions?
It is more likely to result in an easy-to-follow audit trail than is online transaction processing.
It has largely been replaced by online real-time processing in all but legacy systems.
Transactions are processed in the order they occur, regardless of type.
It is used only in non-database applications.
When an auditor tests a computerized accounting system, which of the following is true of the test data approach?
Test data are processed by the client’s computer programs under the auditor’s control.
The program tested is different from the program used throughout the year by the client.
Several transactions of each type must be tested.
Test data must consist of all possible valid and invalid conditions.
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses an EDP system is that the auditor may:
Access information stored on computer files while having a limited understanding of the client's hardware and software features.
Substantiate the accuracy of data through self-checking digits and hash totals.
Reduce the level of required tests of controls to a relatively small amount.
Consider increasing the use of substantive tests of transactions in place of analytical procedures.
Which of the following strategies would a CPA most likely consider in auditing an entity that processes most of its financial data only in electronic form, such as a paperless system?
Continuous monitoring and analysis of transaction processing with an embedded audit module.
Extensive testing of firewall boundaries that restrict the recording of outside network traffic.
Verification of encrypted digital certificates used to monitor the authorization of transactions.
Increased reliance on internal control activities that emphasize the segregation of duties.
S1: “Auditing around the computer” is acceptable only if the auditor has access to the client’s data in a machine-readable language.
S2: “Auditing around the computer” is most appropriate when the client has not maintained detailed output or source documents in a form readable by humans.
False, False
True, False
False, True
True, True
When using the test data approach:
select data may remain in the client system after testing.
application programs tested must be virtually identical to those used by employees.
none of the above statements is correct.
test data should include only exception conditions.
Which of the following is not an appropriate statement with regard to computer control activities?
Specific passwords should be required to access online files.
Computer programmers should be periodically rotated across different applications.
Computer operators should maintain control of all software programs.
The duties of application programming, computer operation, and control of data files should be separated.
Which of the following is least likely to be considered by an auditor considering engagement of an information technology (IT) specialist on an audit?
Client’s use of emerging technologies.
Extent of entity’s participation in electronic commerce.
Requirements to assess going concern status.
Complexity of client’s systems and IT controls.
Computer systems are typically supported by a variety of utility software packages that are important to an auditor because they
Are written specifically to enable auditors to extract and sort data.
Are very versatile programs that can be used on hardware of many manufacturers.
May enable unauthorized changes to data files if not properly controlled.
May be significant components of a client’s application programs.
A customer intended to order 100 units of product CPA1022 but incorrectly ordered product CPA1023, which is not an actual product. Which of the following controls most likely would detect this error?
Redundant data check.
Check digit verification/ Validity check.
Hash total.
Record count.
Which of the following computer-assisted auditing techniques processes client input data on a controlled program under the auditor’s control to test controls in the computer system?
Review of program logic.
Parallel simulation.
Test data.
Integrated test facility.
An auditor would most likely be concerned with which of the following controls in a distributed data processing system?
Access controls.
Systems documentation controls.
Disaster recovery controls.
Hardware controls.
CIS application controls include, except
Controls over processing and computer data files.
Controls over output.
Controls over input.
Monitoring controls.
Which of the following procedures most likely would not be an internal control procedure designed to reduce the risk of errors in the billing process?
Comparing control totals for shipping documents with corresponding totals for sales invoices
Reconciling the control totals for sales invoices with the accounts receivable subsidiary ledger.
Using computer programmed controls on the pricing and mathematical accuracy of sales invoices
Matching shipping documents with approved sales orders before invoice preparation.
Which of the following is not a major difference between a manual processing environment and a computerized processing environment?
Random errors are more likely in a manual processing environment than a computerized processing environment.
A computerized processing environment has an increased level of human involvement.
A computerized processing environment requires data to be converted into electronic format, which introduces the possibility of input errors.
A hard copy "audit trail" is less likely to exist in a computerized processing environment than a manual processing environment.
A weakness in internal control over according retirement of equipment may cause an auditor to
selects certain items of equipment from the accounting records and locate them in the plant
inspects certain items of equipment in the plant and trace those items to the accounting records
trace additions to the other assets account to search for equipment that is still on hand but no longer being used
reviews the subsidiary ledger to ascertain whether depreciation was taken on each item of equipment during the year
Talaga Sharmaine Co. uses an online sales order processing system to process its sales transactions. Talaga Sharmaine's sales data are electronically sorted and subjected to edit checks. A direct output of the edit checks most likely would be a
File of all rejected sales transactions.
Report of all missing sales invoices.
Printout of all user code numbers and passwords.
List of all voided shipping documents.
Internal control over cash receipts is weakened when an employee who receives customer mail receipts also
Records credit to individual accounts receivable
Maintains a petty cash fund
Prepares bank deposit slips for all mail receipts
Prepares initial cash receipts record
Which of the following is not an application control?
Post-processing review of sales transactions by the sales department.
Reasonableness test for unit selling price of sale.
Separation of duties between computer programmer and operators.
Preprocessing authorization of sales transactions.
System characteristics that may result from the nature of CIS processing include, except
Lack of visible transaction trail.
Lack of visible output.
Absence of input documents.
Difficulty of access to data and computer programs.
Which of the following control procedures most likely could prevent computer personnel from modifying programs to bypass computer controls?
Separation of duties for computer programming and computer operations.
Periodic management review of computer utilization reports and systems documentation.
Participation of user department personnel in designing and approving new systems.
Physical security of computer facilities in limiting access to computer equipment.
Erica Kaye Corp. has changed from a system of recording time worked on clock cards to a computerized payroll system in which employees’ record time in and out with magnetic cards. The computer system automatically updates all payroll records. Because of this change
Transactions must be processed in batches.
Part of the audit trail is altered.
A generalized computer audit program must be used.
The potential for payroll-related fraud is diminished.
A primary advantage of using generalized audit software packages to audit the financial statements of a client that uses a computer system is that the auditor may
Access information stored on computer files while having a limited understanding of the client’s hardware and software features.
Reduce the level of required tests of controls to a relatively small amount.
Substantiate the accuracy of data through self checking digits and hash totals.
Consider increasing the use of substantive tests of transactions in place of analytical procedures.
An advantage of using systems flowcharts to document information about internal control instead of using internal control questionnaires is that systems flowcharts
Indicate whether control procedures are operating effectively.
Reduce the need to observe clients’ employees performing routine tasks.
Provide a visual depiction of clients’ activities.
Identify internal control weaknesses more prominently.
S1: The test data approach requires the auditor to insert an audit module in the client’s application system to test transaction data specifically identified by the auditor as unusual.
S2: General controls in smaller companies are usually less effective than in more complex IT environments.
True, False
False, False
False, True
True, True
S1: Firewalls can protect company data and software programs.
S2: Programmers should have access to transaction data.
False, False
False, True
True, True
True, False
An organization performs a daily backup of critical data and software files and stores the backup tapes at an offsite location. The backup tapes are used to restore the files in case of a disruption. This is an example of a:
corrective control.
management control.
detective control
preventive control.
An auditor would be most likely to assess control risk at the maximum level in an electronic environment with automated system-generated information when
Fixed asset transactions are few in number, but large in dollar amount.
Sales orders are initiated using predetermined, automated decision rules.
Accounts receivable records are based on many transactions and are large in dollar amount.
Payables are based on many transactions and large in dollar amount.
Controls which apply to a specific element of the system are called:
user controls.
general controls.
applications controls.
systems controls.
Which of the following client information technology (IT) systems generally can be audited without examining or directly testing the IT computer programs of the system?
A system that affects a number of essential master files and produces a limited output.
A system that updates a few essential master files and produces no printed output other than final balances.
A system that performs relatively complicated processing and produces very little detailed output.
A system that performs relatively uncomplicated processes and produces detailed output.
Which of the following statements related to application controls is correct?
Application controls relate to all aspects of the IT function.
Application controls relate to various aspects of the IT function including physical security and the processing of transactions in various cycles.
Application controls relate to various aspects of the IT function including software acquisition and the processing of transactions.
Application controls relate to the processing of individual transactions.
A collection of data that is shared and used by a number of different users for different purposes.
Transaction file
Database
Master file
Information file
To obtain evidence that user identification and password controls are functioning as designed, an auditor would most likely
Write a computer program that simulates the logic of the client’s access control software.
Examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
Extract a random sample of processed transactions were appropriately authorized.
Attempt to sign-on to the system using invalid user identifications and passwords.
Which of the following is not a major reason for maintaining an audit trail for a computer system?
Analytical procedures.
Monitoring purposes.
Query answering.
Deterrent to fraud.
Which documentation is required for an audit in accordance with generally accepted auditing standards?
A flowchart or an internal control questionnaire that evaluates the effectiveness of the entity’s controls.
The basis for the auditor’s conclusions when the assessed level of control risk is at the maximum level for all financial statement assertions.
An indication in the working papers that the accounting records agree or reconcile with the financial statements.
A client engagement letter that provides details of timing of each significant audit procedure and personnel performing that procedure.
An auditor can use a generalized computer audit program to verify the accuracy of
Account classifications.
Data processing controls.
Totals and sub-totals.
Accounting estimates.
Auditing by testing the input and output of a computer system instead of the computer program itself will
Provide the auditor with the same type of evidence as tests of application controls.
Detect all program errors, regardless of the nature of the output.
Not detect program errors which do not show up in the output sampled.
Not provide the auditor with confidence in the results of the auditing procedures.
An auditor who is testing EDP controls in a payroll system would most likely use test data that contain conditions such as
Overtime not approved by supervisors.
Payroll checks with unauthorized signatures.
Deductions not authorized by employees.
Time tickets with invalid job numbers.
Which of the following is not a major reason why an accounting audit trail should be maintained for a computer system?
Deterrent to irregularities.
Query answering.
Monitoring purposes.
Analytical procedures.
Which of the following is not among the errors that an auditor might include in the test data when auditing a client’s computer system?
Differences in description of units of measure.
Illogical entries in fields whose logic is tested by programmed consistency checks.
Authorized code.
Numeric characters in alphanumeric fields.
Rocelle Corporation has numerous customers. A customer file is kept on disk storage. Each customer file contains name, address, credit limit, and account balance. The auditor wishes to test this file to determine whether credit limits are being exceeded. The best procedure for the auditor to follow would be to
Develop test data that would cause some account balances to exceed the credit limit and determine if the system properly detects such situations.
Request a printout of a sample of account balances so they can be individually checked against the credit limits.
Develop a program to compare credit limits with account balances and print out the details of any account with a balance exceeding its credit limit.
Request a printout of all account balances so they can be manually checked against the credit limits.
An audit team's approach to evaluating computerized processing systems that compares source documents to the computer output is known as auditing
Around the computer.
With the computer.
Through the computer.
Without the computer.
To obtain evidence that user identification and password control procedures are functioning as designed, an auditor would most likely
Attempt to sign on to the system using invalid user identifications and passwords.
Extract a random sample of processed transactions and ensure that the transactions were appropriately authorized.
Write a computer program that simulates the logic of the client’s access control software.
Examine statements signed by employees stating that they have not divulged their user identifications and passwords to any other person.
When using test data, why are audit teams required to prepare only one transaction to test each computer processing alternative?
The speed and efficiency of the computer results in reduced sample sizes.
In a computerized processing environment, each transaction is handled in an identical manner.
Audit teams generally perform more extensive substantive testing in a computerized processing environment, resulting in less need to test processing controls.
The risk of misstatement is typically lower in a computerized processing environment.
Application controls vary across the IT system. To gain an understanding of internal control for a private company, the auditor must evaluate the application controls for every:
every material audit area.
every audit area in which the client uses the computer.
every audit area.
every audit area where the auditor plans to reduce assessed control risk.
Which of the following would be least likely to be included in an auditor's tests of controls?
observation
inquiry
confirmation
inspection
An auditor most likely would test for the presence of unauthorized computer program changes by running a
Source code comparison program.
Program that computes control totals.
Check digit verification program.
Program with test data.
______ controls prevent and detect errors while transaction data are processed.
Processing
Transaction
Software
Application
A control that relates to all parts of the IT system is called a(n):
systems control.
universal control.
applications control.
general control.
An example of an internal control weakness is to assign to a department supervisor the responsibility for
initiating request for salary adjustments for subordinate employees
distributing payroll checks to subordinate employees
reviewing and approving time reports for subordinate employees
authorizing payroll checks for terminated employees
Using laptop computers in auditing may affect the methods used to review the work of staff assistants because
Working paper documentation may not contain readily observable details of calculations.
Documenting the supervisory review may require assistance of consulting services personnel.
The generally accepted auditing standards may differ.
Supervisory personnel may not have an understanding of the capabilities and limitations of laptops.
Auditors usually obtain information about general and application controls through:
examination of systems documentation.
reading program change requests.
all of the methods.
interviews with IT personnel.
In creating lead schedules for an audit engagement, a CPA often uses automated workpaper software. What client information is needed to begin this process?
General ledger information such as account numbers, prior year account balances, and current year unadjusted information.
Interim financial information such as third quarter sales, net income, and inventory and receivables balances.
Adjusting entry information such as deferrals and accruals, and reclassification journal entries.
Specialized journal information such as the invoice and purchase order numbers of the last few sales and purchases of the year.
In a properly designed internal control system, the same employee most likely would much vendor’s invoices with receiving reports and also
posts the detailed accounts payable records
canceled vendor’s invoices after payment
reconciles the accounts payable ledger
compute the calculations and vendors' invoices
Auditors often make use of computer programs that perform routine processing functions such as sorting and merging. These programs are made available by electronic data processing companies and others and are specifically referred to as
Compiler programs.
Utility programs.
Supervisory programs.
User programs.
An auditor anticipates assessing control risk at a low level in a computerized environment. Under these circumstances, on which of the following activities would the auditor initially focus?
Output control activities.
Programmed control activities.
General control activities.
Application control activities.
An auditor most likely would test for the presence of unauthorized EDP program changes by running a
Source code comparison program.
Program that computes control totals.
Program with test data.
Check digit verification program.
An auditor who wishes to capture an entity’s data as transactions are processed and continuously test the entity’s computerized information system most likely would use which of the following techniques?
Integrated data check.
Embedded audit module.
Snapshot application.
Test data generator.
In a properly designed internal control system, the same employee most likely would much vendor’s invoices with receiving reports and also
canceled vendor’s invoices after payment
reconciles the accounts payable ledger
compute the calculations and vendors' invoices
posts the detailed accounts payable records
Which of the following is not a general control?
Processing controls.
Procedures for documenting, reviewing, and approving systems and programs.
The plan of organization and operation of IT activity.
Hardware controls.
Squid Game Corporation has just completely computerized its billing and accounts receivable recordkeeping. You want to make maximum use of the new computer in your audit of Squid Game Corporation. Which of the following audit techniques could not be performed through a computer program?
Resolving differences reported by customers on confirmation requests.
Tracing audited cash receipts to accounts receivable credits.
Examining sales invoices for completeness, consistency between different items, valid conditions and reasonable mounts.
Selecting on a random number basis accounts to be confirmed.
