CCISO Audit Management 4 — Questions and Answers
Question 1: When an external auditor identifies a material weakness in internal controls, what must a publicly traded company in the US do under SOX Section 404?
- Keep the finding confidential until remediation is complete
- Disclose the material weakness in its annual report and management's assessment (Correct answer)
- Replace the internal audit team immediately
- Suspend external audit activities pending board review
Correct answer: Disclose the material weakness in its annual report and management's assessment
SOX Section 404 requires management and external auditors to report on internal control effectiveness, including disclosure of any material weaknesses in the annual report.
Question 2: Which audit evidence type is generally considered most reliable?
- Evidence obtained directly by the auditor through observation and reperformance (Correct answer)
- Evidence provided verbally by management during interviews
- Evidence sourced from third-party documents obtained via the client
- Evidence from prior year audit working papers
Correct answer: Evidence obtained directly by the auditor through observation and reperformance
Evidence obtained directly by the auditor — through observation, inspection, or reperformance — is considered the most reliable because it is not filtered through the auditee.
Question 3: A CISO is conducting a gap analysis between current security controls and ISO 27001 requirements. What audit technique is being applied?
- Substantive testing
- Compliance testing (Correct answer)
- Benchmarking
- Control self-assessment
Correct answer: Compliance testing
Comparing existing controls against a standard's requirements is compliance (or conformance) testing, which determines whether controls meet defined criteria.
Question 4: What is the purpose of an audit work paper review by a senior auditor before report issuance?
- To update the risk register with new threats discovered during the audit
- To verify that evidence supports findings and that conclusions are adequately documented (Correct answer)
- To obtain management sign-off on all recommendations
- To calculate audit fees for the engagement
Correct answer: To verify that evidence supports findings and that conclusions are adequately documented
Senior review of work papers ensures that findings are supported by sufficient evidence and that documentation meets quality standards before the report is issued.
Question 5: Which concept describes the risk that audit procedures will fail to detect a material misstatement that exists?
- Inherent risk
- Control risk
- Detection risk (Correct answer)
- Residual risk
Correct answer: Detection risk
Detection risk is the risk that the auditor's procedures will not identify a material misstatement or control failure that actually exists.
Question 6: An organization uses a shared service center for financial processing. How should the CISO approach auditing controls in this shared environment?
- Audit only the organization's own controls and ignore the shared service center
- Rely exclusively on the shared service center's management assertions
- Obtain and review a SOC 1 or SOC 2 report from the shared service center (Correct answer)
- Require the shared service center to become ISO 27001 certified before use
Correct answer: Obtain and review a SOC 1 or SOC 2 report from the shared service center
A SOC 1 (Type II) or SOC 2 report from the shared service center provides independent assurance over controls at the service organization relevant to user entities.
Question 7: What does 'audit risk' represent in the context of a financial or compliance audit?
- The risk that the auditee will retaliate against auditors for negative findings
- The combined risk that material misstatements exist and that the auditor fails to detect them (Correct answer)
- The risk that audit costs exceed the approved budget
- The risk that audit findings are leaked to competitors
Correct answer: The combined risk that material misstatements exist and that the auditor fails to detect them
Audit risk is the product of inherent risk, control risk, and detection risk — the overall risk that the auditor issues an incorrect opinion.
When an external auditor identifies a material weakness in internal controls, what must a publicly traded company in the US do under SOX Section 404?