NEW
Font size
WorksheetsIS Audit - Mid Exam
Total questions: 50
Worksheet time: 3hrs 30mins
An internal audit function reports administratively to the CEO but functionally to the Audit Committee. The primary benefit is:
Faster budget approvals for audit tools
Stronger independence with oversight aligned to governance expectations
Less interaction with executive management
Reduced need for audit evidence
Which set best reflects data/transaction control objectives across input–processing–output?
Authentication, encryption, hashing
Accuracy, completeness, authorization, and proper audit trail
Efficiency, effectiveness, scalability
Identification, classification, disposal
An IS auditor reviews the control environment. Which observation most strongly indicates a healthy environment?
Informal role descriptions to increase flexibility
Documented structure with clear authority limits and SoD
One super-user account for all administrators
Ad-hoc policies maintained by teams
In manual vs. automated systems, the risk most uniquely elevated in on-line, real-time processing is:
Availability and concurrency control
Optical character recognition error
File label mismatch on tapes
Misfiled paper vouchers
The IS internal audit objective that most directly links to management assurance is to:
Design and implement controls
Express an opinion supported by sufficient, competent, relevant, and useful evidence
Approve business strategies
Negotiate vendor contracts
Which pair most accurately matches preventive vs. detective application controls?
Limit check vs. batch exception report
Reconciliation vs. edit check
After-the-fact approval vs. field validation
Logging vs. encryption
When compensating controls are acceptable, the auditor’s focus should be on:
Whether the compensating control fully duplicates the original design
Whether residual risk is reduced to an acceptable level and is sustainable
Whether compensating control is cheaper
Whether it is manual rather than automated
In a risk-based IS audit plan, which factor most increases systems risk score?
Highly stable system with low monetary throughput
High monetary values, high confidentiality, and high impact of disruption
Complex tech but zero regulatory exposure
No external interfaces
The strongest evidence of effective program change control in production is:
Email approvals saved by the developer
Digitally signed, system-enforced workflow logs with time-stamps and release gates
A weekly release calendar alone
A retrospective verbal sign-off
In audit reporting, the section most likely read by senior executives and must emphasize risk/impact is the:
Appendices
Detailed findings
Executive summary
Formalities section
Input controls that best ensure “once and only once” capture of transactions include:
Range checks only
Pre-numbering, control totals, and cancellation marks
Encryption keys
Color-coded forms
For online update systems, the auditor’s primary concern versus batch is:
Tape density
Concurrency and integrity under multi-user conditions
Printer alignment
Microfilm storage
A test data approach is least persuasive when:
The program under test is not the live production version
Both valid and invalid cases are used
Population coverage is risk-focused
Results are reconciled to expected edit routines
Integrated Test Facility (ITF) provides strong assurance if and only if the auditor ensures:
ITF transactions remain in production totals for realism
ITF entities are segregated and purged from live results post-test
Source code is rewritten by audit
No user involvement in testing
Parallel simulation is most useful when:
The client cannot share data layouts
The auditor can process the same input/data with an independent program and compare results
Manual recalculation is prohibited
The system is offline
Snapshot techniques are preferred when the auditor needs to:
Eliminate traceability
Tag selected transactions and capture processing logic path for those items
Disable edit checks temporarily
Avoid data capture overhead
Statistical sampling advantage over nonstatistical is primarily:
Lower staff training requirements
Quantified sampling risk and defensible confidence/precision
Less documentation effort
Guaranteed detection of fraud
In attribute sampling, raising tolerable deviation while other parameters are constant will typically:
Increase sample size
Decrease sample size
Not change sample size
Eliminate sampling risk
PPS (Dollar-Unit) sampling is especially suited to detect:
Understatements in small items
Overstatements in high-value items
Control deviations
Missing documents
A 95% confidence level implies a reliability factor near:
1.00
1.64
1.96–2.00 (context dependent)
2.70–2.996
In hardware risk and controls, which pairing is strongest?
Theft ↔ carpet color
Environmental failures ↔ UPS, AC, humidity control, surge protection, maintenance
Disaster ↔ disable backups
Vandalism ↔ open server rooms
Operating system control weakness most critical to investigate first:
Screensaver settings
Excessive special privileges and weak password/rights management
GUI theme
Desktop icons
Effective OS review typically includes:
Ignoring licensing status
Change controls for system libraries and parameter hardening with audit/logging
Allowing universal write access to SYS libraries
Skipping documentation checks
In network architecture, a star topology’s key risk is:
Every node has equal token access
Central hub/switch as single point of failure
Difficult cable runs
Inability to add nodes
A firewall is best described as:
A replacement for anti-virus tools
A choke-point enforcing network access policy and logging traffic that passes through
A solution to malicious insiders
Protection against all unknown, emerging threats by default
A common Internet risk that policies and controls must address is:
Guaranteed attribution of all remote users
Unknown external actors and back-door paths
Perfect confidentiality via SMTP alone
Automatic compliance with data privacy
For data centers, which control set is most fundamental?
Posters and signage
Physical access control, environmental protections, redundant power/links, and DRP
Decorative server racks
Floor carpeting
The information criteria that concerns delivering relevant, correct, timely, consistent, usable, complete information is:
Reliability
Integrity
Effectiveness
Efficiency
Confidentiality in COBIT’s criteria primarily addresses:
Preventing unauthorized disclosure of sensitive information
Ensuring information is timely
Ensuring information is inexpensive
Guaranteeing 100% uptime
Which is not an IT resource per COBIT?
Data
People
Facilities
Equity capital structure
Planning & Organization (PO) processes are most directly about:
Incident handling and operations
Strategic direction, information architecture, tech direction, project/quality/risk management
Installing systems into production
Independent assurance
Acquisition & Implementation (AI) includes:
Define service levels and manage capacity
Identify automated solutions, acquire/maintain apps and tech, develop procedures, manage changes
Monitor processes and obtain assurance
Educate users and manage data
Delivery & Support (DS) typically includes all except:
Ensure continuous service and security
Manage operations, facilities, configuration, incidents
Define service levels and assist customers
Install and accredit systems before go-live
Monitoring (ME) encompasses:
Portfolio management
Independent assurance and control assessment over all domains
Talent development
Contract negotiation
Which metric best indicates efficiency (vs. effectiveness)?
Percentage of complete, correct outputs
Cost per processed transaction at a target throughput
Number of stakeholders satisfied
Compliance rate with regulation
ISACA/IIA Codes of Ethics most directly require auditors to:
Maximize audit fees
Act with integrity, objectivity, due care, and protect confidentiality
Disclose proprietary data publicly if useful
Avoid ongoing education
In engagement planning, a realistic time budget should consider:
Only fieldwork hours
Leave, sickness, training, and administration overheads
No allowance for unplanned work
A fixed template for all audits
A balanced audit report should include:
Only negative findings
Purpose, scope, results, opinion, recommendations, and management’s responses
Raw logs only
A single KPI chart
Generalized Audit Software (GAS) is favored because it:
Replaces all audit procedures
Gives auditor direct control with lower development cost and rapid implementation
Requires source code rewriting
Eliminates documentation needs
The primary objective of an annual IS audit plan built on risk assessment is to:
Distribute hours equally across departments
Allocate scarce audit resources to systems with the greatest risk
Audit only new systems
Avoid regulated areas to reduce complexity
The control environment sets the conditions under which internal controls operate, including structure, policies, and external influences.
Online systems shift primary control concerns from availability to completeness only.
Integrated Test Facility can be risky if dummy entities contaminate production totals.
Statistical sampling always produces smaller samples than nonstatistical methods.
PPS (Dollar-Unit) sampling tends to select higher-value items and is strong for detecting overstatements.
In OS reviews, weak privilege management and logging are more critical than GUI settings.
A firewall can fully protect against malicious insiders and traffic that bypasses it.
COBIT’s information criteria include effectiveness, efficiency, confidentiality, integrity, availability, compliance, and reliability.
Delivery & Support domain typically includes managing incidents, configuration, and operations.
The internal audit function’s role includes designing and implementing controls.
