wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

IS Audit - Mid Exam

Total questions: 50

Worksheet time: 3hrs 30mins

Name
Class
Date
1.

An internal audit function reports administratively to the CEO but functionally to the Audit Committee. The primary benefit is:

a)

Faster budget approvals for audit tools

b)

Stronger independence with oversight aligned to governance expectations

c)

Less interaction with executive management

d)

Reduced need for audit evidence

2.

Which set best reflects data/transaction control objectives across input–processing–output?

a)

Authentication, encryption, hashing

b)

Accuracy, completeness, authorization, and proper audit trail

c)

Efficiency, effectiveness, scalability

d)

Identification, classification, disposal

3.

An IS auditor reviews the control environment. Which observation most strongly indicates a healthy environment?

a)

Informal role descriptions to increase flexibility

b)

Documented structure with clear authority limits and SoD

c)

One super-user account for all administrators

d)

Ad-hoc policies maintained by teams

4.

In manual vs. automated systems, the risk most uniquely elevated in on-line, real-time processing is:

a)

Availability and concurrency control

b)

Optical character recognition error

c)

File label mismatch on tapes

d)

Misfiled paper vouchers

5.

The IS internal audit objective that most directly links to management assurance is to:

a)

Design and implement controls

b)

Express an opinion supported by sufficient, competent, relevant, and useful evidence

c)

Approve business strategies

d)

Negotiate vendor contracts

6.

Which pair most accurately matches preventive vs. detective application controls?

a)

Limit check vs. batch exception report

b)

Reconciliation vs. edit check

c)

After-the-fact approval vs. field validation

d)

Logging vs. encryption

7.

When compensating controls are acceptable, the auditor’s focus should be on:

a)

Whether the compensating control fully duplicates the original design

b)

Whether residual risk is reduced to an acceptable level and is sustainable

c)

Whether compensating control is cheaper

d)

Whether it is manual rather than automated

8.

In a risk-based IS audit plan, which factor most increases systems risk score?

a)

Highly stable system with low monetary throughput

b)

High monetary values, high confidentiality, and high impact of disruption

c)

Complex tech but zero regulatory exposure

d)

No external interfaces

9.

The strongest evidence of effective program change control in production is:

a)

Email approvals saved by the developer

b)

Digitally signed, system-enforced workflow logs with time-stamps and release gates

c)

A weekly release calendar alone

d)

A retrospective verbal sign-off

10.

In audit reporting, the section most likely read by senior executives and must emphasize risk/impact is the:

a)

Appendices

b)

Detailed findings

c)

Executive summary

d)

Formalities section

11.

Input controls that best ensure “once and only once” capture of transactions include:

a)

Range checks only

b)

Pre-numbering, control totals, and cancellation marks

c)

Encryption keys

d)

Color-coded forms

12.

For online update systems, the auditor’s primary concern versus batch is:

a)

Tape density

b)

Concurrency and integrity under multi-user conditions

c)

Printer alignment

d)

Microfilm storage

13.

A test data approach is least persuasive when:

a)

The program under test is not the live production version

b)

Both valid and invalid cases are used

c)

Population coverage is risk-focused

d)

Results are reconciled to expected edit routines

14.

Integrated Test Facility (ITF) provides strong assurance if and only if the auditor ensures:

a)

ITF transactions remain in production totals for realism

b)

ITF entities are segregated and purged from live results post-test

c)

Source code is rewritten by audit

d)

No user involvement in testing

15.

Parallel simulation is most useful when:

a)

The client cannot share data layouts

b)

The auditor can process the same input/data with an independent program and compare results

c)

Manual recalculation is prohibited

d)

The system is offline

16.

Snapshot techniques are preferred when the auditor needs to:

a)

Eliminate traceability

b)

Tag selected transactions and capture processing logic path for those items

c)

Disable edit checks temporarily

d)

Avoid data capture overhead

17.

Statistical sampling advantage over nonstatistical is primarily:

a)

Lower staff training requirements

b)

Quantified sampling risk and defensible confidence/precision

c)

Less documentation effort

d)

Guaranteed detection of fraud

18.

In attribute sampling, raising tolerable deviation while other parameters are constant will typically:

a)

Increase sample size

b)

Decrease sample size

c)

Not change sample size

d)

Eliminate sampling risk

19.

PPS (Dollar-Unit) sampling is especially suited to detect:

a)

Understatements in small items

b)

Overstatements in high-value items

c)

Control deviations

d)

Missing documents

20.

A 95% confidence level implies a reliability factor near:

a)

1.00

b)

1.64

c)

1.96–2.00 (context dependent)

d)

2.70–2.996

21.

In hardware risk and controls, which pairing is strongest?

a)

Theft ↔ carpet color

b)

Environmental failures ↔ UPS, AC, humidity control, surge protection, maintenance

c)

Disaster ↔ disable backups

d)

Vandalism ↔ open server rooms

22.

Operating system control weakness most critical to investigate first:

a)

Screensaver settings

b)

Excessive special privileges and weak password/rights management

c)

GUI theme

d)

Desktop icons

23.

Effective OS review typically includes:

a)

Ignoring licensing status

b)

Change controls for system libraries and parameter hardening with audit/logging

c)

Allowing universal write access to SYS libraries

d)

Skipping documentation checks

24.

In network architecture, a star topology’s key risk is:

a)

Every node has equal token access

b)

Central hub/switch as single point of failure

c)

Difficult cable runs

d)

Inability to add nodes

25.

A firewall is best described as:

a)

A replacement for anti-virus tools

b)

A choke-point enforcing network access policy and logging traffic that passes through

c)

A solution to malicious insiders

d)

Protection against all unknown, emerging threats by default

26.

A common Internet risk that policies and controls must address is:

a)

Guaranteed attribution of all remote users

b)

Unknown external actors and back-door paths

c)

Perfect confidentiality via SMTP alone

d)

Automatic compliance with data privacy

27.

For data centers, which control set is most fundamental?

a)

Posters and signage

b)

Physical access control, environmental protections, redundant power/links, and DRP

c)

Decorative server racks

d)

Floor carpeting

28.

The information criteria that concerns delivering relevant, correct, timely, consistent, usable, complete information is:

a)

Reliability

b)

Integrity

c)

Effectiveness

d)

Efficiency

29.

Confidentiality in COBIT’s criteria primarily addresses:

a)

Preventing unauthorized disclosure of sensitive information

b)

Ensuring information is timely

c)

Ensuring information is inexpensive

d)

Guaranteeing 100% uptime

30.

Which is not an IT resource per COBIT?

a)

Data

b)

People

c)

Facilities

d)

Equity capital structure

31.

Planning & Organization (PO) processes are most directly about:

a)

Incident handling and operations

b)

Strategic direction, information architecture, tech direction, project/quality/risk management

c)

Installing systems into production

d)

Independent assurance

32.

Acquisition & Implementation (AI) includes:

a)

Define service levels and manage capacity

b)

Identify automated solutions, acquire/maintain apps and tech, develop procedures, manage changes

c)

Monitor processes and obtain assurance

d)

Educate users and manage data

33.

Delivery & Support (DS) typically includes all except:

a)

Ensure continuous service and security

b)

Manage operations, facilities, configuration, incidents

c)

Define service levels and assist customers

d)

Install and accredit systems before go-live

34.

Monitoring (ME) encompasses:

a)

Portfolio management

b)

Independent assurance and control assessment over all domains

c)

Talent development

d)

Contract negotiation

35.

Which metric best indicates efficiency (vs. effectiveness)?

a)

Percentage of complete, correct outputs

b)

Cost per processed transaction at a target throughput

c)

Number of stakeholders satisfied

d)

Compliance rate with regulation

36.

ISACA/IIA Codes of Ethics most directly require auditors to:

a)

Maximize audit fees

b)

Act with integrity, objectivity, due care, and protect confidentiality

c)

Disclose proprietary data publicly if useful

d)

Avoid ongoing education

37.

In engagement planning, a realistic time budget should consider:

a)

Only fieldwork hours

b)

Leave, sickness, training, and administration overheads

c)

No allowance for unplanned work

d)

A fixed template for all audits

38.

A balanced audit report should include:

a)

Only negative findings

b)

Purpose, scope, results, opinion, recommendations, and management’s responses

c)

Raw logs only

d)

A single KPI chart

39.

Generalized Audit Software (GAS) is favored because it:

a)

Replaces all audit procedures

b)

Gives auditor direct control with lower development cost and rapid implementation

c)

Requires source code rewriting

d)

Eliminates documentation needs

40.

The primary objective of an annual IS audit plan built on risk assessment is to:

a)

Distribute hours equally across departments

b)

Allocate scarce audit resources to systems with the greatest risk

c)

Audit only new systems

d)

Avoid regulated areas to reduce complexity

41.

The control environment sets the conditions under which internal controls operate, including structure, policies, and external influences.

a)
True
b)
False
42.

Online systems shift primary control concerns from availability to completeness only.

a)
True
b)
False
43.

Integrated Test Facility can be risky if dummy entities contaminate production totals.

a)
True
b)
False
44.

Statistical sampling always produces smaller samples than nonstatistical methods.

a)
True
b)
False
45.

PPS (Dollar-Unit) sampling tends to select higher-value items and is strong for detecting overstatements.

a)
True
b)
False
46.

In OS reviews, weak privilege management and logging are more critical than GUI settings.

a)
True
b)
False
47.

A firewall can fully protect against malicious insiders and traffic that bypasses it.

a)
True
b)
False
48.

COBIT’s information criteria include effectiveness, efficiency, confidentiality, integrity, availability, compliance, and reliability.

a)
True
b)
False
49.

Delivery & Support domain typically includes managing incidents, configuration, and operations.

a)
True
b)
False
50.

The internal audit function’s role includes designing and implementing controls.

a)
True
b)
False