AICPA AICPA Information Technology 1 β Questions and Answers
Question 1: Which framework is most commonly referenced by CPAs when evaluating IT general controls and IT application controls in a US audit?
- COBIT (Correct answer)
- TOGAF
- ITIL
- PRINCE2
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the primary IT governance framework referenced by CPAs evaluating IT controls in audits.
Question 2: Under AICPA standards, what is the primary purpose of reviewing IT general controls (ITGCs) during a financial statement audit?
- To assess whether automated application controls can be relied upon (Correct answer)
- To test the accuracy of individual journal entries
- To verify the physical security of server hardware
- To evaluate software licensing compliance
Correct answer: To assess whether automated application controls can be relied upon
ITGCs provide the foundation for relying on automated application controls; if ITGCs are weak, application controls may not function as intended.
Question 3: Which type of IT control automatically prevents an invalid transaction from being processed in an accounting system?
- Preventive application control (Correct answer)
- Detective general control
- Corrective manual control
- Compensating physical control
Correct answer: Preventive application control
A preventive application control is embedded in the software and stops an invalid transaction before it is recorded.
Question 4: An auditor discovers that a company allows programmers to have direct access to the production environment. This is an example of a weakness in which ITGC domain?
- Change management
- Logical access (Correct answer)
- Computer operations
- System development
Correct answer: Logical access
Allowing programmers access to the production environment is a segregation-of-duties failure within the logical access ITGC domain.
Question 5: Under the AICPA's guidance, a Service Organization Control (SOC) 1 report is primarily used to address controls at a service organization that are relevant to:
- User entities' internal control over financial reporting (Correct answer)
- Privacy of personal information
- Cybersecurity risk management
- Operational efficiency metrics
Correct answer: User entities' internal control over financial reporting
A SOC 1 report focuses on controls at a service organization that are likely to be relevant to a user entity's internal control over financial reporting.
Question 6: Which data backup strategy ensures the shortest recovery time objective (RTO) by maintaining a continuously updated copy of the production database?
- Hot site with real-time replication (Correct answer)
- Cold site with weekly tape backup
- Warm site with daily incremental backup
- Offsite vault with monthly full backup
Correct answer: Hot site with real-time replication
A hot site with real-time replication keeps a live mirror of production data, enabling near-instant failover and the shortest RTO.
Which framework is most commonly referenced by CPAs when evaluating IT general controls and IT application controls in a US audit?