โ† All CIA Flashcard Decks

CIA IT Audit & Information Systems Flashcards

6 cards from real CIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CIA IT Audit & Information Systems flashcards as text
  1. Which framework is most commonly referenced for evaluating and improving IT governance and management within internal audit?

    Answer: COBIT

    COBIT (Control Objectives for Information and Related Technologies) is the leading framework for IT governance and management used in internal audit evaluations.

  2. What is a 'privileged user' in the context of IT access controls, and why are they a higher risk?

    Answer: A user with elevated system rights who can bypass normal controls

    Privileged users (e.g., system administrators) have elevated access that can circumvent normal controls, making their accounts a significant fraud and error risk requiring enhanced monitoring.

  3. Which of the following best describes a 'data integrity' control in an accounting information system?

    Answer: Ensuring data is accurate, complete, and unaltered throughout its lifecycle

    Data integrity controls ensure that information remains accurate, consistent, and unaltered from creation through storage and reporting.

  4. An internal auditor reviewing cloud computing arrangements should be most concerned with which risk?

    Answer: Loss of direct control over data and processes managed by the cloud provider

    Cloud arrangements shift operational control to a third party, creating risks around data security, availability, regulatory compliance, and the ability to audit the provider.

  5. What is the role of an audit log (audit trail) in IT systems?

    Answer: Record a chronological history of user activities and system events for accountability

    Audit logs create an immutable chronological record of system activities, enabling auditors and security teams to reconstruct events and establish accountability.

  6. Which IT audit approach involves testing application controls by re-performing automated calculations independently to verify system accuracy?

    Answer: Parallel simulation

    Parallel simulation involves the auditor independently replicating the system's processing logic against live data to verify that the system produces correct results.