AICPA Information Technology Flashcards
6 cards from real AICPA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 AICPA Information Technology flashcards as text
During a SOC 2 examination, which Trust Services Criteria category addresses the system's availability for operation and use as committed?
Answer: Availability
The Availability Trust Services Criteria addresses whether the system is available for operation and use as committed or agreed.
An auditor using data analytics tools extracts a complete population of transactions rather than a sample. This approach is best described as:
Answer: Full population testing
Full population testing uses the entire data set, eliminating sampling risk by examining every transaction rather than a subset.
Which IT control type would detect unauthorized changes to a financial application by comparing current program code to an authorized baseline?
Answer: File integrity monitoring
File integrity monitoring continuously compares program code or configuration files to a known-good baseline to detect unauthorized changes.
A company implements role-based access control (RBAC) for its ERP system. What is the primary internal control benefit of RBAC?
Answer: Enforcing segregation of duties by restricting user access to job-relevant functions
RBAC enforces segregation of duties by ensuring users can only access functions appropriate to their job role, limiting fraud and error risk.
Under AICPA standards, an auditor assessing IT risks in a cloud-based accounting environment should primarily obtain evidence about controls through:
Answer: A SOC 1 Type II report from the cloud provider
A SOC 1 Type II report provides independent evidence of the design and operating effectiveness of a cloud provider's controls relevant to financial reporting.
Which concept in IT audit refers to the maximum tolerable period during which data might be lost due to a major incident?
Answer: Recovery point objective (RPO)
Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, driving backup frequency decisions.