Certified Public Accountant Technology & Digital Applications 2 — Questions and Answers
Question 1: A CPA firm is implementing a cloud-based accounting system. Which control is MOST critical to establish before migrating sensitive client data?
- Automated invoice processing
- Data encryption in transit and at rest (Correct answer)
- Real-time currency conversion
- Multi-currency reporting dashboards
Correct answer: Data encryption in transit and at rest
Encryption of data both in transit and at rest is the foundational control for protecting sensitive client financial data in cloud environments.
Question 2: Under the AICPA's SOC 2 framework, which Trust Services Criterion addresses the system's availability for operation and use?
- Confidentiality
- Privacy
- Availability (Correct answer)
- Processing Integrity
Correct answer: Availability
The Availability criterion in SOC 2 addresses whether the system is available for operation and use as committed or agreed upon.
Question 3: A company uses robotic process automation (RPA) to process vendor invoices. What is the PRIMARY audit risk introduced by RPA?
- Increased processing time
- Errors or fraud propagating at machine speed without human review (Correct answer)
- Higher software licensing costs
- Reduced transaction volume
Correct answer: Errors or fraud propagating at machine speed without human review
RPA can execute thousands of transactions rapidly, meaning a misconfigured rule or fraudulent input can propagate errors at scale before detection.
Question 4: Which data analytics technique is BEST suited for identifying unusual journal entries that may indicate financial statement fraud?
- Regression analysis
- Benford's Law analysis (Correct answer)
- Moving average calculations
- Monte Carlo simulation
Correct answer: Benford's Law analysis
Benford's Law analysis tests whether the leading digits in financial data follow a natural logarithmic distribution, deviations from which can signal manipulation.
Question 5: An ERP system upgrade is planned during a client's fiscal year-end. What is the auditor's PRIMARY concern?
- The vendor's market capitalization
- Migration completeness and accuracy of historical data transferred (Correct answer)
- The number of user licenses purchased
- Whether the system supports mobile access
Correct answer: Migration completeness and accuracy of historical data transferred
Data migration errors during an ERP upgrade can cause incomplete or inaccurate financial records, directly affecting audit evidence reliability.
Question 6: Which of the following BEST describes a 'general IT control' as opposed to an 'application control'?
- A control that validates individual transaction amounts
- A pervasive control such as access management that supports multiple applications (Correct answer)
- A control embedded in the payroll calculation logic
- A report that reconciles accounts receivable balances
Correct answer: A pervasive control such as access management that supports multiple applications
General IT controls (e.g., logical access, change management, IT operations) are pervasive and underpin the reliability of application-level controls across the entire IT environment.
Question 7: A client stores financial records using a distributed ledger (blockchain). Which characteristic of blockchain is MOST relevant to auditor reliance on those records?
- Smart contract programmability
- Immutability of confirmed transaction records (Correct answer)
- Token issuance capabilities
- Anonymous transaction processing
Correct answer: Immutability of confirmed transaction records
Blockchain's immutability means confirmed records cannot be altered without consensus, which supports the integrity and reliability of recorded transactions for audit purposes.
A CPA firm is implementing a cloud-based accounting system.
Which control is MOST critical to establish before migrating sensitive client data?