13) Which general IT control covers acquisition, implementation, and maintenance of system
software including the operating system, DBMS, network software, and security software?
A) Access security controls
B) Computer operations controls
C) Program change controls
D) Program development controls
14) What do the audit committee’s responsibilities include?
15) What are the three major objectives of an IT audit?
1) The reporting framework for Service Organization Control (SOC) consists of five SOC
reports.
2) Service organizations are external organizations that perform services to the company being
audited.
3) ________ reports are issued by the service organization to report on its controls relevant to a
company’s internal control over financial reporting.
4) ________ reports are issued by the service organization to report on controls other than those
relevant to a company’s internal control related to financial reporting.
5) Which report provides an opinion regarding fairness of the service organization’s description
of controls other than those relevant to a company’s internal control related to financial reporting,
including the service auditor tests controls and expresses an opinion regarding the effectiveness
of the controls?
A) SOC 1 Type 1 Report
B) SOC 1 Type 2 Report
C) SOC 2 Type 1 Report
D) SOC 2 Type 2 Report
6) Which report provides an opinion regarding fairness of the service organization’s description
of controls relevant to a company’s internal control over financial reporting, but does not test the
controls or express an opinion regarding the effectiveness of the controls?
A) SOC 1 Type 1 Report
B) SOC 1 Type 2 Report
C) SOC 2 Type 1 Report
D) SOC 2 Type 2 Report
7) Which SOC report is conducted by the service organization’s auditors using Attestation
Standards (AT) Section 101 and prepared using the AICPA Trust Services?
A) SOC 1
B) SOC 2
C) SOC 3
D) SOC 3 Type 2 report
8) To attest, the auditor is
A) Testifying in court
B) Expressing an opinion
C) Testing financial reporting controls
D) Testing the fairness of the description of controls
17
Match the privacy principle to the correct definition.
A) The entity defines, documents, communicates, and assigns accountability for its privacy
policies and procedures.
B) The entity provides information about its privacy policies and procedures and identifies the
purposes for which personal information is collected, used, retained, and disclosed.
C) The entity limits the use of personal information to the purposes identified in the notice and
for which the individual has provided implicit or explicit consent. The entity retains personal
information only for as long as necessary to fulfill the stated purposes.
D) The entity maintains accurate, complete, and relevant personal information for the purposes
identified in the notice.
E) The entity shares personal information to third parties only for the purposes identified in the
notice and with the implicit or explicit consent of the individual.
F) The entity monitors compliance with its privacy policies and procedures and has procedures to
address privacy-related complaints and disputes.
G) The entity provides individuals their personal information for review and update.
H) The entity collects personal information only for the purposes identified in the notice.
I) The entity describes the choices available to the individual and obtains implicit or explicit
consent with respect to the collection, use, and disclosure of personal information.
J) The entity protects personal information against unauthorized access (both physical and
logical).
9) Management
Diff: 2
Objective: Q10.5 What are service organization controls?
10) Notice
Diff: 2
Objective: Q10.5 What are service organization controls?
11) Choice and Consent
Diff: 1
Objective: Q10.5 What are service organization controls?
12) Collection
Diff: 1
Objective: Q10.5 What are service organization controls?
13) Use and Retention
Diff: 1
Objective: Q10.5 What are service organization controls?
14) Access
Diff: 2
Objective: Q10.5 What are service organization controls?
15) Disclosure to Third Parties
Diff: 1
Objective: Q10.5 What are service organization controls?
16) Security for Privacy
Diff: 2
Objective: Q10.5 What are service organization controls?
17) Quality
Diff: 2
Objective: Q10.5 What are service organization controls?
18) Monitoring and Enforcement
Diff: 1
Objective: Q10.5 What are service organization controls?
19) Define the two types of SOC 1 reports.
20) Define the two types of SOC 2 reports.
21) What is the main difference between a SOC 2 and SOC 3 report?
22) List the five principle the on which the Trust Services framework is based.
23) Define or explain the five principle the on which the Trust Services framework is based.
24) List the four aspects of the Trust Services framework.
25) Define the four aspects of the Trust Services framework.
26) What is the purpose of the Trust Services framework?
27) List and define the 10 generally accepted privacy principles.
1) The ________ of internal auditors establishes trust and thus provides the basis for reliance on
their judgment.
2) Internal auditors exhibit the highest level of professional ________ in gathering, evaluating,
and communicating information about the activity or process being examined.
Match the internal auditors code of ethics principle to the appropriate definition.
A) Internal auditors exhibit the highest level of professional objectivity in gathering, evaluating,
and communicating information about the activity or process being examined.
B) The integrity of internal auditors establishes trust and thus provides the basis for reliance on
their judgment.
C) Internal auditors respect the value and ownership of information they receive and do not
disclose information without appropriate authority unless there is a legal or professional
obligation to do so.
D) Internal auditors apply the knowledge, skills, and experience needed in the performance of
internal audit services.
3) Competency
Diff: 2
Objective: Chapter 10 Extension
4) Integrity
Diff: 1
Objective: Chapter 10 Extension
5) Confidentiality
Diff: 2
Objective: Chapter 10 Extension
6) Objectivity
Diff: 1
Objective: Chapter 10 Extension
Match the internal auditors code of conduct principle with the appropriate definition.
A) Shall engage only in those services for which they have the necessary knowledge, skills, and
experience.
B) Shall be prudent in the use and protection of information acquired in the course of their
duties.
C) Shall perform their work with honesty, diligence, and responsibility.
D) Shall not participate in any activity or relationship that may impair or be presumed to impair
their unbiased assessment.
7) Competency
Diff: 2
Objective: Chapter 10 Extension
8) Confidentiality
Diff: 2
Objective: Chapter 10 Extension
9) Integrity
Diff: 2
Objective: Chapter 10 Extension
10) Objectivity
Diff: 2
Objective: Chapter 10 Extension
11) Which principle in the Code of Ethics for internal auditors states that the are to make a
balanced assessment of all the relevant circumstances and are not unduly influenced by their own
interests or by others in forming judgments?
A) Confidentiality
B) Competency
C) Objectivity
D) Integrity
12) Which principle in the Code of Ethics for internal auditors states that they are to respect the
value and ownership of information they receive and do not disclose information without
appropriate authority unless there is a legal or professional obligation to do so?
A) Confidentiality
B) Competency
C) Objectivity
D) Integrity
13) Which Rule of Conduct for internal auditors states that they will not knowingly be a party to
any illegal activity, or engage in acts that are discreditable to the profession of internal auditing
or to the organization?
A) Objectivity
B) Integrity
C) Competency
D) Confidentiality
14) Which Rule of Conduct for internal auditors states that they shall respect and contribute to
the legitimate and ethical objectives of the organization.
A) Confidentiality
B) Competency
C) Objectivity
D) Integrity
15) Which Rule of Conduct for internal auditors states that they are to disclose all material facts
known to them that, if not disclosed, may distort the reporting of activities under review?
A) Objectivity
B) Integrity
C) Competency
D) Confidentiality
16) Which Rule of Conduct for internal auditors states that they will not accept anything that
may or be presumed to impair their professional judgment.
A) Integrity
B) Competency
C) Objectivity
D) Confidentiality
17) Which Rule of Conduct for internal auditors states that they are not to use information for
any personal gain or in any manner that would be contrary to the law or detrimental to the
legitimate and ethical objectives of the organization?
A) Objectivity
B) Integrity
C) Competency
D) Confidentiality
18) Which Rule of Conduct for internal auditors states that they shall continually improve their
proficiency and the effectiveness and quality of their services.
A) Objectivity
B) Integrity
C) Competency
D) Confidentiality
19) You are an internal auditor for a company with a policy stating all software on company
computers must be approved and installed by the IT department. During the course of an IT audit
you discover an employee has installed MP3s on their company computer. What do you do?