wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Quiz 1 - Information System Audit - SU - Spring 2026

Total questions: 21

Worksheet time: 11mins

Name
Class
Date
1.
In a complex IT environment, which professional is most likely to be involved when a database has reached its storage limit on an SSD?
a)
The Database Administrator
b)
The Network Analyst
c)
The Systems Analyst
d)
All are correct
2.
An auditor reviewing a database design identifies a 'Many-to-Many' relationship. What is the auditor's primary evaluative task regarding this relationship?
a)
Evaluate the strength of the relationship and verify consistency with business needs.
b)
Ensure that the key of each record is not unique.
c)
Verify that it can be converted into a One-to-Many relationship immediately.
d)
Read and analyze the descriptions of the CPU handling the data.
3.

In the context of evolving IT Audit paradigms, which of the following best describes the 'Modern Re-engineered Paradigm' regarding control ownership and management role?

a)

Control equals management control and top management can control everything.

b)

Control is focused with process owners who become custodians of internal control.

c)

Control is embedded within processes and focuses on continuous improvement control.

d)
Control equals management control and is imposed from above.
4.

Which component of the Audit Charter explicitly establishes the right to acquire people, properties, assets, and records?

a)

Professionalism Statement

b)
Formal Definition
c)

Authority & Access

d)
Terms of Reference
5.
From an auditor’s perspective, which of the following is considered a disadvantage or risk associated with Database technology?
a)
Data integrity tradeoffs.
b)
Migration of controls from applications to the general environment.
c)

Reducing the quality of audit by reducing accessibility.

d)

Lack of consistency of data across the organization.

6.
What is the primary function of the Job Control Language (JCL) in an IT environment?
a)

To serve as an interface between the CPU and the BIOS

b)
To create a script that operates under the control of the owners
c)

To automate the job-running process using batch programming instructions.

d)
To write application programs for business functions.
7.
In the management process, which step involves deciding whether to transfer a risk (e.g., through insurance) or manage it internally?
a)
Decide the control strategies
b)
Establish organizational needs
c)
Identify key activities
d)
Implement and monitor controls
8.
Which IT professional is specifically responsible for ensuring availability, performance standards, and security on networks?
a)

Security Analyst

b)
Systems Analyst
c)
Systems Programmer
d)

Network Analyst

9.
According to the materials, what is the 'pioneer syndrome' in the context of DBMS implementation?
a)
The risks associated with implementing new, unproven technology.
b)
The success of early adopters in capturing market share.
c)
The pioneer framework for migrating legacy data to cloud storage
d)
The ability of auditors to use new tools to explore data.
10.
Corporate Governance is defined as the relationship among participants in determining the direction and performance of a company. Who are the primary participants mentioned?
a)
Shareholders, Board of Directors, Management, and Employees.
b)
Shareholders, Customers, Suppliers, and Competitors.
c)
IT Auditors, External Auditors, Internal Auditors, and Public Sector Auditors.
d)
External Auditors, Internal Auditors, Management, and Employees.
11.
Which type of memory is described as 'non-volatile' because its instructions are 'burned-in' and not lost during power loss?
a)

RAM

b)
Virtual RAM
c)

ROM

d)
Optical Disks
12.
An auditor finds that a project is 'off-track' during the monitoring phase. According to the cyclical management process, what is the next logical step?
a)
Intervene by adjusting the plan, reallocating resources, or changing processes.
b)
Create new plan with decreasing scale of IT operations immediately.
c)
Wait until the next annual report is released.
d)
Begin a new literature search on the organization to construct better IT Projects by learning from the previous mistake
13.
What is the primary objective of Information Systems Auditing?
a)

To adjust the business design specifications for new systems.

b)
To act as the guardians of control in an organization that able to provide assurance to your quality.
c)
To reduce the cost of IT implementation for better quality.
d)

To provide independent, objective assurance that systems safeguard assets and maintain data integrity.

14.
Which standard is specifically categorized as an 'Accreditation framework' for quality management systems?
a)
ISO 9000
b)
COBIT
c)
TCSEC
d)
ITIL
15.
A Modem (Modulator/Demodulator) performs what specific translation?
a)
Digital computer signals into analog signals for telephone wires.
b)
Translate human natural language into the standardized digital computer information.
c)
High-capacity magnetic data into laser-encoded data.
d)
Analog computer signals to digital telephone signals.
16.
In the context of IT auditing, what is 'Information Warfare' or 'Cyber Terrorism' listed as?
a)
The new threat landscape necessitating robust auditing frameworks.
b)
Transformative potentials of technology into an attack that able to penetrate the security of a network.
c)
Methods for evaluating the performance of a security system.
d)
Components of the Audit Charter that identify a hole in the system before release.
17.
Which storage device is characterized by high speed and a capacity range typically between 256 GB and 8 TB?
a)

Optical Disk

b)
Hard Disk Drive (HDD)
c)

Solid State Drive (SSD)

d)
RAM
18.
Under the 'Modern Re-engineered Paradigm', if an auditor finds a control weakness in a business process, who is held primarily responsible for being the 'custodian' of that control?
a)
The Process Owners
b)
The External Regulatory Body
c)
The Internal Audit Department
d)
The Chief Executive Officer
19.
A company is transitioning from a traditional top-down management structure to a continuous improvement model. How does this specifically change the 'Origin of Control'?
a)

Control becomes solely a function of technical hardware limitations.

b)
Control is removed from management and given entirely to software algorithms.
c)

Control shifts from being a governance-led directive to being driven by continuous improvement.

d)
Control shifts from the process level to the Board of Directors.
20.
An IT Audit Manager is drafting the 'Terms of Reference' section of the Audit Charter. What should this section specifically contain?
a)
A detailed description of the roles and working objectives of the head of IT Audit.
b)
The detailed legal definitions of Information Technology especially with recent issue that has been found in the world.
c)
The reporting line to the Chief Executive Officer (CEO) to create the information line from bottom-to-top.
d)
A list of the physical assets the auditor can use as the main reference for finding any issues.
21.
Which scenario would most likely require an auditor to invoke the 'Authority & Access' clause of the Audit Charter?
a)

When the auditor is deciding which ISO standard to apply to the organization.

b)

When a department head refuses to provide logs for a database managed by a third party.

c)
When the auditor needs to purchase new CAATs (Computer Assisted Audit Techniques).
d)
When the auditor is deciding who is responsible for breaking the system.