Skip to main content

IT Governance and Assurance Exam Preparation Guide - 1295 Verified Questions

Page 1


IT Governance and Assurance

Exam Preparation Guide

Course Introduction

This course explores the principles and frameworks guiding IT governance and assurance within organizations. Students will learn how effective governance aligns IT strategy with business objectives, manages risks, and ensures compliance with regulatory requirements. Topics include IT governance models such as COBIT, risk management practices, internal controls, audit processes, and methods for evaluating IT performance and value delivery. Emphasis is placed on assessing and improving IT assurance functions to support organizational integrity and accountability in an ever-evolving technological landscape.

Recommended Textbook Information Technology Auditing 3rd Edition by James A. Hall

Available Study Resources on Quizplus

12 Chapters

1295 Verified Questions

1295 Flashcards

Source URL: https://quizplus.com/study-set/351

Page 2

Chapter 1: Auditing and Internal Control

Available Study Resources on Quizplus for this Chatper

103 Verified Questions

103 Flashcards

Source URL: https://quizplus.com/quiz/5812

Sample Questions

Q1) Prior to SOX,external auditors were required to be familiar with the client organization's internal controls,but not test them.Explain.

Answer: Auditors had the option of not relying on internal controls in the conduct of an audit and therefore did not need to test them.Instead auditors could focus primarily of substantive tests.Under SOX,management is required to make specific assertions regarding the effectiveness of internal controls.To attest to the validity of these assertions,auditors are required to test the controls.

Q2) Inherent risk

A) exists because all control structures are flawed in some ways.

B) is the likelihood that material misstatements exist in the financial statements of the firm.

C) is associated with the unique characteristics of the business or industry of the client.

D) is the likelihood that the auditor will not find material misstatements.

Answer: C

Q3) Not permitting the computer programmer to enter the computer room is an example of _______________________________.

Answer: segregation of duties

To view all questions and flashcards with answers, click on the resource link above.

Page 3

Chapter 2: Auditing IT Governance Controls

Available Study Resources on Quizplus for this Chatper

99 Verified Questions

99 Flashcards

Source URL: https://quizplus.com/quiz/5813

Sample Questions

Q1) An advantage of distributed data processing is that redundant tasks are greatly eliminated

A)True

B)False

Answer: False

Q2) A ROC usually involves two or more user organizations that buy or lease a building and remodel it into a computer site,but without the computer and peripheral equipment. A)True

B)False

Answer: False

Q3) Describe two tests that an auditor would perform to ensure that the disaster recovery plan is adequate.

Answer: review second site backup plan,critical application list,and off-site backups of critical libraries,applications and data files; ensure that backup supplies,source documents and documentation are located off-site; review which employees are members of disaster recovery team

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: Security Part I: Auditing Operating Systems and Networks

Available Study Resources on Quizplus for this Chatper

143 Verified Questions

143 Flashcards

Source URL: https://quizplus.com/quiz/5814

Sample Questions

Q1) Describe a denial of service (DoS)attack and identify three common forms.

Answer: A denial of service attacks (DoS)is an assault on a web server to prevent it from servicing its legitimate users.While such attacks can be aimed at any type of website,they are particularly devastating to business entities that are prevented from receiving and processing business transactions from their customers.Three common types of DoS attacks are: SYN flood,smurf,and distributed denial of service (DDoS).

Q2) A software program that replicates itself in areas of idle memory until the system fails is called a

A) Trojan horse

B) worm

C) logic bomb

D) none of the above

Answer: B

Q3) A distributed denial of service (DDoS)attack may take the form of a SYN flood but not a smurf attack.

A)True

B)False

Answer: False

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: IT Security Part II: Auditing Database Systems

Available Study Resources on Quizplus for this Chatper

101 Verified Questions

101 Flashcards

Source URL: https://quizplus.com/quiz/5815

Sample Questions

Q1) Why are the hierarchical and network models called navigational databases?

Q2) Subschemas are used to authorize user access privileges to specific data elements. A)True

B)False

Q3) Distinguish between a database lockout and a deadlock.

Q4) A replicated database is appropriate when

A) there is minimal data sharing among information processing units

B) there exists a high degree of data sharing and no primary user

C) there is no risk of the deadlock phenomenon

D) most data sharing consists of read-write transactions

Q5) There is more than one conceptual view of the database. A)True

B)False

Q6) Explain a database lockout and the deadlock phenomenon.Contrast that to concurrency control and the timestamping technique.Describe the importance of these items in relation to database integrity.

Q7) What are two types of distributed databases?

Q8) Explain the three views of a database.

Q9) What is the partitioned database approach and what are its advantages?

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Systems Development and Program Change

Activities

Available Study Resources on Quizplus for this Chatper

108 Verified Questions

108 Flashcards

Source URL: https://quizplus.com/quiz/5816

Sample Questions

Q1) Which control is not associated with new systems development activities?

A) reconciling program version numbers

B) program testing

C) user involvement

D) internal audit participation

Q2) Source program library controls should prevent and detect unauthorized access to application programs.

A)True

B)False

Q3) Which step is least likely to occur when choosing a commercial software package?

A) a detailed review of the source code

B) contact with user groups

C) preparation of a request for proposal

D) comparison of the results of a benchmark problem

Q4) Why is the payback method often more useful than the net present value method for evaluating systems projects?

Q5) Describe two methods used to control the source program library.

Page 7

Q6) ____________________ benefits can be measured and expressed in financial terms,while ____________________ benefits cannot be easily measured and/or quantified.

To view all questions and flashcards with answers, click on the resource link above.

Page 8

Chapter 6: Overview of Transaction Processing and Financial Reporting Systems

Available Study Resources on Quizplus for this Chatper

143 Verified Questions

143 Flashcards

Source URL: https://quizplus.com/quiz/5817

Sample Questions

Q1) Mnemonic codes are appropriate for items in either an ascending or descending sequence,such as the numbering of checks or source documents.

A)True

B)False

Q2) Give an example of how cardinality relates to business policy?

Q3) Program flowcharts depict the type of media being used (paper,magnetic tape,or disks)and terminals.

A)True

B)False

Q4) Documents that are created at the beginning of the transaction are called

Q5) How is backup of database files accomplished?

Q6) What is XML?

Q7) List,in order,the steps in the Financial Accounting Process.

Q8) Resource use is one characteristic used to distinguish between batch and real-time systems.Explain.

Page 9

Q9) ______________________________________ are the two data processing approaches used in modern systems.

Q10) With regard to an entity relationship diagram,what is an entity?

To view all questions and flashcards with answers, click on the resource link above.

Page 10

Chapter 7: Computer-Assisted Audit Tools and Techniques

Available Study Resources on Quizplus for this Chatper

83 Verified Questions

83 Flashcards

Source URL: https://quizplus.com/quiz/5818

Sample Questions

Q1) All of the following statements are true about the integrated test facility (ITF)except

A) production reports are affected by ITF transactions

B) ITF databases contain "dummy" records integrated with legitimate records

C) ITF permits ongoing application auditing

D) ITF does not disrupt operations or require the intervention of computer services personnel

Q2) Which statement is not true? A batch control record

A) contains a transaction code

B) records the record count

C) contains a hash total

D) control figures in the record may be adjusted during processing

E) All the above are true

Q3) The integrated test facility (ITF)is an automated approach that permits auditors to test an application's logic and controls during its normal operation.

A)True

B)False

Q4) Describe two types of transposition error

Q5) Name four input controls and describe what they test

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 8: Data Structures and CAATTs for Data Extraction

Available Study Resources on Quizplus for this Chatper

89 Verified Questions

89 Flashcards

Source URL: https://quizplus.com/quiz/5819

Sample Questions

Q1) Which statement is true about a hashing structure?

A) The same address could be calculated for two records.

B) Storage space is used efficiently.

C) Records cannot be accessed rapidly.

D) A separate index is required.

Q2) What is repeating group data?

Q3) An advantage of using an indexed random file structure is that records are easily added and deleted.

A)True

B)False

Q4) What is a transitive dependency?

Q5) Logical database design is the foundation of the conceptual design.

A)True

B)False

Q6) Outline some of the key advantages of GAS.

GAS allows auditors to access electronically coded data files of their clients,both simple and complex structures,and to perform various operations on their contents.GAS is popular for the following reasons:

Q7) Explain the purpose of an ER diagram in database design.

Q8) What is an embedded audit module?

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 9: Auditing the Revenue Cycle

Available Study Resources on Quizplus for this Chatper

105 Verified Questions

105 Flashcards

Source URL: https://quizplus.com/quiz/5820

Sample Questions

Q1) Which of the following is not a risk exposure in a PC accounting system?

A) reliance on paper documentation is increased

B) functions that are segregated in a manual environment may be combined in a microcomputer accounting system

C) backup procedures require human intervention

D) data are easily accessible

Q2) The credit department

A) prepares credit memos when goods are returned

B) approves credits to accounts receivable when payments are received

C) authorizes the granting of credit to customers

D) none of the above

Q3) The cash receipts journal is a special journal.

A)True B)False

Q4) What task can the accounts receivable department engage in to verify that all checks sent by the customers have been appropriately deposited and recorded?

Q5) Inventory control has physical custody of inventory.

A)True B)False

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 10: Auditing the Expenditure Cycle

Available Study Resources on Quizplus for this Chatper

144 Verified Questions

144 Flashcards

Source URL: https://quizplus.com/quiz/5821

Sample Questions

Q1) The inventory procurement process begins with the purchasing clerk preparing a purchase order.

A)True

B)False

Q2) The payroll department performs all of the following except

A) prepares the payroll register

B) distributes paychecks

C) updates employee payroll records

D) prepares paychecks

Q3) Of the following duties,it is most important to separate

A) warehouse from stores

B) warehouse from inventory control

C) accounts payable and accounts receivable

D) purchasing and accounts receivable

Q4) Most payroll systems for mid-size firms use real-time data processing.

A)True

B)False

Q5) Why should the copy of a purchase order,which is sent to receiving,be a "blind" copy?

Page 14

Q6) Why should employees clocking on and off the job be supervised.

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Business Ethics, Fraud, and Fraud Detection

Available Study Resources on Quizplus for this Chatper

85 Verified Questions

85 Flashcards

Source URL: https://quizplus.com/quiz/5822

Sample Questions

Q1) Operations fraud includes

A) altering program logic to cause the application to process data incorrectly

B) misusing the firm's computer resources

C) destroying or corrupting a program's logic using a computer virus

D) creating illegal programs that can access data files to alter, delete, or insert values

Q2) What fraud detection responsibilities (if any)are imposed on auditors by the Sarbanes-Oxley Act?

Q3) Four principal types of corruption are discussed.Name all four and explain at least two.

Q4) The ethical principle of informed consent suggests that the decision should be implemented so as to minimize all of the risks and to avoid any unnecessary risks.

A)True

B)False

Q5) Explain the pass through fraud.

Q6) Employees should be made aware of the firm's commitment to ethics.

A)True

B)False

Q7) Explain the problems associated with inappropriate accounting practices.

To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 11: Enterprise Resource Planning Systems

Available Study Resources on Quizplus for this Chatper

92 Verified Questions

92 Flashcards

Source URL: https://quizplus.com/quiz/5823

Sample Questions

Q1) Day-to-day transactions are stored in the operational database.

A)True

B)False

Q2) Data mining typically focuses on the operational databases.

A)True

B)False

Q3) What is SCM software?

Q4) Define OLAP and give some examples.

Q5) Define the term "core applications" and give some examples.

Q6) RBAC assigns access permissions to the role an individual plays in the organization rather than directly to the individual.

A)True

B)False

Q7) Goals of ERP include all of the following except

A) improved customer service

B) improvements of legacy systems

C) reduced production time

D) increased production

Q8) What is the client-server model?

Q9) What is the "Big-Bang" approach?

Page 16

To view all questions and flashcards with answers, click on the resource link above.

Page 17

Turn static files into dynamic content formats.

Create a flipbook
IT Governance and Assurance Exam Preparation Guide - 1295 Verified Questions by Quizplus - Issuu