โ† All Certified Internal Auditor Flashcard Decks

IT Audit & Data Analytics Flashcards

7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 IT Audit & Data Analytics flashcards as text
  1. An auditor is assessing risks in a robotic process automation (RPA) implementation. Which risk is MOST unique to RPA environments?

    Answer: Bot credentials with excessive privileges performing actions without human oversight

    RPA bots often require broad system access to perform their tasks, and without proper governance, these credentials can be exploited or misused without human review.

  2. During an IT audit, the auditor wants to assess completeness of data migration from a legacy system to a new ERP. Which procedure is MOST effective?

    Answer: Comparing record counts and control totals between the source and target systems

    Comparing record counts and control totals between source and target systems provides direct evidence that all data was transferred completely and accurately.

  3. Which data quality dimension addresses whether data values fall within an acceptable range or conform to defined business rules?

    Answer: Validity

    Validity measures whether data conforms to defined formats, ranges, and business rules, ensuring values are acceptable and meaningful within their context.

  4. An auditor is reviewing a third-party vendor that processes sensitive customer data. Which document provides the MOST reliable evidence of the vendor's internal controls?

    Answer: A SOC 2 Type II report covering the audit period

    A SOC 2 Type II report is produced by an independent auditor and covers the operating effectiveness of controls over a defined period, providing the most reliable third-party assurance.

  5. When using stratified sampling in an audit, what is the PRIMARY benefit over simple random sampling?

    Answer: It ensures proportional representation and allows focused testing on high-risk segments

    Stratified sampling divides the population into meaningful subgroups so auditors can apply greater scrutiny to high-value or high-risk strata while still covering the full population.

  6. Which concept describes the process of masking or replacing sensitive data with realistic but fictitious values for use in testing environments?

    Answer: Data obfuscation or data masking

    Data masking (obfuscation) replaces sensitive production data with realistic fictitious values, protecting privacy while still enabling realistic testing.

  7. An auditor is evaluating the effectiveness of an organization's IT risk management process. Which finding would indicate the WEAKEST risk management maturity?

    Answer: IT risks are identified and addressed on an ad hoc basis with no formal process

    An ad hoc approach to IT risk identification and remediation indicates immature risk management with no repeatable process, leading to inconsistent and unreliable risk coverage.