AICPA AICPA Information Technology 2 — Questions and Answers
Question 1: During a SOC 2 examination, which Trust Services Criteria category addresses the system's availability for operation and use as committed?
- Availability (Correct answer)
- Confidentiality
- Processing integrity
- Privacy
Correct answer: Availability
The Availability Trust Services Criteria addresses whether the system is available for operation and use as committed or agreed.
Question 2: An auditor using data analytics tools extracts a complete population of transactions rather than a sample. This approach is best described as:
- Full population testing (Correct answer)
- Stratified sampling
- Attribute sampling
- Discovery sampling
Correct answer: Full population testing
Full population testing uses the entire data set, eliminating sampling risk by examining every transaction rather than a subset.
Question 3: Which IT control type would detect unauthorized changes to a financial application by comparing current program code to an authorized baseline?
- File integrity monitoring (Correct answer)
- Firewall rule review
- Password complexity policy
- Network segmentation
Correct answer: File integrity monitoring
File integrity monitoring continuously compares program code or configuration files to a known-good baseline to detect unauthorized changes.
Question 4: A company implements role-based access control (RBAC) for its ERP system. What is the primary internal control benefit of RBAC?
- Enforcing segregation of duties by restricting user access to job-relevant functions (Correct answer)
- Encrypting all data at rest within the ERP database
- Automating month-end closing journal entries
- Reducing software licensing costs
Correct answer: Enforcing segregation of duties by restricting user access to job-relevant functions
RBAC enforces segregation of duties by ensuring users can only access functions appropriate to their job role, limiting fraud and error risk.
Question 5: Under AICPA standards, an auditor assessing IT risks in a cloud-based accounting environment should primarily obtain evidence about controls through:
- A SOC 1 Type II report from the cloud provider (Correct answer)
- Direct testing of the provider's physical data centers
- A vendor-provided marketing brochure about security
- Only substantive procedures on financial balances
Correct answer: A SOC 1 Type II report from the cloud provider
A SOC 1 Type II report provides independent evidence of the design and operating effectiveness of a cloud provider's controls relevant to financial reporting.
Question 6: Which concept in IT audit refers to the maximum tolerable period during which data might be lost due to a major incident?
- Recovery point objective (RPO) (Correct answer)
- Recovery time objective (RTO)
- Mean time to repair (MTTR)
- Service level agreement (SLA)
Correct answer: Recovery point objective (RPO)
Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, driving backup frequency decisions.
During a SOC 2 examination, which Trust Services Criteria category addresses the system's availability for operation and use as committed?