← All Certified Public Accountant Flashcard Decks

Technology & Digital Applications Flashcards

7 cards from real Certified Public Accountant practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Technology & Digital Applications flashcards as text
  1. A CPA advising a client on digital transformation notes the client plans to use APIs to integrate its ERP with a third-party payment processor. The MOST important control to recommend is:

    Answer: API authentication tokens with expiration and least-privilege access scopes

    API security requires authenticated, scoped tokens with expiration so that only authorized systems can initiate transactions and compromised tokens have limited lifespan and capability.

  2. In a SOC 1 Type II engagement, the service auditor's report covers which of the following?

    Answer: The service organization's controls over financial reporting relevant to user entities' ICFR, tested over a specified period

    A SOC 1 Type II report describes and tests the operating effectiveness of a service organization's controls relevant to user entities' internal control over financial reporting over a defined period.

  3. Which of the following represents a 'preventive' IT control rather than a 'detective' IT control?

    Answer: User access restrictions preventing unauthorized transactions from being entered

    Preventive controls stop problems before they occur; restricting access prevents unauthorized users from entering transactions, while detective controls identify issues after the fact.

  4. A company implements multi-factor authentication (MFA) for all financial system logins. This control PRIMARILY mitigates which risk?

    Answer: Account takeover through compromised passwords alone

    MFA requires a second verification factor beyond a password, so stolen or guessed credentials alone are insufficient for an attacker to gain access.

  5. When auditing a company that uses machine learning models to estimate the allowance for doubtful accounts, the CPA's MOST important procedure is to:

    Answer: Assess the model's inputs, assumptions, and validation testing to evaluate the reasonableness of the output

    The auditor must understand and challenge the ML model's inputs and assumptions because biased training data or flawed logic can produce materially misstated accounting estimates.

  6. The concept of 'data governance' in an organization MOST directly supports financial reporting quality by:

    Answer: Establishing accountability, quality standards, and ownership for data used in financial processes

    Data governance defines who owns data, what quality standards apply, and how data is maintained, all of which directly affect the accuracy and completeness of financial reporting inputs.

  7. A CPA discovers that a client's IT department can deploy code changes to the production financial system without any approval or testing documentation. This MOST directly indicates:

    Answer: A deficiency in change management controls that could allow unauthorized modifications to financial data

    Unauthorized deployment capability bypasses the authorization, testing, and documentation requirements of change management, creating significant risk of undetected errors or fraud in financial systems.