wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

audit

Total questions: 110

Worksheet time: 6hrs 30mins

Name
Class
Date
1.

Which situation poses the GREATEST risk in Change Management?

a)

Delays in approving low-risk changes

b)

Developers have ability to migrate code to production.

c)

Separate environments maintained for testing

d)

Weekly CAB meetings are held

2.

What is the MOST effective control to ensure completeness of data transferred through an API interface?

a)

Manual reconciliation

b)

Checksum validation for each message batch

c)

Archiving API logs monthly

d)

Internal memo confirmation from system owner

3.

Which BEST describes a preventive access control?

a)

Daily review of audit logs

b)

MFA requirement for privileged access

c)

Monthly SoD analysis

d)

Exception reporting

4.

What is the PRIMARY benefit of a formal configuration baseline?

a)

It reduces the number of user requests

b)

It ensures deviations from approved settings can be detected and investigated

c)

It improves UI consistency

d)

It eliminates patching requirements

5.

Which is the BEST control to detect unauthorized updates to master data?

a)

User training

b)

Audit logs monitored independently

c)

Password rotation policy

d)

Shared admin accounts

6.

During SDLC, a failure to document acceptance criteria MOSTLY impacts:

a)

Ability to deploy code rapidly

b)

Ability to confirm whether delivered functionality meets business needs

c)

System infrastructure capacity

d)

User support requirements

7.

Which BEST mitigates the risk of data corruption during ETL loads?

a)

Restrict developer access

b)

Implement load balancing

c)

Validate record counts, hash totals, and reject unmatched loads

d)

Require sign-off from reporting team

8.

A strong Superuser Management process MUST include:

a)

A) A written list of all IT staff

b)

B) Quarterly review of privileged rights with evidence of removal actions

c)

C) Allowing CIO to approve all access requests

d)

D) Shared admin account for emergencies

9.

Which scenario indicates an INEFFECTIVE interface control?

a)

System generates exception reports for mismatched data

b)

Destination system accepts files even if record counts differ

c)

Hash totals are validated before load

d)

Automated retry logic is enabled

10.

Which BEST reduces the risk of unauthorized system development activities?

a)

Daily stand-up meetings

b)

Enforcing Git version control with restricted merge permissions

c)

Maintaining a development wiki

d)

Automatically rotating passwords

11.

A key weakness in Computer Operations is indicated when:

a)

Batch jobs are executed via scripts with no monitoring

b)

A SOC monitors network traffic

c)

Cloud resources autoscale

d)

Developers submit enhancement requests

12.

The PRIMARY audit concern with undocumented hotfixes is:

a)

Increased hardware load

b)

Inability to reproduce or validate changes introduced to production

c)

Reduction in deployment time

d)

Increase in licensing costs

13.

Which control BEST mitigates risk of unauthorized elevation of privileges?

a)

Annual audit by external firm

b)

PAM solution with approval workflow and time-boxed access

c)

VPN encryption

d)

User password complexity rules

14.

Lack of reconciliation between two financial subsystems MOSTLY results in:

a)

Bad user experience

b)

Inaccurate balances and undetected transaction discrepancies

c)

Slow interface processing

d)

Need for manual documentation

15.

Which of the following is MOST important when testing an automated calculation control?

a)

User interviews

b)

Independent recalculation of sample transactions

c)

Review of organizational policies

d)

Approval workflows

16.

The MAIN purpose of migration controls is to ensure:

a)

Developers can deploy changes quickly

b)

Only authorized and tested components are moved to production

c)

Cloud infrastructure is optimized

d)

Operations team reduces workload

17.

Which represents a WEAKNESS in program development controls?

a)

Mandatory peer code review

b)

Developers testing their own code in production

c)

Segregated development and test environments

d)

System integration testing

18.

In an automated control environment, a lack of exception handling MOSTLY leads to:

a)

Higher developer productivity

b)

Incomplete or incorrect processing of transactions

c)

Cleaner system logs

d)

Faster user onboarding

19.

Which BEST ensures validity of access provisioning?

a)

Role-based access model aligned with job responsibilities

b)

Copying access from a peer employee

c)

Temporary access granted indefinitely

d)

Manager approval without verification

20.

Which BEST describes an IT Application Control (ITAC)?

a)

Firewall configuration

b)

Automated validation ensuring invoice amounts match contract terms

c)

Anti-virus scanning

d)

CCTV in server room

21.

The key goal of IT audit is to:

a)

Optimize marketing

b)

Assess IT control effectiveness

c)

Build new systems

d)

Hire staff

22.

ITGC controls normally include:

a)
Asset valuation
b)

Logical access, change, computer operation

c)

Payroll

d)

HR analytics

23.

Access to systems should be:

a)

Granted automatically

b)

Approved by a business owner

c)

Given to all developers

d)

Permanent

24.

A risk of missing access termination is:

a)

Increased productivity

b)

Unauthorized access by former employee

c)

Higher audit score

d)

None

25.

Which document sets IT control requirements?

a)

Security Policy

b)

Employee Handbook

c)

Expense Report

d)

User Manual

26.

Who performs user access review?

a)

IT Support

b)

System Owner

c)

End User

d)

HR

27.

Which of the following is NOT an ITGC area?

a)

Program Change

b)

Access Security

c)

Financial Reporting

d)

Program acquisition and Development

28.

Which of the following is a risk associated with IT operations?

a)

Data backup

b)

Conflict of interest

c)

Software installation

d)

Data entry errors

29.

What is "Change Log"?

a)

List of salary changes

b)

Record of system modifications

c)

Calendar file

d)

User directory

30.

When implementing a risk-based IT audit program, which approach BEST ensures optimal coverage across an organization's technology landscape?

a)

Developing comprehensive audit procedures that examine all systems regardless of their risk profile to ensure complete coverage

b)

Selecting IT components for audit based on rotating schedules that guarantee all systems are reviewed within a five-year period

c)

Auditing IT assets based on the technical complexity of systems and the required specialized knowledge of the audit team

d)

Categorizing IT assets by criticality and impact to business objectives

31.

What is the purpose of control testing?

a)

Determine if control is designed and operating effectively

b)

Replace IT staff

c)

Prepare budget

d)

Train users

32.

Password policy should define:

a)

Complexity, expiry, history

b)

Username length only

c)

Access levels

d)

Work schedules

33.

When implementing a multi-layered defense strategy for information assets, which component serves as the foundation for all other security measures?

a)

Comprehensive risk assessment

b)

Implementation of complex technical controls that address all potential vulnerabilities in the network infrastructure

c)

Detailed documentation of all security procedures following industry best practices

d)

Regular security awareness training for employees with documented participation metrics

34.

Which IT framework is used to manage IT risks?

a)

COBIT

b)

IFRS

c)

IAS

d)

COSO only

35.

Which department approves system changes?

a)

HR

b)

Application Owner

c)

Sales

d)

Finance

36.

What is a privileged account?

a)

Account with elevated administrative rights

b)

Guest account

c)

Shared account

d)

Expired user

37.

Who should monitor privileged account activity?

a)

IT Operations / Security

b)

HR

c)

End user

d)

Marketing

38.

Which approach best represents the optimal design of application controls in a system?

a)

Adding controls only at the output phase where data validation is most critical and effective

b)

Integrating controls that address specific risks at the input, processing, and output stages

c)

Deploying only automated controls that require minimal human intervention and oversight

d)

Implementing redundant controls at all system levels to ensure maximum protection against all possible threats

39.

Which is NOT a control evidence type?

a)

System log

b)

Screenshot

c)

Auditor's memory

d)

Configuration export

40.

What happens if Change Management is missing?

a)

A) Systems become more secure

b)

B) Uncontrolled code deployments

c)

C) Lower costs

d)

D) Automated rollback

41.

Access reviews ensure that:

a)

All users have admin rights

b)

Rights match job responsibilities

c)

Passwords are visible

d)

HR owns all accounts

42.

What aspect of vendor performance should be prioritized during a Post-Implementation Review (PIR) for an outsourced IT implementation?

a)

Frequency of executive sponsor engagement during critical implementation milestones

b)

Adherence to contractual service level agreements

c)

Documentation of all technical support interactions and resolution timestamps across the entire project lifecycle

43.

Physical security controls include:

a)

Firewalls

b)

Door locks and CCTV

c)

Passwords

d)

Encryption

44.

Who is responsible for enforcing password policy?

a)

Cybersecurity team

b)

HR

c)

Finance

d)

Marketing

45.

Evidence of user termination control could be:

a)

HR exit report and system access log

b)

Employee photo

c)

Expense sheet

d)

Email signature

46.

What is an IT-dependent manual control?

a)

Manual review relying on system data

b)

Automated control

c)

Paper-based only

d)

No control

47.

Why are periodic reviews of IT policies important?

a)

To ensure continued relevance and compliance

b)

To delete documents

c)

To satisfy auditors only

d)

To reduce team workload

48.

Which of the following is the best practice for user account management?

a)

A) Named individual accounts

b)

B) Group logins

c)

C) Anonymous access

49.

Which reporting technique is most effective for highlighting critical security issues to the board of directors?

a)

Comprehensive narrative reports that explain all methodologies, tools used, and present complete technical specifications of each vulnerability

b)

Executive dashboards with risk indicators and trend analysis

c)

Statistical tables showing all security incidents organized by department with full remediation history over the past five years

d)

Technical audit logs with detailed findings and exhaustive evidence collections from all system components

50.

The final IT audit report should include:

a)

Findings, risk rating, and recommendations

b)

Employee list

c)

Source code

d)

Budget summary

51.

The main goal of IT General Controls is to:

a)

Ensure the accuracy of financial statements

b)

Increase operational efficiency

c)

Reduce IT staff workload

d)

Implement automation

52.

Which of the following is a key element of IT risk assessment?

a)

Identify business strategy

b)

Estimate asset depreciation

c)

Evaluate control design and RAFITS

d)

Check regulatory deadlines

53.

An IT auditor should review backup logs primarily to:

a)

Measure network performance

b)

Verify successful and timely backup completion

c)

Identify user activity

d)

Check backup vendor license

54.

Which process ensures all system modifications are authorized and documented?

a)

Configuration Management

b)

Incident Management

c)

Problem Management

d)

Change Management

55.

What is the main objective of access recertification?

a)

Confirm access rights remain appropriate

b)

Detect password reuse

c)

Monitor login times

d)

Simplify onboarding

56.

The purpose of a Change Advisory Board (CAB) is to:

a)

Monitor daily incidents

b)

Review and approve change requests

c)

Manage user training

d)

Conduct vulnerability scans

57.

Which of the following BEST represents an inherent risk?

a)

Residual risk after controls

b)

Risk existing before controls are applied

c)

Risk after audit testing

d)

Risk accepted by management

58.

During an IT audit, which MOST important for the auditor to verify first?

a)

Number of applications

b)

Audit report template

c)

RAFITS and Layers of technology

d)

Staff interviews

59.

Which of the following is the primary focus when assessing the design of a control?

a)

Whether the control works properly

b)

Whether a control exists and is properly structured

c)

The frequency of control execution

d)

Its documentation format

60.

Which reduces the risk of unauthorized software installation?

a)

Application whitelisting

b)

Antivirus scanning

c)

User awareness training

d)

Data encryption

61.

What supporting tool helps detect unauthorized changes in critical files?

a)

Log retention

b)

Integrity monitoring tools

c)

Password policy

d)

Firewall filters

62.

Which evidence provides the highest level of assurance?

a)

Management representation

b)

Document review

c)

Interview notes

d)

Observation by auditor

63.

When evaluating ITGCs, an auditor should focus on:

a)

Access, Change, and Operations controls

b)

Application design

c)

Business process maps

d)

Customer data quality

64.

What is the main audit objective for Change Management?

a)

Limit IT costs

b)

Reduce project delays

c)

Ensure all changes are approved, tested, and documented

d)

Improve customer satisfaction

65.

A deficiency in backup testing may result in:

a)

Increased storage

b)

Data loss during recovery

c)

Lower risk exposure

d)

Faster archiving

66.

The principle of least privilege requires:

a)

Assigning admin rights to all IT staff

b)

Restricting access by job title only

c)

Disabling multi-factor authentication

d)

Granting only necessary access rights

67.

When assessing IT risk, which component is considered first?

a)

Mitigation plan

b)

Threats and vulnerabilities

c)

Control documentation

d)

Compliance register

68.

The purpose of continuous monitoring is to:

a)

Replace manualeries in real time

b)

Eliminate auditors

c)

Test backup processes

69.

What is the most effective method to verify control operation?

a)

Reviewing policies

b)

Re-performing the control activity

c)

Interviewing employees

d)

Checking reports only

70.

A strong ITGC environment contributes to:

a)

Faster data entry

b)

Reduced costs

c)

Increased server uptime

d)

Reliable financial reporting

71.

An IS auditor is reviewing the physical security controls of a data center and notices several areas for concern. Which of the following areas is the MOST important?

a)

The emergency power off button cover is missing.

b)

Scheduled maintenance of the fire suppression system was not performed.

c)

There are no security cameras inside the data center.

d)

The emergency exit door is blocked.

72.

Which IT process does RAFIT fit into? Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.

a)

Access to programs and data

b)

Program changes

c)

Program acquisition and development

d)

Computer operations

73.

Which common GITC(s) address RAFIT? Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.

a)

Access provisioning - All users

b)

Password configurations

c)

User access review

d)

Privileged access

74.

Which of the following controls is MOST effective in preventing social engineering attacks?

a)

Multi-factor authentication

b)

Security awareness training

c)

Email spam filtering

d)

Data loss prevention (DLP)

75.

Which aspects do you consider when preparing for an interview?

Select all that apply.

a)

Incentive

b)

Content

c)

Approach

d)

Relationship

76.

Which of these describe the "nature" of a control?

a)

Manual control

b)

Detective control

c)

Automated control

d)

Preventive control

77.

Supporting IT systems may be relevant to the audit if they support the operation of GITC over IT processes and/or produce information used as audit evidence.

a)

True

b)

False

78.

Which of the following should be the PRIMARY concern of an IS auditor when evaluating an organization's incident response plan?

a)

The plan is approved by executive management.

b)

The plan is tested annually.

c)

Roles and responsibilities are clearly defined.

d)

The plan includes contact information for all employees.

79.

When reviewing user account management, an IS auditor is MOST concerned if:

a)

Passwords are set to expire every 90 days.

b)

Privileged accounts are reviewed quarterly.

c)

User accounts of terminated employees remain active.

d)

User IDs are unique.

80.

During an application system audit, the MOST important control to verify is that:

a)

Source code is commented properly.

b)

Changes are approved, tested, and documented.

c)

Developers have production access.

d)

Data migration is performed by operations

81.

Which of the following is the PRIMARY objective of an IT audit?

a)

Increase system performance

b)

Assess control design and operating effectiveness

c)

Verify compliance with HR policies

d)

Optimize IT spending

82.

Which ITGC control ensures that only authorized individuals can make system modifications?

a)

Change management control

b)

Physical access control

c)

Business continuity planning

d)

Data classification

83.

What is the FIRST step in performing a risk-based IT audit?

a)

Prepare audit report

b)

Review control test plan

c)

Interview management

d)

Identify key business processes

84.

The most effective control to prevent unauthorized program changes is:

a)

Version tracking

b)

Change request logging

c)

Segregation of duties between development and operations

d)

End-user testing

85.

In assessing IT risk, which factor is MOST important?

a)

Probability and impact of potential threats

b)

Number of audit staff

c)

Budget available

d)

Number of IT systems

86.

What best describes a compensating control?

a)

A redundant control

b)

A temporary control

c)

A control implemented to mitigate a deficiency

d)

A control that replaces others entirely

87.

The main purpose of a post-implementation review is to:

a)

Evaluate project profitability

b)

Confirm new system's performance

c)

Close financial accounts

d)

Identify lessons learned and control weaknesses V

88.

Which control objective relates to data completeness and accuracy?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Auditability

89.

Which of the following would MOST concern an IT auditor reviewing access controls?

a)

User accounts not disabled after termination

b)

Passwords changed quarterly

c)

Multi-factor authentication enabled

d)

Limited administrator rights

90.

Which control ensures accountability for changes made in production?

a)

Incident reporting

b)

Rollback testing

c)

Audit trail logging

d)

Patch notes

91.

The BEST indicator of effective IT governance is:

a)

Strong password policy

b)

Centralized service desk

c)

Formal IT policies

d)

Existence of a steering committee

92.

In Change Management, what is the auditor's main focus?

a)

Business satisfaction

b)

Adequacy of approval, testing, and documentation

c)

Technical performance

d)

Budget efficiency

93.

Which testing approach is MOST appropriate for evaluating ITGC effectiveness?

a)

Walkthrough and inquiry

b)

Sampling and survey

c)

Analytical procedures

d)

Regression testing

94.

What is the auditor's role in assessing Controls?

a)

Implement mitigation measures

b)

Approve internal controls

c)

Identify and evaluate risk arising from IT

d)

Train system administrators

95.

Which represents a key control for backup management?

a)

Weekly snapshot saving only

b)

Encryption only

c)

Retention without verification

d)

Backups encrypted and tested for restoration

96.

What type of control ensures that critical systems can resume after a disruption?

a)

Preventive

b)

Corrective

c)

Detective

d)

Directive

97.

In an IT audit, evidence must be:

a)

Visual and verbal

b)

Sufficient, relevant, and reliable

c)

Only quantitative

d)

Signed by management

98.

A primary IT risk when developers have unrestricted access to production data is:

a)

Unauthorized data modification

b)

Lack of training

c)

Budget overrun

d)

Project delay

99.

The key objective of information security management is:

a)

Efficiency and automation

b)

High data availability only

c)

Speed of processing

d)

Confidentiality, Integrity, and Availability (CIA)

100.

What is the auditor's BEST response when a high-risk control deficiency is identified?

a)

Reassign responsibility

b)

Report immediately to management

c)

Ignore until next audit

d)

Document and archive only

101.

Which IT process does this RAFIT fit into?

identification and authentication mechanisms are not implemented to restrict logical access to IT systems andcdata.

a)

Access to programs and data

b)

Program changes

c)

Program acquisition and development

d)

Computer operations

102.

Which common GITC(s) address RAFIT? Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.

Select all that apply.

a)

Access provisioning - All users

b)

Password configurations

c)

User access review

d)

Privileged access

103.

An audit charter should:

a)

be dynamic and change to coincide with the changing nature of technology and the audit profession.

b)

clearly state audit objectives for, and the delegation of, authority to the maintenance and review of internal controls.

c)

document the audit procedures designed to achieve the planned audit objectives.

d)

outline the overall authority, scope and responsibilities of the audit function.

104.

An IS auditor finds a small number of user access requests that had not been authorized by managers through the normal predefined workflow steps and escalation rules. The IS auditor should:

a)

perform an additional analysis.

b)

report the problem to the audit committee.

c)

conduct a security risk assessment.

d)

recommend that the owner of the identity management (IDM) system fix the workflow issues.

105.

An IS auditor observes that an enterprise has outsourced software development to a third party that is a startup company. To ensure that the enterprise's investment in software is protected, which of the following should be recommended by the IS auditor?

a)

Due diligence should be performed on the software vendor.

b)

A quarterly audit of the vendor facilities should be performed

c)

There should be a source code escrow agreement in place.

d)

A high penalty clause should be included in the contract.

106.

.An enterprise's risk appetite is BEST established by:

a)

the chief legal officer.

b)

security management.

c)

the audit committee.

d)

the steering committee.

107.

When identifying an earlier project completion time, which is to be obtained by paying a premium for early

completion, the activities that should be selected are those:

a)

whose sum of activity time is the shortest.

b)

that have zero slack time.

c)

that give the longest possible completion time.

d)

whose sum of slack time is the shortest.

108.

Which of the following should be the PRIMARY concern of an IS auditor when evaluating an

organization's incident response plan?

a)

The plan is approved by executive management.

b)

The plan is tested annually.

c)

Roles and responsibilities are clearly defined.

d)

The plan includes contact information for all employees.

109.

When reviewing user account management, an IS auditor is MOST concerned if:

a)

Passwords are set to expire every 90 days.

b)

Privileged accounts are reviewed quarterly.

c)

User accounts of terminated employees remain active.

d)

User IDs are unique.

110.

During an application system audit, the MOST important control to verify is that:

a)

Source code is commented properly.

b)

Changes are approved, tested, and documented.

c)

Developers have production access.

d)

Data migration is performed by operations