Certified Internal Auditor IT Audit & Data Analytics 2 — Questions and Answers
Question 1: During an IT audit, an auditor discovers that database administrators have unrestricted access to modify production data without any logging. Which control deficiency does this BEST represent?
- Inadequate change management
- Lack of privileged access monitoring (Correct answer)
- Insufficient data backup procedures
- Weak network perimeter controls
Correct answer: Lack of privileged access monitoring
Unrestricted, unlogged privileged access to production data represents a lack of privileged access monitoring, a critical IT general control.
Question 2: An internal auditor is using data analytics to test for duplicate payments. Which technique is MOST appropriate for this objective?
- Regression analysis
- Fuzzy matching algorithms (Correct answer)
- Control chart analysis
- Monte Carlo simulation
Correct answer: Fuzzy matching algorithms
Fuzzy matching algorithms detect near-duplicate records even when minor variations exist in vendor names or invoice numbers, making them ideal for duplicate payment testing.
Question 3: Which of the following is the PRIMARY purpose of an IT application control?
- Ensure the IT infrastructure is secured from external threats
- Provide reasonable assurance that transactions are processed completely and accurately (Correct answer)
- Manage the software development lifecycle
- Restrict physical access to data centers
Correct answer: Provide reasonable assurance that transactions are processed completely and accurately
IT application controls are designed to ensure the completeness, accuracy, and validity of transaction processing within specific applications.
Question 4: When auditing a cloud computing environment, which risk is MOST unique compared to traditional on-premises environments?
- Virus and malware exposure
- Dependency on third-party vendor for data sovereignty and security (Correct answer)
- User authentication weaknesses
- Outdated software patch management
Correct answer: Dependency on third-party vendor for data sovereignty and security
Cloud environments introduce unique risks around data sovereignty and reliance on third-party providers for security controls that the organization cannot directly manage.
Question 5: An auditor selects a random sample of 100 transactions from 50,000 using a random number generator. Which sampling method is being used?
- Systematic sampling
- Judgmental sampling
- Simple random sampling (Correct answer)
- Stratified sampling
Correct answer: Simple random sampling
Simple random sampling gives every item in the population an equal chance of selection, which is achieved by using a random number generator.
Question 6: In data analytics, what does the term 'data normalization' refer to in the context of audit analysis?
- Encrypting data before transmission
- Standardizing data formats and scales to enable meaningful comparison (Correct answer)
- Removing all outliers from a dataset
- Backing up data to a secondary server
Correct answer: Standardizing data formats and scales to enable meaningful comparison
Data normalization involves transforming data into a consistent format and scale so that comparisons and analyses yield meaningful and unbiased results.
Question 7: Which IT general control category directly addresses the risk of unauthorized changes being made to production programs?
- Logical access controls
- Change management controls (Correct answer)
- Business continuity planning
- Data classification controls
Correct answer: Change management controls
Change management controls govern how modifications to IT systems are requested, approved, tested, and implemented to prevent unauthorized or untested changes in production.
During an IT audit, an auditor discovers that database administrators have unrestricted access to modify production data without any logging.
Which control deficiency does this BEST represent?