Certified Public Accountant Technology & Digital Applications 3 — Questions and Answers
Question 1: A CPA performing IT audit procedures identifies that database administrators have both read and write access to the general ledger tables. This MOST likely represents a violation of which control principle?
- Separation of duties (Correct answer)
- Data redundancy
- Disaster recovery planning
- Input validation
Correct answer: Separation of duties
Granting DBAs unrestricted access to the general ledger violates separation of duties because they could alter financial records without independent oversight.
Question 2: Which encryption standard is currently recommended by NIST for protecting highly sensitive financial data?
- DES (56-bit)
- 3DES (112-bit)
- AES-256 (Correct answer)
- RC4
Correct answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the current NIST-recommended standard for protecting sensitive data and is considered computationally infeasible to brute-force.
Question 3: When evaluating a SaaS vendor's controls, a CPA should FIRST request which document?
- The vendor's marketing brochure
- A SOC 1 Type II or SOC 2 Type II report (Correct answer)
- The vendor's employee handbook
- A list of the vendor's other customers
Correct answer: A SOC 1 Type II or SOC 2 Type II report
A Type II SOC report provides independent assurance over the design AND operating effectiveness of controls over a period of time, which is essential for evaluating a SaaS vendor.
Question 4: A company's IT disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours. What does this mean?
- Data must be backed up every 4 hours
- Systems must be restored and operational within 4 hours of a disruption (Correct answer)
- The disaster recovery test must complete in 4 hours
- No more than 4 hours of data can be lost
Correct answer: Systems must be restored and operational within 4 hours of a disruption
RTO is the maximum acceptable time for restoring a system or process after a disruption before the impact becomes unacceptable.
Question 5: In the context of IT controls, 'change management' procedures PRIMARILY exist to ensure that:
- Employees adapt quickly to organizational restructuring
- System modifications are authorized, tested, and documented before implementation (Correct answer)
- Customer data is migrated accurately
- Software licenses are renewed on time
Correct answer: System modifications are authorized, tested, and documented before implementation
Change management controls govern the process of modifying IT systems to prevent unauthorized changes, ensure testing, and maintain a complete audit trail of modifications.
Question 6: A CPA uses continuous auditing techniques to monitor a client's transactions. Which technology is MOST commonly used to enable real-time transaction monitoring?
- Spreadsheet macros
- Embedded audit modules within the client's ERP system (Correct answer)
- Paper-based reconciliation forms
- Static end-of-year data extracts
Correct answer: Embedded audit modules within the client's ERP system
Embedded audit modules (EAMs) are built directly into the client's application systems to capture and evaluate transactions as they occur, enabling continuous auditing.
Question 7: Which of the following is a PRIMARY concern when a CPA relies on a client-provided data extract for audit analytics?
- File size of the extract
- Completeness and integrity of the extracted data (Correct answer)
- The file format used (CSV vs. Excel)
- The speed of the extraction process
Correct answer: Completeness and integrity of the extracted data
If the client's extract is incomplete or manipulated, all subsequent analytics will produce flawed conclusions, making data completeness and integrity the paramount concern.
A CPA performing IT audit procedures identifies that database administrators have both read and write access to the general ledger tables.
This MOST likely represents a violation of which control principle?