CIA CIA IT Audit & Information Systems 3 — Questions and Answers
Question 1: Which framework is most commonly referenced for evaluating and improving IT governance and management within internal audit?
- COSO ERM
- COBIT (Correct answer)
- ISO 9001
- NIST SP 800-53
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the leading framework for IT governance and management used in internal audit evaluations.
Question 2: What is a 'privileged user' in the context of IT access controls, and why are they a higher risk?
- A user who works remotely, increasing network exposure
- A user with elevated system rights who can bypass normal controls (Correct answer)
- A vendor with read-only access to financial reports
- An executive with approval authority over large transactions
Correct answer: A user with elevated system rights who can bypass normal controls
Privileged users (e.g., system administrators) have elevated access that can circumvent normal controls, making their accounts a significant fraud and error risk requiring enhanced monitoring.
Question 3: Which of the following best describes a 'data integrity' control in an accounting information system?
- Ensuring data is backed up daily
- Ensuring data is accurate, complete, and unaltered throughout its lifecycle (Correct answer)
- Restricting user access to sensitive tables
- Encrypting all transmitted data
Correct answer: Ensuring data is accurate, complete, and unaltered throughout its lifecycle
Data integrity controls ensure that information remains accurate, consistent, and unaltered from creation through storage and reporting.
Question 4: An internal auditor reviewing cloud computing arrangements should be most concerned with which risk?
- Increased hardware maintenance costs
- Loss of direct control over data and processes managed by the cloud provider (Correct answer)
- Slower processing speed compared to on-premise systems
- Reduced need for IT staff
Correct answer: Loss of direct control over data and processes managed by the cloud provider
Cloud arrangements shift operational control to a third party, creating risks around data security, availability, regulatory compliance, and the ability to audit the provider.
Question 5: What is the role of an audit log (audit trail) in IT systems?
- Speed up transaction processing
- Record a chronological history of user activities and system events for accountability (Correct answer)
- Automatically correct data entry errors
- Compress data to reduce storage costs
Correct answer: Record a chronological history of user activities and system events for accountability
Audit logs create an immutable chronological record of system activities, enabling auditors and security teams to reconstruct events and establish accountability.
Question 6: Which IT audit approach involves testing application controls by re-performing automated calculations independently to verify system accuracy?
- Parallel simulation (Correct answer)
- Integrated test facility
- Embedded audit module
- Test data method
Correct answer: Parallel simulation
Parallel simulation involves the auditor independently replicating the system's processing logic against live data to verify that the system produces correct results.
Which framework is most commonly referenced for evaluating and improving IT governance and management within internal audit?