Certified Internal Auditor IT Audit & Data Analytics 3 — Questions and Answers
Question 1: An auditor is reviewing an organization's IT disaster recovery plan. Which element is MOST critical to validate during the audit?
- The physical location of backup tapes
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO) alignment with business needs (Correct answer)
- The number of IT staff assigned to recovery
- The age of the backup hardware
Correct answer: Recovery Time Objective (RTO) and Recovery Point Objective (RPO) alignment with business needs
RTO and RPO define how quickly systems must be restored and how much data loss is acceptable, and they must align with business requirements to be effective.
Question 2: During a cybersecurity audit, the auditor finds that the organization has not conducted a penetration test in three years. Which risk does this PRIMARILY increase?
- Risk of natural disasters affecting operations
- Risk of unidentified exploitable vulnerabilities in systems (Correct answer)
- Risk of non-compliance with HR policies
- Risk of physical theft of IT equipment
Correct answer: Risk of unidentified exploitable vulnerabilities in systems
Penetration testing identifies exploitable vulnerabilities; without regular testing, new vulnerabilities introduced through system changes may go undetected.
Question 3: When performing continuous auditing, what is the PRIMARY advantage over traditional periodic auditing?
- Lower cost of audit tools and technology
- Near real-time detection of anomalies and control failures (Correct answer)
- Reduced need for auditor professional judgment
- Elimination of sampling risk
Correct answer: Near real-time detection of anomalies and control failures
Continuous auditing enables near real-time monitoring of transactions and controls, allowing auditors to detect and respond to issues as they occur rather than after the fact.
Question 4: An internal auditor is assessing IT governance. Which framework is MOST widely used as a reference for IT governance and management of enterprise IT?
- ISO 27001
- COBIT (Correct answer)
- ITIL
- NIST Cybersecurity Framework
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the most widely recognized framework specifically designed for IT governance and management.
Question 5: Which data analytics technique would BEST help an auditor identify trends in expense report submissions over a 12-month period?
- Benford's Law analysis
- Time-series analysis (Correct answer)
- Ratio analysis
- Cluster analysis
Correct answer: Time-series analysis
Time-series analysis examines data points collected over time to identify patterns, trends, or seasonal variations in the data.
Question 6: During an IT audit, the auditor determines that input validation controls are missing in a financial application. What is the MOST likely consequence?
- Slower system processing speeds
- Entry of erroneous or malicious data into the system (Correct answer)
- Unauthorized access to the network
- Failure of data backup procedures
Correct answer: Entry of erroneous or malicious data into the system
Without input validation, erroneous, incomplete, or malicious data can be entered and processed, potentially corrupting financial records or enabling injection attacks.
Question 7: An auditor is reviewing segregation of duties in an ERP system. Which combination of access rights represents the HIGHEST risk?
- Ability to create and approve purchase orders (Correct answer)
- Ability to view and print financial reports
- Ability to add new users and reset passwords
- Ability to run and schedule automated reports
Correct answer: Ability to create and approve purchase orders
Having the ability to both create and approve purchase orders in a single role eliminates a key authorization control and enables fraudulent procurement transactions.
An auditor is reviewing an organization's IT disaster recovery plan.
Which element is MOST critical to validate during the audit?