CIA CIA IT Audit & Information Systems 1 — Questions and Answers
Question 1: Which IT general control ensures that only authorized users can access an organization's financial systems?
- Change management controls
- Access controls (Correct answer)
- Backup and recovery controls
- System development lifecycle controls
Correct answer: Access controls
Access controls (logical security) restrict system entry to authorized users through authentication, authorization, and user account management.
Question 2: What is the primary objective of IT general controls (ITGCs) as evaluated during an internal audit?
- Ensure IT projects are completed on schedule
- Provide a foundation of reliability for application controls and financial data (Correct answer)
- Reduce IT hardware procurement costs
- Manage vendor contracts for software licenses
Correct answer: Provide a foundation of reliability for application controls and financial data
ITGCs provide the control environment upon which application controls depend; unreliable ITGCs undermine the integrity of all automated application-level controls.
Question 3: Which concept describes the process of verifying that a user is who they claim to be before granting system access?
- Authorization
- Authentication (Correct answer)
- Accountability
- Non-repudiation
Correct answer: Authentication
Authentication is the process of verifying identity (e.g., via password, biometrics, or multi-factor methods) before access is granted.
Question 4: In IT audit, what does 'change management control' primarily prevent?
- Unauthorized or untested changes to production systems (Correct answer)
- Budget overruns on IT projects
- Hardware failures in data centers
- Phishing attacks on end users
Correct answer: Unauthorized or untested changes to production systems
Change management controls ensure all modifications to production systems are authorized, tested, and documented before deployment to prevent errors and unauthorized alterations.
Question 5: What is the purpose of a business continuity plan (BCP) from an IT audit perspective?
- Ensure daily data backups are performed
- Enable the organization to continue critical operations after a disruptive event (Correct answer)
- Test employee cybersecurity awareness
- Manage software licensing compliance
Correct answer: Enable the organization to continue critical operations after a disruptive event
A BCP provides documented procedures to sustain essential business functions during and after major disruptions such as natural disasters or cyberattacks.
Question 6: Which audit procedure is most effective for testing that user access privileges are appropriate and follow least privilege principles?
- Reviewing IT project plans
- Performing a user access review (UAR) (Correct answer)
- Testing disaster recovery procedures
- Inspecting software licensing agreements
Correct answer: Performing a user access review (UAR)
A user access review compares granted system privileges against job responsibilities to identify excessive, inappropriate, or orphaned access rights.
Which IT general control ensures that only authorized users can access an organization's financial systems?