Font size
Worksheetsaudit
Total questions: 110
Worksheet time: 6hrs 30mins
Which situation poses the GREATEST risk in Change Management?
Delays in approving low-risk changes
Developers have ability to migrate code to production.
Separate environments maintained for testing
Weekly CAB meetings are held
What is the MOST effective control to ensure completeness of data transferred through an API interface?
Manual reconciliation
Checksum validation for each message batch
Archiving API logs monthly
Internal memo confirmation from system owner
Which BEST describes a preventive access control?
Daily review of audit logs
MFA requirement for privileged access
Monthly SoD analysis
Exception reporting
What is the PRIMARY benefit of a formal configuration baseline?
It reduces the number of user requests
It ensures deviations from approved settings can be detected and investigated
It improves UI consistency
It eliminates patching requirements
Which is the BEST control to detect unauthorized updates to master data?
User training
Audit logs monitored independently
Password rotation policy
Shared admin accounts
During SDLC, a failure to document acceptance criteria MOSTLY impacts:
Ability to deploy code rapidly
Ability to confirm whether delivered functionality meets business needs
System infrastructure capacity
User support requirements
Which BEST mitigates the risk of data corruption during ETL loads?
Restrict developer access
Implement load balancing
Validate record counts, hash totals, and reject unmatched loads
Require sign-off from reporting team
A strong Superuser Management process MUST include:
A) A written list of all IT staff
B) Quarterly review of privileged rights with evidence of removal actions
C) Allowing CIO to approve all access requests
D) Shared admin account for emergencies
Which scenario indicates an INEFFECTIVE interface control?
System generates exception reports for mismatched data
Destination system accepts files even if record counts differ
Hash totals are validated before load
Automated retry logic is enabled
Which BEST reduces the risk of unauthorized system development activities?
Daily stand-up meetings
Enforcing Git version control with restricted merge permissions
Maintaining a development wiki
Automatically rotating passwords
A key weakness in Computer Operations is indicated when:
Batch jobs are executed via scripts with no monitoring
A SOC monitors network traffic
Cloud resources autoscale
Developers submit enhancement requests
The PRIMARY audit concern with undocumented hotfixes is:
Increased hardware load
Inability to reproduce or validate changes introduced to production
Reduction in deployment time
Increase in licensing costs
Which control BEST mitigates risk of unauthorized elevation of privileges?
Annual audit by external firm
PAM solution with approval workflow and time-boxed access
VPN encryption
User password complexity rules
Lack of reconciliation between two financial subsystems MOSTLY results in:
Bad user experience
Inaccurate balances and undetected transaction discrepancies
Slow interface processing
Need for manual documentation
Which of the following is MOST important when testing an automated calculation control?
User interviews
Independent recalculation of sample transactions
Review of organizational policies
Approval workflows
The MAIN purpose of migration controls is to ensure:
Developers can deploy changes quickly
Only authorized and tested components are moved to production
Cloud infrastructure is optimized
Operations team reduces workload
Which represents a WEAKNESS in program development controls?
Mandatory peer code review
Developers testing their own code in production
Segregated development and test environments
System integration testing
In an automated control environment, a lack of exception handling MOSTLY leads to:
Higher developer productivity
Incomplete or incorrect processing of transactions
Cleaner system logs
Faster user onboarding
Which BEST ensures validity of access provisioning?
Role-based access model aligned with job responsibilities
Copying access from a peer employee
Temporary access granted indefinitely
Manager approval without verification
Which BEST describes an IT Application Control (ITAC)?
Firewall configuration
Automated validation ensuring invoice amounts match contract terms
Anti-virus scanning
CCTV in server room
The key goal of IT audit is to:
Optimize marketing
Assess IT control effectiveness
Build new systems
Hire staff
ITGC controls normally include:
Logical access, change, computer operation
Payroll
HR analytics
Access to systems should be:
Granted automatically
Approved by a business owner
Given to all developers
Permanent
A risk of missing access termination is:
Increased productivity
Unauthorized access by former employee
Higher audit score
None
Which document sets IT control requirements?
Security Policy
Employee Handbook
Expense Report
User Manual
Who performs user access review?
IT Support
System Owner
End User
HR
Which of the following is NOT an ITGC area?
Program Change
Access Security
Financial Reporting
Program acquisition and Development
Which of the following is a risk associated with IT operations?
Data backup
Conflict of interest
Software installation
Data entry errors
What is "Change Log"?
List of salary changes
Record of system modifications
Calendar file
User directory
When implementing a risk-based IT audit program, which approach BEST ensures optimal coverage across an organization's technology landscape?
Developing comprehensive audit procedures that examine all systems regardless of their risk profile to ensure complete coverage
Selecting IT components for audit based on rotating schedules that guarantee all systems are reviewed within a five-year period
Auditing IT assets based on the technical complexity of systems and the required specialized knowledge of the audit team
Categorizing IT assets by criticality and impact to business objectives
What is the purpose of control testing?
Determine if control is designed and operating effectively
Replace IT staff
Prepare budget
Train users
Password policy should define:
Complexity, expiry, history
Username length only
Access levels
Work schedules
When implementing a multi-layered defense strategy for information assets, which component serves as the foundation for all other security measures?
Comprehensive risk assessment
Implementation of complex technical controls that address all potential vulnerabilities in the network infrastructure
Detailed documentation of all security procedures following industry best practices
Regular security awareness training for employees with documented participation metrics
Which IT framework is used to manage IT risks?
COBIT
IFRS
IAS
COSO only
Which department approves system changes?
HR
Application Owner
Sales
Finance
What is a privileged account?
Account with elevated administrative rights
Guest account
Shared account
Expired user
Who should monitor privileged account activity?
IT Operations / Security
HR
End user
Marketing
Which approach best represents the optimal design of application controls in a system?
Adding controls only at the output phase where data validation is most critical and effective
Integrating controls that address specific risks at the input, processing, and output stages
Deploying only automated controls that require minimal human intervention and oversight
Implementing redundant controls at all system levels to ensure maximum protection against all possible threats
Which is NOT a control evidence type?
System log
Screenshot
Auditor's memory
Configuration export
What happens if Change Management is missing?
A) Systems become more secure
B) Uncontrolled code deployments
C) Lower costs
D) Automated rollback
Access reviews ensure that:
All users have admin rights
Rights match job responsibilities
Passwords are visible
HR owns all accounts
What aspect of vendor performance should be prioritized during a Post-Implementation Review (PIR) for an outsourced IT implementation?
Frequency of executive sponsor engagement during critical implementation milestones
Adherence to contractual service level agreements
Documentation of all technical support interactions and resolution timestamps across the entire project lifecycle
Physical security controls include:
Firewalls
Door locks and CCTV
Passwords
Encryption
Who is responsible for enforcing password policy?
Cybersecurity team
HR
Finance
Marketing
Evidence of user termination control could be:
HR exit report and system access log
Employee photo
Expense sheet
Email signature
What is an IT-dependent manual control?
Manual review relying on system data
Automated control
Paper-based only
No control
Why are periodic reviews of IT policies important?
To ensure continued relevance and compliance
To delete documents
To satisfy auditors only
To reduce team workload
Which of the following is the best practice for user account management?
A) Named individual accounts
B) Group logins
C) Anonymous access
Which reporting technique is most effective for highlighting critical security issues to the board of directors?
Comprehensive narrative reports that explain all methodologies, tools used, and present complete technical specifications of each vulnerability
Executive dashboards with risk indicators and trend analysis
Statistical tables showing all security incidents organized by department with full remediation history over the past five years
Technical audit logs with detailed findings and exhaustive evidence collections from all system components
The final IT audit report should include:
Findings, risk rating, and recommendations
Employee list
Source code
Budget summary
The main goal of IT General Controls is to:
Ensure the accuracy of financial statements
Increase operational efficiency
Reduce IT staff workload
Implement automation
Which of the following is a key element of IT risk assessment?
Identify business strategy
Estimate asset depreciation
Evaluate control design and RAFITS
Check regulatory deadlines
An IT auditor should review backup logs primarily to:
Measure network performance
Verify successful and timely backup completion
Identify user activity
Check backup vendor license
Which process ensures all system modifications are authorized and documented?
Configuration Management
Incident Management
Problem Management
Change Management
What is the main objective of access recertification?
Confirm access rights remain appropriate
Detect password reuse
Monitor login times
Simplify onboarding
The purpose of a Change Advisory Board (CAB) is to:
Monitor daily incidents
Review and approve change requests
Manage user training
Conduct vulnerability scans
Which of the following BEST represents an inherent risk?
Residual risk after controls
Risk existing before controls are applied
Risk after audit testing
Risk accepted by management
During an IT audit, which MOST important for the auditor to verify first?
Number of applications
Audit report template
RAFITS and Layers of technology
Staff interviews
Which of the following is the primary focus when assessing the design of a control?
Whether the control works properly
Whether a control exists and is properly structured
The frequency of control execution
Its documentation format
Which reduces the risk of unauthorized software installation?
Application whitelisting
Antivirus scanning
User awareness training
Data encryption
What supporting tool helps detect unauthorized changes in critical files?
Log retention
Integrity monitoring tools
Password policy
Firewall filters
Which evidence provides the highest level of assurance?
Management representation
Document review
Interview notes
Observation by auditor
When evaluating ITGCs, an auditor should focus on:
Access, Change, and Operations controls
Application design
Business process maps
Customer data quality
What is the main audit objective for Change Management?
Limit IT costs
Reduce project delays
Ensure all changes are approved, tested, and documented
Improve customer satisfaction
A deficiency in backup testing may result in:
Increased storage
Data loss during recovery
Lower risk exposure
Faster archiving
The principle of least privilege requires:
Assigning admin rights to all IT staff
Restricting access by job title only
Disabling multi-factor authentication
Granting only necessary access rights
When assessing IT risk, which component is considered first?
Mitigation plan
Threats and vulnerabilities
Control documentation
Compliance register
The purpose of continuous monitoring is to:
Replace manualeries in real time
Eliminate auditors
Test backup processes
What is the most effective method to verify control operation?
Reviewing policies
Re-performing the control activity
Interviewing employees
Checking reports only
A strong ITGC environment contributes to:
Faster data entry
Reduced costs
Increased server uptime
Reliable financial reporting
An IS auditor is reviewing the physical security controls of a data center and notices several areas for concern. Which of the following areas is the MOST important?
The emergency power off button cover is missing.
Scheduled maintenance of the fire suppression system was not performed.
There are no security cameras inside the data center.
The emergency exit door is blocked.
Which IT process does RAFIT fit into? Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.
Access to programs and data
Program changes
Program acquisition and development
Computer operations
Which common GITC(s) address RAFIT? Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.
Access provisioning - All users
Password configurations
User access review
Privileged access
Which of the following controls is MOST effective in preventing social engineering attacks?
Multi-factor authentication
Security awareness training
Email spam filtering
Data loss prevention (DLP)
Which aspects do you consider when preparing for an interview?
Select all that apply.
Incentive
Content
Approach
Relationship
Which of these describe the "nature" of a control?
Manual control
Detective control
Automated control
Preventive control
Supporting IT systems may be relevant to the audit if they support the operation of GITC over IT processes and/or produce information used as audit evidence.
True
False
Which of the following should be the PRIMARY concern of an IS auditor when evaluating an organization's incident response plan?
The plan is approved by executive management.
The plan is tested annually.
Roles and responsibilities are clearly defined.
The plan includes contact information for all employees.
When reviewing user account management, an IS auditor is MOST concerned if:
Passwords are set to expire every 90 days.
Privileged accounts are reviewed quarterly.
User accounts of terminated employees remain active.
User IDs are unique.
During an application system audit, the MOST important control to verify is that:
Source code is commented properly.
Changes are approved, tested, and documented.
Developers have production access.
Data migration is performed by operations
Which of the following is the PRIMARY objective of an IT audit?
Increase system performance
Assess control design and operating effectiveness
Verify compliance with HR policies
Optimize IT spending
Which ITGC control ensures that only authorized individuals can make system modifications?
Change management control
Physical access control
Business continuity planning
Data classification
What is the FIRST step in performing a risk-based IT audit?
Prepare audit report
Review control test plan
Interview management
Identify key business processes
The most effective control to prevent unauthorized program changes is:
Version tracking
Change request logging
Segregation of duties between development and operations
End-user testing
In assessing IT risk, which factor is MOST important?
Probability and impact of potential threats
Number of audit staff
Budget available
Number of IT systems
What best describes a compensating control?
A redundant control
A temporary control
A control implemented to mitigate a deficiency
A control that replaces others entirely
The main purpose of a post-implementation review is to:
Evaluate project profitability
Confirm new system's performance
Close financial accounts
Identify lessons learned and control weaknesses V
Which control objective relates to data completeness and accuracy?
Availability
Integrity
Confidentiality
Auditability
Which of the following would MOST concern an IT auditor reviewing access controls?
User accounts not disabled after termination
Passwords changed quarterly
Multi-factor authentication enabled
Limited administrator rights
Which control ensures accountability for changes made in production?
Incident reporting
Rollback testing
Audit trail logging
Patch notes
The BEST indicator of effective IT governance is:
Strong password policy
Centralized service desk
Formal IT policies
Existence of a steering committee
In Change Management, what is the auditor's main focus?
Business satisfaction
Adequacy of approval, testing, and documentation
Technical performance
Budget efficiency
Which testing approach is MOST appropriate for evaluating ITGC effectiveness?
Walkthrough and inquiry
Sampling and survey
Analytical procedures
Regression testing
What is the auditor's role in assessing Controls?
Implement mitigation measures
Approve internal controls
Identify and evaluate risk arising from IT
Train system administrators
Which represents a key control for backup management?
Weekly snapshot saving only
Encryption only
Retention without verification
Backups encrypted and tested for restoration
What type of control ensures that critical systems can resume after a disruption?
Preventive
Corrective
Detective
Directive
In an IT audit, evidence must be:
Visual and verbal
Sufficient, relevant, and reliable
Only quantitative
Signed by management
A primary IT risk when developers have unrestricted access to production data is:
Unauthorized data modification
Lack of training
Budget overrun
Project delay
The key objective of information security management is:
Efficiency and automation
High data availability only
Speed of processing
Confidentiality, Integrity, and Availability (CIA)
What is the auditor's BEST response when a high-risk control deficiency is identified?
Reassign responsibility
Report immediately to management
Ignore until next audit
Document and archive only
Which IT process does this RAFIT fit into?
identification and authentication mechanisms are not implemented to restrict logical access to IT systems andcdata.
Access to programs and data
Program changes
Program acquisition and development
Computer operations
Which common GITC(s) address RAFIT? Identification and authentication mechanisms are not implemented to restrict logical access to IT systems and data.
Select all that apply.
Access provisioning - All users
Password configurations
User access review
Privileged access
An audit charter should:
be dynamic and change to coincide with the changing nature of technology and the audit profession.
clearly state audit objectives for, and the delegation of, authority to the maintenance and review of internal controls.
document the audit procedures designed to achieve the planned audit objectives.
outline the overall authority, scope and responsibilities of the audit function.
An IS auditor finds a small number of user access requests that had not been authorized by managers through the normal predefined workflow steps and escalation rules. The IS auditor should:
perform an additional analysis.
report the problem to the audit committee.
conduct a security risk assessment.
recommend that the owner of the identity management (IDM) system fix the workflow issues.
An IS auditor observes that an enterprise has outsourced software development to a third party that is a startup company. To ensure that the enterprise's investment in software is protected, which of the following should be recommended by the IS auditor?
Due diligence should be performed on the software vendor.
A quarterly audit of the vendor facilities should be performed
There should be a source code escrow agreement in place.
A high penalty clause should be included in the contract.
.An enterprise's risk appetite is BEST established by:
When identifying an earlier project completion time, which is to be obtained by paying a premium for early
completion, the activities that should be selected are those:
whose sum of activity time is the shortest.
that have zero slack time.
that give the longest possible completion time.
whose sum of slack time is the shortest.
Which of the following should be the PRIMARY concern of an IS auditor when evaluating an
organization's incident response plan?
The plan is approved by executive management.
The plan is tested annually.
Roles and responsibilities are clearly defined.
The plan includes contact information for all employees.
When reviewing user account management, an IS auditor is MOST concerned if:
Passwords are set to expire every 90 days.
Privileged accounts are reviewed quarterly.
User accounts of terminated employees remain active.
User IDs are unique.
During an application system audit, the MOST important control to verify is that:
Source code is commented properly.
Changes are approved, tested, and documented.
Developers have production access.
Data migration is performed by operations
