IT Audit & Data Analytics Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 IT Audit & Data Analytics flashcards as text
An auditor is reviewing an organization's IT disaster recovery plan. Which element is MOST critical to validate during the audit?
Answer: Recovery Time Objective (RTO) and Recovery Point Objective (RPO) alignment with business needs
RTO and RPO define how quickly systems must be restored and how much data loss is acceptable, and they must align with business requirements to be effective.
During a cybersecurity audit, the auditor finds that the organization has not conducted a penetration test in three years. Which risk does this PRIMARILY increase?
Answer: Risk of unidentified exploitable vulnerabilities in systems
Penetration testing identifies exploitable vulnerabilities; without regular testing, new vulnerabilities introduced through system changes may go undetected.
When performing continuous auditing, what is the PRIMARY advantage over traditional periodic auditing?
Answer: Near real-time detection of anomalies and control failures
Continuous auditing enables near real-time monitoring of transactions and controls, allowing auditors to detect and respond to issues as they occur rather than after the fact.
An internal auditor is assessing IT governance. Which framework is MOST widely used as a reference for IT governance and management of enterprise IT?
Answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the most widely recognized framework specifically designed for IT governance and management.
Which data analytics technique would BEST help an auditor identify trends in expense report submissions over a 12-month period?
Answer: Time-series analysis
Time-series analysis examines data points collected over time to identify patterns, trends, or seasonal variations in the data.
During an IT audit, the auditor determines that input validation controls are missing in a financial application. What is the MOST likely consequence?
Answer: Entry of erroneous or malicious data into the system
Without input validation, erroneous, incomplete, or malicious data can be entered and processed, potentially corrupting financial records or enabling injection attacks.
An auditor is reviewing segregation of duties in an ERP system. Which combination of access rights represents the HIGHEST risk?
Answer: Ability to create and approve purchase orders
Having the ability to both create and approve purchase orders in a single role eliminates a key authorization control and enables fraudulent procurement transactions.