Certified Internal Auditor IT Audit & Data Analytics 4 — Questions and Answers
Question 1: Benford's Law is applied by auditors to a dataset of vendor invoice amounts. A finding shows the digit '9' appears far more frequently than expected as the leading digit. What does this MOST likely suggest?
- The invoices are from international vendors using different currencies
- Potential manipulation of amounts to stay just below an approval threshold (Correct answer)
- The dataset is too small to produce reliable results
- An error in the data extraction process
Correct answer: Potential manipulation of amounts to stay just below an approval threshold
Unexpected frequency of high leading digits like '9' often indicates amounts are being manipulated to fall just below an authorization threshold, a red flag for fraud.
Question 2: Which of the following BEST describes the role of a 'control owner' in an IT control environment?
- The external auditor responsible for testing the control
- The individual accountable for designing, implementing, and maintaining a specific control (Correct answer)
- The IT vendor who supplies the control software
- The board member who approves the IT risk appetite
Correct answer: The individual accountable for designing, implementing, and maintaining a specific control
A control owner is the individual with accountability for ensuring a specific control is properly designed, operating effectively, and maintained over time.
Question 3: An auditor is evaluating an organization's patch management process. Which finding represents the GREATEST risk?
- Patches are tested in a staging environment before deployment
- Critical security patches are applied within 72 hours of release
- A backlog of 200 low-severity patches exists from the past year
- No formal process exists for tracking and prioritizing security patches (Correct answer)
Correct answer: No formal process exists for tracking and prioritizing security patches
The absence of a formal patch management process means critical vulnerabilities may go unaddressed indefinitely, creating significant exposure to cyberattacks.
Question 4: When auditing data analytics capabilities within an organization, which attribute MOST indicates a mature analytics program?
- Use of spreadsheets for all data analysis
- Defined data governance policies with repeatable, automated analytics workflows (Correct answer)
- Ad hoc analysis performed only during audit periods
- Reliance solely on vendor-provided reports
Correct answer: Defined data governance policies with repeatable, automated analytics workflows
A mature analytics program is characterized by strong data governance, standardized methodologies, and automated workflows that enable consistent and reliable analysis.
Question 5: What is the PRIMARY purpose of an IT audit trail (audit log)?
- To improve system performance by caching transactions
- To provide a chronological record of system activities for accountability and forensic analysis (Correct answer)
- To encrypt sensitive data during transmission
- To automatically correct erroneous transactions
Correct answer: To provide a chronological record of system activities for accountability and forensic analysis
Audit trails create an immutable chronological record of system events that supports accountability, forensic investigations, and after-the-fact review of activities.
Question 6: During a review of an IT project, the auditor notes that user acceptance testing (UAT) was skipped to meet the go-live deadline. What is the PRIMARY risk introduced by this decision?
- The project may exceed its approved budget
- The system may not meet business requirements and contain undetected errors (Correct answer)
- IT staff may require additional training
- The vendor contract terms may be violated
Correct answer: The system may not meet business requirements and contain undetected errors
Skipping UAT removes the key validation step where business users confirm the system meets requirements, increasing the risk that defects and misalignments go live undetected.
Question 7: Which of the following is an example of a preventive IT control?
- Reviewing system logs for unauthorized access attempts
- Reconciling system-generated reports to source documents
- Requiring multi-factor authentication before system login (Correct answer)
- Generating exception reports for transactions above a set threshold
Correct answer: Requiring multi-factor authentication before system login
Multi-factor authentication prevents unauthorized access from occurring, making it a preventive control rather than a detective or corrective control.
Benford's Law is applied by auditors to a dataset of vendor invoice amounts.
A finding shows the digit '9' appears far more frequently than expected as the leading digit.
What does this MOST likely suggest?