Certified Public Accountant Technology & Digital Applications 4 — Questions and Answers
Question 1: Artificial intelligence tools used in audit workflows MOST require CPAs to exercise professional judgment in which area?
- Selecting the font for audit reports
- Evaluating and validating AI-generated outputs and conclusions (Correct answer)
- Choosing between PDF and Word report formats
- Scheduling client meetings
Correct answer: Evaluating and validating AI-generated outputs and conclusions
AI can produce plausible but incorrect outputs; CPAs must critically evaluate AI-generated findings rather than accepting them without independent professional judgment.
Question 2: A 'bring your own device' (BYOD) policy at an audit client introduces which PRIMARY data security risk for the CPA?
- Increased office supply costs
- Client data may reside on personal devices outside the firm's security controls (Correct answer)
- Higher mobile data charges
- Slower internet speeds on the audit
Correct answer: Client data may reside on personal devices outside the firm's security controls
BYOD means sensitive financial data may be stored on personally owned devices that lack the firm's security configurations, encryption, and remote-wipe capabilities.
Question 3: Under PCAOB standards, when an issuer's financial reporting relies heavily on IT systems, the auditor must evaluate IT controls because:
- IT systems always contain fraud
- Effective IT controls are a prerequisite for the reliability of automated processing that feeds financial reports (Correct answer)
- IT evaluations increase audit fees
- PCAOB requires a minimum number of IT findings per engagement
Correct answer: Effective IT controls are a prerequisite for the reliability of automated processing that feeds financial reports
If IT general and application controls are ineffective, the automated processing that populates financial statement amounts cannot be relied upon, requiring the auditor to expand substantive testing.
Question 4: A 'phishing' attack successfully compromises an accounting manager's credentials. The MOST immediate financial reporting risk is:
- Slower internet connectivity
- Unauthorized journal entries or wire transfers initiated using stolen credentials (Correct answer)
- Loss of email history
- Reduced printer access
Correct answer: Unauthorized journal entries or wire transfers initiated using stolen credentials
Compromised credentials give an attacker the same system access as the victim, enabling fraudulent journal entries, payment redirections, or data exfiltration with minimal detection.
Question 5: Which of the following BEST describes 'data normalization' in the context of audit data analytics?
- Distributing data evenly across multiple servers
- Restructuring data into a consistent format to eliminate redundancy and enable accurate analysis (Correct answer)
- Encrypting data before transmission
- Archiving old financial records
Correct answer: Restructuring data into a consistent format to eliminate redundancy and enable accurate analysis
Data normalization standardizes formats, removes duplicates, and structures data consistently so that analytical comparisons and aggregations produce accurate results.
Question 6: A CPA reviewing cybersecurity risk for a public company client notes that the company has not patched a known OS vulnerability for 90 days. This is MOST relevant to which financial reporting risk?
- Revenue recognition timing
- Material weakness in internal control over financial reporting if the vulnerability could allow unauthorized data modification (Correct answer)
- Depreciation method selection
- Going concern assessment only if the company is small
Correct answer: Material weakness in internal control over financial reporting if the vulnerability could allow unauthorized data modification
An unpatched vulnerability that could allow unauthorized access to financial systems may constitute a significant deficiency or material weakness in ICFR, requiring disclosure.
Question 7: What is the PRIMARY purpose of a 'rollback' capability in an enterprise accounting system?
- To generate consolidated financial statements
- To reverse erroneous or unauthorized transactions and restore the system to a prior valid state (Correct answer)
- To accelerate month-end close processing
- To export data to external analytics tools
Correct answer: To reverse erroneous or unauthorized transactions and restore the system to a prior valid state
Rollback functionality allows the system to undo incorrect or fraudulent changes and return to a known-good state, supporting both error correction and internal control objectives.
Artificial intelligence tools used in audit workflows MOST require CPAs to exercise professional judgment in which area?