โ† All CIA Flashcard Decks

CIA Information Technology & Systems Flashcards

6 cards from real CIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CIA Information Technology & Systems flashcards as text
  1. In evaluating IT general controls, which test procedure would an internal auditor most likely use to assess user access management?

    Answer: Reviewing a listing of user accounts and comparing to HR termination records

    Comparing active user accounts to HR termination records identifies terminated employees who still have system access.

  2. What is the main risk associated with 'shadow IT' (employees using unauthorized applications)?

    Answer: Uncontrolled data exposure and lack of IT governance

    Shadow IT creates uncontrolled environments where data may be stored in unapproved tools without proper security or governance.

  3. A CIA auditor is reviewing controls over a cloud-based accounting system. Which shared responsibility model principle is most important to understand?

    Answer: The organization retains responsibility for data classification and user access

    In a shared responsibility model, the organization always retains responsibility for its own data, user access management, and application-level controls.

  4. Which of the following is the best example of a preventive IT control?

    Answer: Input validation that rejects invalid data entry at the source

    Input validation prevents invalid data from entering the system in the first place, making it a preventive rather than detective control.

  5. When assessing IT controls for SOX compliance, an internal auditor must evaluate controls over:

    Answer: All IT systems that have a material impact on financial reporting

    SOX requires evaluation of IT controls over all systems that materially affect the accuracy of financial reporting.

  6. What is the purpose of an IT steering committee in IT governance?

    Answer: To provide executive oversight and strategic alignment of IT investments

    An IT steering committee aligns IT initiatives with organizational strategy and provides executive-level oversight of IT spending and priorities.