Certified Internal Auditor IT Audit & Data Analytics 5 — Questions and Answers
Question 1: An auditor is assessing risks in a robotic process automation (RPA) implementation. Which risk is MOST unique to RPA environments?
- Inadequate physical security of servers
- Bot credentials with excessive privileges performing actions without human oversight (Correct answer)
- Insufficient network bandwidth for data transmission
- Weak password policies for end users
Correct answer: Bot credentials with excessive privileges performing actions without human oversight
RPA bots often require broad system access to perform their tasks, and without proper governance, these credentials can be exploited or misused without human review.
Question 2: During an IT audit, the auditor wants to assess completeness of data migration from a legacy system to a new ERP. Which procedure is MOST effective?
- Interviewing the project manager about the migration approach
- Comparing record counts and control totals between the source and target systems (Correct answer)
- Reviewing the vendor's migration documentation
- Observing the go-live cutover process
Correct answer: Comparing record counts and control totals between the source and target systems
Comparing record counts and control totals between source and target systems provides direct evidence that all data was transferred completely and accurately.
Question 3: Which data quality dimension addresses whether data values fall within an acceptable range or conform to defined business rules?
- Completeness
- Timeliness
- Validity (Correct answer)
- Uniqueness
Correct answer: Validity
Validity measures whether data conforms to defined formats, ranges, and business rules, ensuring values are acceptable and meaningful within their context.
Question 4: An auditor is reviewing a third-party vendor that processes sensitive customer data. Which document provides the MOST reliable evidence of the vendor's internal controls?
- The vendor's marketing materials and certifications page
- A SOC 2 Type II report covering the audit period (Correct answer)
- A self-assessment questionnaire completed by the vendor
- The vendor's published privacy policy
Correct answer: A SOC 2 Type II report covering the audit period
A SOC 2 Type II report is produced by an independent auditor and covers the operating effectiveness of controls over a defined period, providing the most reliable third-party assurance.
Question 5: When using stratified sampling in an audit, what is the PRIMARY benefit over simple random sampling?
- It is faster and requires less auditor judgment
- It ensures proportional representation and allows focused testing on high-risk segments (Correct answer)
- It eliminates the need to define a sampling frame
- It guarantees detection of all material errors
Correct answer: It ensures proportional representation and allows focused testing on high-risk segments
Stratified sampling divides the population into meaningful subgroups so auditors can apply greater scrutiny to high-value or high-risk strata while still covering the full population.
Question 6: Which concept describes the process of masking or replacing sensitive data with realistic but fictitious values for use in testing environments?
- Data archiving
- Data tokenization for production
- Data obfuscation or data masking (Correct answer)
- Data replication
Correct answer: Data obfuscation or data masking
Data masking (obfuscation) replaces sensitive production data with realistic fictitious values, protecting privacy while still enabling realistic testing.
Question 7: An auditor is evaluating the effectiveness of an organization's IT risk management process. Which finding would indicate the WEAKEST risk management maturity?
- IT risks are formally documented in a risk register and reviewed quarterly
- Risk appetite has been defined and approved by senior management
- IT risks are identified and addressed on an ad hoc basis with no formal process (Correct answer)
- Risk mitigation actions are tracked with assigned owners and due dates
Correct answer: IT risks are identified and addressed on an ad hoc basis with no formal process
An ad hoc approach to IT risk identification and remediation indicates immature risk management with no repeatable process, leading to inconsistent and unreliable risk coverage.
An auditor is assessing risks in a robotic process automation (RPA) implementation.
Which risk is MOST unique to RPA environments?