AICPA Information Technology Flashcards
6 cards from real AICPA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 AICPA Information Technology flashcards as text
An entity uses an automated three-way match control in its procure-to-pay system. Which three documents are compared by this control?
Answer: Purchase order, receiving report, and vendor invoice
A three-way match compares the purchase order, receiving report, and vendor invoice to ensure quantities and prices agree before payment is approved.
When evaluating cybersecurity risk under AICPA's cybersecurity risk management reporting framework, the description criterion requires management to describe:
Answer: The nature and scope of the entity's cybersecurity risk management program
The description criterion requires management to provide a clear description of the entity's cybersecurity risk management program and related controls.
Which encryption standard is currently recommended by NIST and referenced in AICPA cybersecurity guidance for protecting data at rest in US organizations?
Answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the NIST-recommended standard for encrypting sensitive data at rest.
In an IT audit, 'privileged access' accounts are considered high-risk primarily because:
Answer: They can override system controls and access or modify any data without restriction
Privileged accounts (e.g., system administrator or root accounts) can bypass application controls and directly alter any data, posing significant fraud and error risk.
An auditor notes that system-generated audit logs are stored in the same environment as the application being monitored. What is the key risk?
Answer: An administrator could alter or delete logs to conceal unauthorized activity
Storing logs in the same environment allows a privileged user to tamper with or delete evidence of their unauthorized actions, undermining the integrity of the audit trail.
Under the AICPA attestation standards, a Type II SOC report differs from a Type I report in that it includes:
Answer: An opinion on the operating effectiveness of controls over a specified period
A Type II report tests whether controls operated effectively throughout a defined period, while a Type I report only describes and evaluates design at a single point in time.