← All Certified Internal Auditor Flashcard Decks

IT Audit & Data Analytics Flashcards

6 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 IT Audit & Data Analytics flashcards as text
  1. What is the primary objective of an IT general controls audit?

    Answer: To evaluate the effectiveness of controls over the IT environment that support all applications

    IT general controls (ITGCs) are foundational controls over the IT environment — access management, change management, operations, and backup — that support the reliability of all applications and data.

  2. What is data analytics in internal auditing?

    Answer: Using automated tools and techniques to analyze entire datasets for patterns, anomalies, and exceptions

    Data analytics enables auditors to analyze 100% of transactions rather than sampling, identifying anomalies, patterns, trends, and exceptions that indicate control weaknesses or potential fraud.

  3. What is continuous auditing and how does it differ from traditional auditing?

    Answer: Automated, ongoing testing of controls and transactions versus periodic point-in-time audits

    Continuous auditing uses technology to automatically and continuously test controls and transactions in near real-time, providing ongoing assurance rather than periodic snapshots.

  4. What is the significance of access controls in IT audit?

    Answer: They ensure only authorized users can access systems and data, preventing unauthorized activity

    Access controls (authentication, authorization, and accounting) are critical IT controls that restrict system and data access to authorized users, preventing unauthorized transactions and data breaches.

  5. What is a Computer-Assisted Audit Technique (CAAT)?

    Answer: Software tools used by auditors to extract, analyze, and test data from information systems

    CAATs are software tools (like ACL, IDEA, or SQL-based tools) that help auditors extract data from systems, perform analysis, identify exceptions, and test controls more efficiently.

  6. What is change management in the context of IT audit?

    Answer: A formal process for requesting, reviewing, approving, testing, and implementing changes to IT systems

    IT change management ensures all modifications to systems, applications, and configurations follow a formal process of request, review, approval, testing, and implementation to prevent unauthorized or problematic changes.