Deck 11: Auditing Computer-Based Information Systems

ملء الشاشة (f)
exit full mode
سؤال
The ________ audit examines the reliability and integrity of accounting records.

A)financial
B)informational
C)information systems
D)operational
استخدم زر المسافة أو
up arrow
down arrow
لقلب البطاقة.
سؤال
Verifying the accuracy of certain information,often through communication with third parties,is known as

A)reperformance.
B)confirmation.
C)substantiation.
D)documentation.
سؤال
The possibility that a material error will occur even though auditors are following audit procedures and using good judgment is referred to as

A)control risk.
B)detection risk.
C)inherent risk.
D)investigating risk.
سؤال
A(n)________ audit is concerned with the economical and efficient use of resources and the accomplishment of established goals and objectives.

A)operational or management
B)financial
C)information systems
D)internal control
سؤال
The auditor's objective is to seek ________ that no material error exists in the information audited.

A)absolute reliability
B)reasonable objectivity
C)reasonable evidence
D)reasonable assurance
سؤال
Consideration of risk factors and materiality is most associated with which audit stage?

A)collection of audit evidence
B)communication of audit results
C)audit planning
D)evaluation of audit evidence
سؤال
What is not a typical responsibility of an internal auditor?

A)helping management to improve organizational effectiveness
B)assisting in the design and implementation of an AIS
C)preparation of the company's financial statements
D)implementing and monitoring of internal controls
سؤال
Which of the choices below best describes a risk-based audit approach?

A)a four-step approach to internal control evaluation.
B)a three-step approach to internal control evaluation.
C)a four-step approach to financial statement review and recommendations.
D)a three-step approach to financial statement review and recommendations.
سؤال
Organizing the audit team and the physical examination of assets are components of which two separate audit stages?

A)planning; evaluating audit evidence
B)planning; collecting audit evidence
C)collecting audit evidence; communicating audit results
D)communicating audit results; evaluating audit evidence
سؤال
A system that employs various types of advanced technology has more ________ risk than traditional batch processing.

A)control
B)detection
C)inherent
D)investing
سؤال
Auditing involves the

A)collection,review,and documentation of audit evidence.
B)planning and verification of economic events.
C)collection of audit evidence and approval of economic events.
D)testing,documentation,and certification of audit evidence.
سؤال
The evidence collection method that considers the relationships and trends among information to detect items that should be investigated further is called

A)review of the documentation.
B)vouching.
C)physical examination.
D)analytical review.
سؤال
Control risk is defined as the

A)susceptibility to material risk in the absence of controls.
B)risk that a material misstatement will get through the internal control structure and into the financial statements.
C)risk that auditors and their audit procedures will not detect a material error or misstatement.
D)risk auditors will not be given the appropriate documents and records by management who wants to control audit activities and procedures.
سؤال
Assessing the quality of internal controls,the reliability of information,and operating performance are all part of

A)audit planning.
B)collection of audit evidence.
C)communication of audit results.
D)evaluation of audit evidence.
سؤال
The ________ stage of the auditing process involves (among other things)the auditors observing the operating activities and having discussions with employees.

A)audit planning
B)collection of audit evidence
C)communication of audit results
D)evaluation of audit evidence
سؤال
The evidence collection method that examines all supporting documents to determine the validity of a transaction is called

A)review of documentation.
B)vouching.
C)physical examination.
D)analytical review.
سؤال
The purpose of ________ is to determine why,how,when,and who will perform the audit.

A)audit planning
B)the collection of audit evidence
C)the communication of audit results
D)the evaluation of audit evidence
سؤال
Which type of work listed below is not typical of internal auditors?

A)operational and management audits
B)information system audits
C)financial statement audit
D)financial audit of accounting records
سؤال
The ________ audit is concerned with the economical and efficient use of resources and the accomplishment of established goals and objectives.

A)financial
B)informational
C)information systems
D)operational
سؤال
The ________ audit reviews the general and application controls of an AIS to assess its compliance with internal control policies and procedures and its effectiveness in safeguarding assets.

A)financial
B)information systems
C)management
D)internal control
سؤال
An auditor finds that employee absentee rates are significantly higher on Mondays and Fridays than on other work days.This is an example collecting audit evidence by

A)confirmation.
B)reperformance.
C)vouching.
D)analytical review.
سؤال
The first step in a risk-based audit approach is to

A)evaluate the control procedures.
B)determine the threats facing the AIS.
C)identify the control procedures that should be in place.
D)evaluate weaknesses to determine their effect on the audit procedures.
سؤال
Describe the risk-based audit approach.
سؤال
The information systems audit objective that pertains to source data being processed into some form of output is known as

A)overall security.
B)program development.
C)program modifications.
D)processing.
سؤال
How is a financial audit different from an information systems audit?
سؤال
An auditor examines all documents related to the acquisition,repair history,and disposal of a firm's delivery van.This is an example of collecting audit evidence by

A)confirmation.
B)reperformance.
C)vouching.
D)analytical review.
سؤال
When a control deficiency is identified,the auditor should inquire about

A)tests of controls.
B)compensating controls.
C)the feasibility of a systems review.
D)materiality and inherent risk factors.
سؤال
Describe how audit evidence can be collected.
سؤال
Increasing the effectiveness of auditing software will

A)reduce detection risk.
B)reduce control risk.
C)increase detection risk.
D)increase control risk.
سؤال
________can determine whether the necessary control procedures are in place.

A)A systems review
B)A systems overhaul
C)Tests of controls
D)both B and C
سؤال
Name and describe the different types of audits.
سؤال
Which of the following is not one of the types of internal audits?

A)reviewing corporate organizational structure and reporting hierarchies
B)examining procedures for reporting and disposing of hazardous waste
C)reviewing source documents and general ledger accounts to determine integrity of recorded transactions
D)comparing estimates and analysis made before purchase of a major capital asset to actual numbers and results achieved
سؤال
Why do all audits follow a sequence of events that can be divided into four stages,and what are the four stages?
سؤال
An auditor manually calculates accumulated depreciation on a delivery van and compares her calculation with the accounting records.The auditor is performing

A)vouching.
B)confirmation.
C)reperformance.
D)analytical review.
سؤال
How and to whom does an auditor communicate the audit results?
سؤال
What is the purpose of an information systems audit?

A)to determine the inherent risk factors found in the system
B)to review and evaluate the internal controls that protect the system
C)to examine the reliability and integrity of accounting records
D)to examine whether resources have been used in an economical and efficient manner in keeping with organization goals and objectives
سؤال
Explain the differences between each type of audit risk.
سؤال
Expanding a firm's operations to include a manufacturing facility in Russia will

A)reduce inherent risk.
B)reduce control risk.
C)increase inherent risk.
D)increase control risk.
سؤال
Increasing the effectiveness of internal controls would have the greatest effect on

A)reducing inherent risk.
B)reducing control risk.
C)reducing detection risk.
D)reducing audit risk.
سؤال
The ________ to auditing provides auditors with a clear understanding of possible errors and irregularities and the related risks and exposures.

A)risk-based approach
B)risk-adjusted approach
C)financial audit approach
D)information systems approach
سؤال
The use of a secure file library and restrictions on physical access to data files are control procedures used together to prevent

A)an employee or outsider obtaining data about an important client.
B)a data entry clerk from introducing data entry errors into the system.
C)a computer operator from losing or corrupting files or data during transaction processing.
D)programmers making unauthorized modifications to programs.
سؤال
What role should an auditor play in system development?

A)an independent reviewer only
B)a developer of internal controls
C)an advisor and developer of internal control specifications
D)A and B above
سؤال
Which of the following is not a control procedure for preventing inadvertent programming errors?

A)Review software license agreements.
B)Test new programs,including user acceptance testing.
C)Purchase hardware only from management approved vendors.
D)Require management approval of programming specifications.
سؤال
What is a test data generator?

A)an application that records how well systems personnel have performed on company competency examinations
B)an application that prepares data that can be used for auditing the effectiveness of computer processing
C)an application that records which professional examinations systems personnel have obtained
D)a backup generator application that can be used to generate data if the original storage device fails
سؤال
Which auditing technique will not assist in determining if unauthorized programming changes have been made?

A)use of a source code comparison program
B)use of the reprocessing technique to compare program output
C)interviewing and making inquiries of the programming staff
D)use of parallel simulation to compare program output
سؤال
The ________ procedure for auditing computer process controls uses a hypothetical series of valid and invalid transactions.

A)concurrent audit techniques
B)test data processing
C)integrated test facility
D)dual process
سؤال
________ is one tool used to document source data controls.

A)An input control matrix
B)A flowchart generator program
C)A program algorithm matrix
D)A mapping program
سؤال
Auditors have several techniques available to them to test computer-processing controls.An audit technique that immediately alerts auditors of suspicious transactions is known as

A)a SCARF.
B)reperformance.
C)the snapshot technique.
D)an audit hook.
سؤال
How could auditors determine if unauthorized program changes have been made?

A)by interviewing and making inquiries of the programming staff
B)by examining the systems design and programming documentation
C)by using a source code comparison program
D)by interviewing and making inquiries of recently terminated programming staff
سؤال
You are an internal auditor for Ron Burgandy Suits.The CEO has asked you to perform an audit of the program modifications process.Identify one procedure you might use to test controls surrounding the program modification process.

A)Review logical access control policies.
B)Discuss modification policies with management,users,and systems personnel.
C)Verify logical access controls are in effect for program changes.
D)Separate development,test,and production versions of programs.
سؤال
Identify the activity below that the external auditor should not be involved.

A)examining system access logs
B)developing the information system
C)examining logical access policies and procedures
D)making recommendations to management for improvement of existing internal controls
سؤال
The auditor uses ________ to continuously monitor the system and collect audit evidence while live data are processed.

A)test data processing
B)parallel simulation
C)concurrent audit techniques
D)analysis of program logic
سؤال
Which statement below is incorrect regarding program modifications?

A)Only material program changes should be thoroughly tested and documented.
B)During the change process,the developmental version of the program must be kept separate from the production version.
C)After the modified program has received final approval,the change is implemented by replacing the developmental version with the production version.
D)When a program change is submitted for approval,a list of all required updates should be compiled and then approved by management and program users.
سؤال
Which of the following is not one of the six objectives of an information systems audit?

A)Security provisions exist to protect data from unauthorized access,modification,or destruction.
B)Obtaining evidence to provide reasonable assurance the financial statements are not materially misstated
C)Programs have been developed and acquired in accordance with management's authorization.
D)Program modifications have received management's authorization and approval.
سؤال
You are the head of the IT department at Panther Designs,Inc.A systems review reveals that your firm has poor control procedures for preventing inadvertent programming errors.However,you are not concerned because you feel Panther Designs has strong compensating controls.What control likely exists to give you this confidence?

A)The internal audit department processes test data at Panther Designs.
B)Panther Designs pays its employees well,decreasing the likelihood of errors.
C)Panther Designs only hires competent programmers,decreasing the likelihood of errors.
D)All of Panther Design's IT applications are less than 2 years old.
سؤال
A type of software that auditors can use to analyze program logic and detect unexecuted program code is

A)an audit log.
B)a mapping program.
C)a scanning routine.
D)program tracing.
سؤال
Strong ________ controls can partially compensate for inadequate ________ controls.

A)development; processing
B)processing; development
C)operational; internal
D)internal; operational
سؤال
Which of the following is an information systems audit review procedure?

A)Verify the extent and effectiveness of encryption.
B)Inspect computer sites.
C)Test assignment procedures for user IDs.
D)Observe the preparation of backup files.
سؤال
Which of the following is not an information systems audit test of controls?

A)Observe computer-site access procedures.
B)Investigate how unauthorized access attempts are handled.
C)Review logical access policies and procedures.
D)Examine the results of disaster recovery plan simulations.
سؤال
True or False: Embedded audit molecules can be used to continually monitor the system and collect audit evidence.
سؤال
When programmers are working with program code,they often employ utilities that are also used in auditing.For example,as program code evolves,it is often the case that blocks of code are superseded by other blocks of code.Blocks of code that are not executed by the program can be identified by

A)embedded audit modules.
B)scanning routines.
C)mapping programs.
D)automated flow charting programs.
سؤال
An auditor sets an embedded audit module to selectively monitor transactions.Selected transactions are then reprocessed independently,and the results are compared with those obtained by the normal system processing.The auditor is using

A)an integrated test facility.
B)the snapshot technique.
C)a system control audit review file.
D)continuous and intermittent simulation.
سؤال
An auditor might use ________ to convert data from several sources into a single common format.

A)Windows Media Converter
B)concurrent audit technique
C)computer assisted audit techniques software
D)Adobe Professional
سؤال
Audit tests and procedures traditionally have been performed on a sample basis.Do options exist for auditors to test significantly more (or all)transactions?
سؤال
Describe the disadvantages of test data processing.
سؤال
Define and give examples of embedded audit modules.
سؤال
What is the primary purpose of computer audit software?

A)eliminate auditor judgment errors
B)assist the auditor in retrieving and reviewing information
C)detect unauthorized modifications to system program code
D)recheck all mathematical calculations,cross-foot,reprocess financial statements and compare to originals
سؤال
An audit software program that generates programs that perform certain audit functions,based on auditor specifications,is referred to as a(n)

A)input controls matrix.
B)CAATS.
C)embedded audit module.
D)mapping program.
سؤال
An auditor sets an embedded audit module to record all credit transactions in excess of $4,000 and stores the data in an audit log.The auditor is using

A)audit hooks.
B)the snapshot technique.
C)a system control audit review file.
D)continuous and intermittent simulation.
سؤال
Explain why the auditor's role in program development and acquisition should be limited.
سؤال
An auditor sets an embedded audit module to flag questionable online transactions,display information about the transaction on the auditor's computer,and send a text message to the auditor's cell phone.The auditor is using

A)the snapshot technique.
B)a system control audit review file.
C)audit hooks.
D)continuous and intermittent simulation.
سؤال
True or False: One of the advantages of CAATS software is that it can replace the auditor's judgment in specific areas of an audit.
سؤال
When doing an information systems audit,auditors must review and evaluate the program development process.What errors or fraud could occur during the program development process?
سؤال
An auditor creates a fictitious customer in the system and then creates several fictitious sales to the customer.The records are then tracked as they are processed by the system.The auditor is using

A)an integrated test facility.
B)the snapshot technique.
C)a system control audit review file.
D)continuous and intermittent simulation.
سؤال
Identify the company below that CAATS would likely provide the most value.

A)a local car dealership
B)a mom and pop grocery store
C)a large lumber mill that uses an ERP system
D)a medium-sized shoe retailer with outlets in many cities
سؤال
a)What is test data processing? b)How is it done? c)What are the sources that an auditor can use to generate test data?
سؤال
When programmers are working with program code,they often employ utilities that are also used in auditing.For example,as program code evolves,it is often the case that variables defined during the early part of development become irrelevant.The occurrences of variables that are not used by the program can be found using

A)program tracing.
B)scanning routines.
C)mapping programs.
D)embedded audit modules.
سؤال
An auditor sets an embedded audit module to flag all credit transactions in excess of $3,000.The flag causes the system state to be recorded before and after each transaction is processed.The auditor is using

A)audit hooks.
B)an integrated test facility.
C)the snapshot technique.
D)a system control audit review file.
سؤال
Briefly describe tests that can be used to detect unauthorized program modifications.
سؤال
How has the U.S.government deployed computer-assisted audit techniques to reduce the budget?

A)to identify fraudulent Medicare claims
B)to perform random audits of government spending
C)to replace human auditors with computerized auditors
D)to develop a more balanced government budget
فتح الحزمة
قم بالتسجيل لفتح البطاقات في هذه المجموعة!
Unlock Deck
Unlock Deck
1/93
auto play flashcards
العب
simple tutorial
ملء الشاشة (f)
exit full mode
Deck 11: Auditing Computer-Based Information Systems
1
The ________ audit examines the reliability and integrity of accounting records.

A)financial
B)informational
C)information systems
D)operational
A
2
Verifying the accuracy of certain information,often through communication with third parties,is known as

A)reperformance.
B)confirmation.
C)substantiation.
D)documentation.
B
3
The possibility that a material error will occur even though auditors are following audit procedures and using good judgment is referred to as

A)control risk.
B)detection risk.
C)inherent risk.
D)investigating risk.
B
4
A(n)________ audit is concerned with the economical and efficient use of resources and the accomplishment of established goals and objectives.

A)operational or management
B)financial
C)information systems
D)internal control
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
5
The auditor's objective is to seek ________ that no material error exists in the information audited.

A)absolute reliability
B)reasonable objectivity
C)reasonable evidence
D)reasonable assurance
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
6
Consideration of risk factors and materiality is most associated with which audit stage?

A)collection of audit evidence
B)communication of audit results
C)audit planning
D)evaluation of audit evidence
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
7
What is not a typical responsibility of an internal auditor?

A)helping management to improve organizational effectiveness
B)assisting in the design and implementation of an AIS
C)preparation of the company's financial statements
D)implementing and monitoring of internal controls
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
8
Which of the choices below best describes a risk-based audit approach?

A)a four-step approach to internal control evaluation.
B)a three-step approach to internal control evaluation.
C)a four-step approach to financial statement review and recommendations.
D)a three-step approach to financial statement review and recommendations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
9
Organizing the audit team and the physical examination of assets are components of which two separate audit stages?

A)planning; evaluating audit evidence
B)planning; collecting audit evidence
C)collecting audit evidence; communicating audit results
D)communicating audit results; evaluating audit evidence
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
10
A system that employs various types of advanced technology has more ________ risk than traditional batch processing.

A)control
B)detection
C)inherent
D)investing
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
11
Auditing involves the

A)collection,review,and documentation of audit evidence.
B)planning and verification of economic events.
C)collection of audit evidence and approval of economic events.
D)testing,documentation,and certification of audit evidence.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
12
The evidence collection method that considers the relationships and trends among information to detect items that should be investigated further is called

A)review of the documentation.
B)vouching.
C)physical examination.
D)analytical review.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
13
Control risk is defined as the

A)susceptibility to material risk in the absence of controls.
B)risk that a material misstatement will get through the internal control structure and into the financial statements.
C)risk that auditors and their audit procedures will not detect a material error or misstatement.
D)risk auditors will not be given the appropriate documents and records by management who wants to control audit activities and procedures.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
14
Assessing the quality of internal controls,the reliability of information,and operating performance are all part of

A)audit planning.
B)collection of audit evidence.
C)communication of audit results.
D)evaluation of audit evidence.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
15
The ________ stage of the auditing process involves (among other things)the auditors observing the operating activities and having discussions with employees.

A)audit planning
B)collection of audit evidence
C)communication of audit results
D)evaluation of audit evidence
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
16
The evidence collection method that examines all supporting documents to determine the validity of a transaction is called

A)review of documentation.
B)vouching.
C)physical examination.
D)analytical review.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
17
The purpose of ________ is to determine why,how,when,and who will perform the audit.

A)audit planning
B)the collection of audit evidence
C)the communication of audit results
D)the evaluation of audit evidence
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
18
Which type of work listed below is not typical of internal auditors?

A)operational and management audits
B)information system audits
C)financial statement audit
D)financial audit of accounting records
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
19
The ________ audit is concerned with the economical and efficient use of resources and the accomplishment of established goals and objectives.

A)financial
B)informational
C)information systems
D)operational
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
20
The ________ audit reviews the general and application controls of an AIS to assess its compliance with internal control policies and procedures and its effectiveness in safeguarding assets.

A)financial
B)information systems
C)management
D)internal control
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
21
An auditor finds that employee absentee rates are significantly higher on Mondays and Fridays than on other work days.This is an example collecting audit evidence by

A)confirmation.
B)reperformance.
C)vouching.
D)analytical review.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
22
The first step in a risk-based audit approach is to

A)evaluate the control procedures.
B)determine the threats facing the AIS.
C)identify the control procedures that should be in place.
D)evaluate weaknesses to determine their effect on the audit procedures.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
23
Describe the risk-based audit approach.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
24
The information systems audit objective that pertains to source data being processed into some form of output is known as

A)overall security.
B)program development.
C)program modifications.
D)processing.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
25
How is a financial audit different from an information systems audit?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
26
An auditor examines all documents related to the acquisition,repair history,and disposal of a firm's delivery van.This is an example of collecting audit evidence by

A)confirmation.
B)reperformance.
C)vouching.
D)analytical review.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
27
When a control deficiency is identified,the auditor should inquire about

A)tests of controls.
B)compensating controls.
C)the feasibility of a systems review.
D)materiality and inherent risk factors.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
28
Describe how audit evidence can be collected.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
29
Increasing the effectiveness of auditing software will

A)reduce detection risk.
B)reduce control risk.
C)increase detection risk.
D)increase control risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
30
________can determine whether the necessary control procedures are in place.

A)A systems review
B)A systems overhaul
C)Tests of controls
D)both B and C
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
31
Name and describe the different types of audits.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
32
Which of the following is not one of the types of internal audits?

A)reviewing corporate organizational structure and reporting hierarchies
B)examining procedures for reporting and disposing of hazardous waste
C)reviewing source documents and general ledger accounts to determine integrity of recorded transactions
D)comparing estimates and analysis made before purchase of a major capital asset to actual numbers and results achieved
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
33
Why do all audits follow a sequence of events that can be divided into four stages,and what are the four stages?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
34
An auditor manually calculates accumulated depreciation on a delivery van and compares her calculation with the accounting records.The auditor is performing

A)vouching.
B)confirmation.
C)reperformance.
D)analytical review.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
35
How and to whom does an auditor communicate the audit results?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
36
What is the purpose of an information systems audit?

A)to determine the inherent risk factors found in the system
B)to review and evaluate the internal controls that protect the system
C)to examine the reliability and integrity of accounting records
D)to examine whether resources have been used in an economical and efficient manner in keeping with organization goals and objectives
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
37
Explain the differences between each type of audit risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
38
Expanding a firm's operations to include a manufacturing facility in Russia will

A)reduce inherent risk.
B)reduce control risk.
C)increase inherent risk.
D)increase control risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
39
Increasing the effectiveness of internal controls would have the greatest effect on

A)reducing inherent risk.
B)reducing control risk.
C)reducing detection risk.
D)reducing audit risk.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
40
The ________ to auditing provides auditors with a clear understanding of possible errors and irregularities and the related risks and exposures.

A)risk-based approach
B)risk-adjusted approach
C)financial audit approach
D)information systems approach
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
41
The use of a secure file library and restrictions on physical access to data files are control procedures used together to prevent

A)an employee or outsider obtaining data about an important client.
B)a data entry clerk from introducing data entry errors into the system.
C)a computer operator from losing or corrupting files or data during transaction processing.
D)programmers making unauthorized modifications to programs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
42
What role should an auditor play in system development?

A)an independent reviewer only
B)a developer of internal controls
C)an advisor and developer of internal control specifications
D)A and B above
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
43
Which of the following is not a control procedure for preventing inadvertent programming errors?

A)Review software license agreements.
B)Test new programs,including user acceptance testing.
C)Purchase hardware only from management approved vendors.
D)Require management approval of programming specifications.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
44
What is a test data generator?

A)an application that records how well systems personnel have performed on company competency examinations
B)an application that prepares data that can be used for auditing the effectiveness of computer processing
C)an application that records which professional examinations systems personnel have obtained
D)a backup generator application that can be used to generate data if the original storage device fails
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
45
Which auditing technique will not assist in determining if unauthorized programming changes have been made?

A)use of a source code comparison program
B)use of the reprocessing technique to compare program output
C)interviewing and making inquiries of the programming staff
D)use of parallel simulation to compare program output
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
46
The ________ procedure for auditing computer process controls uses a hypothetical series of valid and invalid transactions.

A)concurrent audit techniques
B)test data processing
C)integrated test facility
D)dual process
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
47
________ is one tool used to document source data controls.

A)An input control matrix
B)A flowchart generator program
C)A program algorithm matrix
D)A mapping program
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
48
Auditors have several techniques available to them to test computer-processing controls.An audit technique that immediately alerts auditors of suspicious transactions is known as

A)a SCARF.
B)reperformance.
C)the snapshot technique.
D)an audit hook.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
49
How could auditors determine if unauthorized program changes have been made?

A)by interviewing and making inquiries of the programming staff
B)by examining the systems design and programming documentation
C)by using a source code comparison program
D)by interviewing and making inquiries of recently terminated programming staff
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
50
You are an internal auditor for Ron Burgandy Suits.The CEO has asked you to perform an audit of the program modifications process.Identify one procedure you might use to test controls surrounding the program modification process.

A)Review logical access control policies.
B)Discuss modification policies with management,users,and systems personnel.
C)Verify logical access controls are in effect for program changes.
D)Separate development,test,and production versions of programs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
51
Identify the activity below that the external auditor should not be involved.

A)examining system access logs
B)developing the information system
C)examining logical access policies and procedures
D)making recommendations to management for improvement of existing internal controls
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
52
The auditor uses ________ to continuously monitor the system and collect audit evidence while live data are processed.

A)test data processing
B)parallel simulation
C)concurrent audit techniques
D)analysis of program logic
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
53
Which statement below is incorrect regarding program modifications?

A)Only material program changes should be thoroughly tested and documented.
B)During the change process,the developmental version of the program must be kept separate from the production version.
C)After the modified program has received final approval,the change is implemented by replacing the developmental version with the production version.
D)When a program change is submitted for approval,a list of all required updates should be compiled and then approved by management and program users.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
54
Which of the following is not one of the six objectives of an information systems audit?

A)Security provisions exist to protect data from unauthorized access,modification,or destruction.
B)Obtaining evidence to provide reasonable assurance the financial statements are not materially misstated
C)Programs have been developed and acquired in accordance with management's authorization.
D)Program modifications have received management's authorization and approval.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
55
You are the head of the IT department at Panther Designs,Inc.A systems review reveals that your firm has poor control procedures for preventing inadvertent programming errors.However,you are not concerned because you feel Panther Designs has strong compensating controls.What control likely exists to give you this confidence?

A)The internal audit department processes test data at Panther Designs.
B)Panther Designs pays its employees well,decreasing the likelihood of errors.
C)Panther Designs only hires competent programmers,decreasing the likelihood of errors.
D)All of Panther Design's IT applications are less than 2 years old.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
56
A type of software that auditors can use to analyze program logic and detect unexecuted program code is

A)an audit log.
B)a mapping program.
C)a scanning routine.
D)program tracing.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
57
Strong ________ controls can partially compensate for inadequate ________ controls.

A)development; processing
B)processing; development
C)operational; internal
D)internal; operational
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
58
Which of the following is an information systems audit review procedure?

A)Verify the extent and effectiveness of encryption.
B)Inspect computer sites.
C)Test assignment procedures for user IDs.
D)Observe the preparation of backup files.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
59
Which of the following is not an information systems audit test of controls?

A)Observe computer-site access procedures.
B)Investigate how unauthorized access attempts are handled.
C)Review logical access policies and procedures.
D)Examine the results of disaster recovery plan simulations.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
60
True or False: Embedded audit molecules can be used to continually monitor the system and collect audit evidence.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
61
When programmers are working with program code,they often employ utilities that are also used in auditing.For example,as program code evolves,it is often the case that blocks of code are superseded by other blocks of code.Blocks of code that are not executed by the program can be identified by

A)embedded audit modules.
B)scanning routines.
C)mapping programs.
D)automated flow charting programs.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
62
An auditor sets an embedded audit module to selectively monitor transactions.Selected transactions are then reprocessed independently,and the results are compared with those obtained by the normal system processing.The auditor is using

A)an integrated test facility.
B)the snapshot technique.
C)a system control audit review file.
D)continuous and intermittent simulation.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
63
An auditor might use ________ to convert data from several sources into a single common format.

A)Windows Media Converter
B)concurrent audit technique
C)computer assisted audit techniques software
D)Adobe Professional
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
64
Audit tests and procedures traditionally have been performed on a sample basis.Do options exist for auditors to test significantly more (or all)transactions?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
65
Describe the disadvantages of test data processing.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
66
Define and give examples of embedded audit modules.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
67
What is the primary purpose of computer audit software?

A)eliminate auditor judgment errors
B)assist the auditor in retrieving and reviewing information
C)detect unauthorized modifications to system program code
D)recheck all mathematical calculations,cross-foot,reprocess financial statements and compare to originals
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
68
An audit software program that generates programs that perform certain audit functions,based on auditor specifications,is referred to as a(n)

A)input controls matrix.
B)CAATS.
C)embedded audit module.
D)mapping program.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
69
An auditor sets an embedded audit module to record all credit transactions in excess of $4,000 and stores the data in an audit log.The auditor is using

A)audit hooks.
B)the snapshot technique.
C)a system control audit review file.
D)continuous and intermittent simulation.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
70
Explain why the auditor's role in program development and acquisition should be limited.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
71
An auditor sets an embedded audit module to flag questionable online transactions,display information about the transaction on the auditor's computer,and send a text message to the auditor's cell phone.The auditor is using

A)the snapshot technique.
B)a system control audit review file.
C)audit hooks.
D)continuous and intermittent simulation.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
72
True or False: One of the advantages of CAATS software is that it can replace the auditor's judgment in specific areas of an audit.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
73
When doing an information systems audit,auditors must review and evaluate the program development process.What errors or fraud could occur during the program development process?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
74
An auditor creates a fictitious customer in the system and then creates several fictitious sales to the customer.The records are then tracked as they are processed by the system.The auditor is using

A)an integrated test facility.
B)the snapshot technique.
C)a system control audit review file.
D)continuous and intermittent simulation.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
75
Identify the company below that CAATS would likely provide the most value.

A)a local car dealership
B)a mom and pop grocery store
C)a large lumber mill that uses an ERP system
D)a medium-sized shoe retailer with outlets in many cities
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
76
a)What is test data processing? b)How is it done? c)What are the sources that an auditor can use to generate test data?
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
77
When programmers are working with program code,they often employ utilities that are also used in auditing.For example,as program code evolves,it is often the case that variables defined during the early part of development become irrelevant.The occurrences of variables that are not used by the program can be found using

A)program tracing.
B)scanning routines.
C)mapping programs.
D)embedded audit modules.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
78
An auditor sets an embedded audit module to flag all credit transactions in excess of $3,000.The flag causes the system state to be recorded before and after each transaction is processed.The auditor is using

A)audit hooks.
B)an integrated test facility.
C)the snapshot technique.
D)a system control audit review file.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
79
Briefly describe tests that can be used to detect unauthorized program modifications.
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
80
How has the U.S.government deployed computer-assisted audit techniques to reduce the budget?

A)to identify fraudulent Medicare claims
B)to perform random audits of government spending
C)to replace human auditors with computerized auditors
D)to develop a more balanced government budget
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.
فتح الحزمة
k this deck
locked card icon
فتح الحزمة
افتح القفل للوصول البطاقات البالغ عددها 93 في هذه المجموعة.