94) Routines that collect and summarize statistics concerning program resource utilization are
called
A) embedded audit routines.
B) mapping.
C) job accounting routines.
D) tracing.
95) The information system auditing technology that originated as a technique to assist in
program design and testing is
A) tracing.
B) parallel simulation.
C) snapshot.
D) mapping.
96) Which of the following information system auditing technologies would be the best to
monitor the execution of a computer program?
A) Integrated test facility
B) Parallel simulation
C) Mapping
D) Embedded audit routine
97) The phase of an information systems audit in which an audit program is created is the
A) first phase.
B) second phase.
C) third phase.
D) fourth phase.
98) Compliance testing is the key activity performed in which phase of an information systems
audit?
A) Second phase
B) First phase
C) Fourth phase
D) Third phase
99) The phase of an information systems audit in which effort is placed on fact-finding in the
areas selected for audit is the
A) first phase.
B) second phase.
C) third phase.
D) fourth phase.
100) Information systems application audits differ from information systems audits because
application audits
A) are divided into four general areas, each of which has three phases.
B) involve reviewing input, processing, and output controls.
C) are directed at the activities of systems analysts and programmers.
D) focus primarily on fact-finding in the areas selected for audit.
101) An audit that examines the controls governing the systems process and which directly affect
the reliability of the application programs created is called a(n)
A) general information system audit.
B) information system applications audit.
C) application systems development audit.
D) information system computer service center audit.
102) Which of the following controls would not be examined in the audit of a computer service
center?
A) Environmental controls
B) Physical security controls
C) Management controls
D) Process application controls
103) In the program change control phase of an application systems development audit, an
element that may represent a major loss exposure in terms of fraud and access to sensitive data is
A) program development.
B) program auditing.
C) program testing and quality control.
D) program maintenance.
104) ________ provides assurances relating to the effectiveness of an organization’s enterprise
risk management processes.
A) RBA
B) OMB
C) REA
D) UML
105) The goal of RBA to auditing is to apply audit efforts to areas in proportion to their
likelihood to
A) reduce exposures in areas of high risk.
B) reduce the exposure and occurrences of fraud.
C) significantly impact the auditor’s overall audit conclusions.
D) All of the above are goals of RBA.
106) IT governance has the objective of enhancing and ensuring the efficient application of IT
resources
A) to ensure success in the development of systems and processes.
B) as a critical success factor.
C) to gain a competitive advantage.
D) as a major component to IT security.
107) The Public Company Accounting Oversight Board (PCAOB) has encouraged a risk-based
approach to test the effectiveness of ________ as they relate to financial audits.
A) internal controls
B) security processes
C) financial misstatements
D) fraud exposure
108) Risks associated with implementing new technologies include
A) IT strategies not aligned with business strategies.
B) control framework for IT does not exist.
C) IT performance is not measured and evaluated.
D) All of the above are risks associated with new technologies.
109) An IT governance framework such as ________ can be a critical element in ensuring proper
control and governance over information and the systems that create, store, manipulate, and
retrieve that information.
A) CISA
B) SOA
C) COBIT
D) RBA
110) COBIT has four domains that include
A) plan and organize, acquire and implement, deliver and support, and monitor and evaluate.
B) analysis, design, implement, and feedback.
C) plan, build, implement, and evaluate.
D) analysis, build, train, and implement.
111) ________ models are used to evaluate an organization’s relative level of achievement of IT
governance and shows what has to be done to improve.
A) RBA
B) Maturity
C) Visibility
D) Navigation
112) ________ is for IS audit, control, assurance and/or security professionals.
A) CISA
B) CISM
C) CGEIT
D) COBIT
113) ________ is for individuals who manage, design, oversee, and assess an enterprise’s
information security program.
A) CISA
B) CISM
C) CGEIT
D) COBIT
114) ________ is the most recent certification programs and for individuals interested in
Governance of Enterprise IT.
A) CISA
B) CISM
C) CGEIT
D) COBIT
115) Presented below is a list of terms relating to accounting information systems, followed by
definitions of those terms.
Required: Match the letter next to each definition with the appropriate term. Each answer will be
used only once.
________ 1. Mapping
________ 2. Compliance testing
________ 3. Extended records
________ 4. Substantive testing
________ 5. Interim audit
________ 6. Snapshot
________ 7. Parallel simulation
________ 8. Audit software
________ 9. Desk checking
________10. Tracing
A. Modification of programs to collect and store additional data of audit interest
B. Computer programs that permit the computer to be used as an auditing tool
C. Special software that is used to monitor the executing of a program
D. The first stage of a financial statement audit which has the objective of establishing the
degree to which the internal control system can be relied upon
E. Provides a detailed audit trail of the instructions executed during a program’s operation
F. Modification of programs to output data of audit interest
G. Direct verification of balances contained in financial statements
H. The auditor manually processes test or real data through the logic of a computer program
I. Testing to confirm the existence, assess the effectiveness, and check the continuity of
operation of internal controls
J. The processing of real data through audit programs, with the simulated output and the regular
output compared for control purposes
116) Presented below is a list of terms relating to accounting information systems, followed by
definitions of those terms.
Required: Match the letter next to each definition with the appropriate term. Each answer will be
used only once.
________ 1. Audit program
________ 2. System control audit review file
________ 3. Auditing around-the-computer
________ 4. In-line code
________ 5. Financial statement audit
________ 6. Control flowcharting
________ 7. Test data
________ 8. Embedded audit routines
________ 9. Sample audit review file
________10. PC software
A. The second stage of a financial statement audit which uses substantive testing for direct
verification of financial statement figures
B. Software that allows the auditor to use PCs to perform audit tasks
C. Information systems auditing approach in which the processing portion of a computer system
is ignored
D. A detailed list of the procedures to be applied on a particular audit
E. Analytic documentation or other graphic techniques used to describe the controls in a system
F. The use of in-line code to randomly select transactions for audit analysis
G. Auditor-prepared input containing both valid and invalid data
H. Special auditing routines included in regular computer programs so that transaction data can
be subjected to audit analysis
I. An application program performs an embedded audit routine such as data collection at the
same time as it processes data for normal use
J. Auditor-determined programmed edit tests for audit transaction analysis are included in a
program as it is initially developed
117) Below are listed four procedures typically performed during an audit of accounts payable:
Audit procedures:
a. Test the mathematical accuracy of the accounts payable subsidiary ledger.
b. Select samples of vouchers to examine in detail.
c. Determine whether cash discounts were properly applied.
d. Stratify accounts by value.
Required: Briefly state a generalized audit software technique that could be used to perform each
procedure, assuming that the accounts payable application is computerized.
118) Listed below are five examples of auditing situations and five information systems auditing
techniques.
Required: First, match the letter of the information system auditing technique which best
identifies the example. Then, in the space below each item, write a brief explanation of how the
technique works in the situation.
A. Parallel simulation
B. Test data approach
C. Mapping
D. PC software
E. Extended records
________ 1. An auditor performs an inexpensive test of a cash disbursements program without
modifying the client’s program. Explanation:
________ 2. Audit team members communicate with each other in separate locations during an
audit by exchanging Word and Excel files electronically. Explanation:
________ 3. An auditor inputs test sales order data to find out whether a sales order program
executes the program statements needed to produce a shipping notice document. Explanation:
________ 4. An internal auditor modifies a newly designed accounts receivable program to
randomly select sales transactions and save each transaction’s complete processing audit trail.
Explanation:
________ 5. During substantive testing, an auditor tests a client’s loan interest accrual program
by submitting the client’s data to a program running on a computer at the auditor’s office.
Explanation:
25
119) Listed below are five examples of auditing situations and five information systems auditing
techniques.
Required: First, match the letter of the information system auditing technique which best
identifies the example. Then, in the space below each item, write a brief explanation of how the
technique works in the situation.
A. Integrated test facility
B. Generalized audit software
C. Tracing
D. Review of systems documentation
E. Embedded audit routines
________ 1. An auditor uses software to select and evaluate a statistical sample of loan payments
at a bank in a substantive test. Explanation:
________ 2. An internal auditor assists systems personnel to modify a newly developed accounts
payable program so that it will tag and save a statistical sample of each month’s transactions for
further review. Explanation:
________ 3. An auditor with a high level of technical experience requests a dump of the object
code of an Internet retailer’s purchasing program. Explanation:
________ 4. An auditor inputs special program statements to provide a listing of the sequence of
a general ledger application program’s execution. The auditor inputs test data and reviews the
listing to learn whether the internal controls executed as expected. Explanation:
________ 5. An auditor works with systems personnel as a real-time account receivable
application is developed. When completed, the application can incorporate the auditor’s test data
in regular processing runs. Explanation:
120) Why are most audits now performed by auditing through and with the computer?
121) Explain why external auditors perform compliance testing when a main objective of a
financial statement audit is to express an opinion regarding the fairness of the monetary balances
in a company’s financial statements.
122) How have personal computers likely affected information systems audits?
123) Because resources are usually limited, not all applications can be audited each year. What
factors should an internal or external auditor consider when deciding which applications to
audit?
124) Briefly describe the three phases of an information systems audit.
125) Describe three areas that an auditor could examine in an audit of a computer service center.