wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

IT General Controls - Set A

Total questions: 25

Worksheet time: 33mins

Name
Class
Date
1.

1.     These are vital for safeguarding information systems and ensuring data integrity and security.

a)

a)    Network segmentation

b)

b)    Network authentication

c)

c)    Security controls

d)

d)    IT general controls

2.

2.     Which of the following actions would NOT be considered a preventive IT control?

a)

a)    User password complexity requirements

b)

b)    Antivirus software installation

c)

c)    System vulnerability scanning

d)

d)    Conducting system audits after an incident

3.

3.     It involves real-time tracking of system activities and configurations to detect anomalies and ensure compliance with security policies.

a)

a)    Checking

b)

b)    Continuous monitoring

c)

c)    Compliance assurance

d)

d)    SOC 2

4.

4.     It is performed to evaluate the effectiveness of internal controls and pinpoint areas where processes can be improved.

a)

a)    Authentication

b)

b)    Monitoring

c)

c)    Audit

d)

d)    Cross-checking

5.

5.     Which of the following is a key factor in ensuring the effectiveness of IT General Controls?

a)

a)    Allowing users to make changes to system settings without approval

b)

b)    Constant software updates

c)

c)    Clear communication of policies and procedures to all employees

d)

d)    Giving all users full access to company data

6.

6.     It is essential for safeguarding data against loss and ensuring rapid recovery in the event of incidents.

a)

a)    Data Follow-Up and Recovery

b)

b)    Data Restoration

c)

c)    Data Backup and Recovery

d)

d)    Data Protection

7.

7.     Which statement/s is/are incorrect?

I. All changes should be documented and tracked to ensure accountability.

II. Implementing a structured change management process helps organizations effectively manage change while maximizing risks.

III. A strong change management process protects organizations from potential security vulnerabilities that could emerge during transitions.

IV. Approval processes ensure that only necessary and unauthorized changes are implemented.

a)

a)    II, III, and IV

b)

b)    II and IV

c)

c)    I, II, and III

d)

d)    III and IV

8.

8.     _____________________ involves verifying the identity of users attempting to access systems, while _____________________ ensures they have the necessary permissions. Effective methods include passwords, biometrics, and multi-factor authentication.

a)

a)    User authorization; authentication

b)

b)    Access control; authentication

c)

c)    Authorization; user authentication

d)

d)    User authentication; authorization

9.

9.     Which of the following best describes the concept of "data integrity" in an IT system?

a)

a)    Preventing unauthorized access to confidential data

b)

b)    Ensuring that data is complete, accurate, and consistent over its lifecycle

c)

c)    Encrypting all sensitive data

d)

d)    Monitoring for suspicious activities

10.

10.     Which of the following is NOT a typical responsibility of an IT department when implementing general controls?

a)

a)    Establishing and enforcing system security policies

b)

b)    Managing user accounts and permissions

c)

c)    Conducting financial audits for internal controls

d)

d)    Ensuring the system remains available and resilient to threats

11.

11.     Which of the following is NOT typically part of IT General Controls?

a)

a)    Access control

b)

b)    Backup procedures

c)

c)    User training

d)

d)    Data encryption

12.

12.     Which statement/s is/are incorrect?

I. IT general controls ensure the accuracy and reliability of data by implementing frail management policies.

II. By implementing IT general controls, organizations can effectively minimize potential risks associated with data breaches and compliance.

III. Change management controls assist in overseeing modifications to IT systems and processes, reducing the risks linked to those changes.

IV. Access controls are crucial for managing who can access or utilize resources within an IT environment, ensuring sensitive information remains secure.

a)

a)    I and IV

b)

b)    II and III

c)

c)    I, II, and III

d)

d)    I and II

13.

13.     Which of the following is/are an example/s of authentication methods used to ensure security in IT General Controls?

a)

a)    Control authentication

b)

b)    Policy authentication

c)

c)    Token-based authentication

d)

c)    Access Control

14.

14.     The change management process involves:

a)

a)    strategizing, testing, and authorizing changes to IT systems to minimize disruptions and maintain compliance with security protocols

b)

b)    testing, planning, and approving changes to IT systems to minimize disruption and ensure compliance with security standards.

c)

c)    scoping and approving changes to IT systems to minimize disruption and ensure compliance with security standards.

d)

d)    planning and testing changes to IT systems to minimize disruptions and maintain compliance with security protocols

15.

15.     Which of the following is true about access controls in ITGC?

a)

a)    Access controls are only needed for applications, not for operating systems

b)

b)    Access controls ensure that users have the appropriate level of access to data and systems

c)

c)    Access controls should only be applied after a data breach has occurred

d)

d)    Access controls are not necessary if encryption is used

16.

16.     What is the importance of data backup?

a)

a)    Data retrieval

b)

b)    Business resilience

c)

c)    Security measures

d)

d)    A, B, and C

e)

e)    A and B

17.

17.     What is the key goal of disaster recovery planning under ITGC?

a)

a)    To ensure that employees know how to operate backup systems

b)

b)    To ensure the company can restore its IT systems and data in the event of a disaster

c)

c)    To eliminate all physical threats to IT systems

d)

d)    To upgrade hardware systems during non-peak hours

18.

18.     The System Development Lifecycle (SDLC) includes several key phases. What are those?

a)

a)    analysis, planning, design, development, testing, and deployment

b)

b)    planning, analysis, design, testing, development, and deployment

c)

c)    planning, analysis, design, testing, and deployment

d)

d)    planning, analysis, design, development, testing, and deployment

19.

19.     Which of the following would be part of an organization's ITGC framework for ensuring confidentiality?

a)

a)    Implementing end-to-end encryption for sensitive communications

b)

b)    Providing full system access to all employees

c)

c)    Ignoring external threats and focusing only on internal controls

d)

d)    Limiting network traffic to ensure no downtime

20.

20.     It is essential to identify potential vulnerabilities in software development.

a)

a)    Security Testing

b)

b)    Conducting Risk Assessments

c)

c)    Secure Coding Practices

d)

d)    Security Development

21.

21.     What is the purpose of the segregation of duties in IT General Controls?

a)

a)    To ensure that there is clear documentation of system configurations

b)

b)    To ensure no one person has the authority to perform conflicting functions, minimizing the risk of fraud

c)

c)    To provide training to users on system usage

d)

d)    To set up automated reports for auditing

22.

22.     Which of the following best describes the concept of “logical security” in ITGC?

a)

a)    Implementing physical barriers to protect IT infrastructure

b)

b)    Establishing procedures for data backup

c)

c)    Securing data and systems through passwords, encryption, and access controls

d)

d)    Monitoring physical security of server rooms

23.

23.     In IT General Controls, “physical security” refers to:

a)

a)    The encryption of sensitive data

b)

b)    The protection of IT infrastructure from physical threats such as fire, theft, or natural disasters

c)

c)    The management of user passwords

d)

d)    The protection of electronic communication between devices

24.

24.     Which of the following is a key component of IT General Controls related to change management?

a)

a)    Ensuring no software updates are applied without proper testing and authorization

b)

b)    Allowing all employees to access administrative systems

c)

c)    Maintaining detailed user manuals for all software

d)

d)    Automatically backing up all data every hour

25.

25.     In ITGC, what is the purpose of a “user access review”?

a)

a)    To check if employees are following security policies

b)

b)    To ensure that employees have the appropriate access levels and privileges based on their roles

c)

c)    To identify which users need additional training on software

d)

d)    To test if users are correctly using system passwords