IT Audit & Data Analytics Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 IT Audit & Data Analytics flashcards as text
Benford's Law is applied by auditors to a dataset of vendor invoice amounts. A finding shows the digit '9' appears far more frequently than expected as the leading digit. What does this MOST likely suggest?
Answer: Potential manipulation of amounts to stay just below an approval threshold
Unexpected frequency of high leading digits like '9' often indicates amounts are being manipulated to fall just below an authorization threshold, a red flag for fraud.
Which of the following BEST describes the role of a 'control owner' in an IT control environment?
Answer: The individual accountable for designing, implementing, and maintaining a specific control
A control owner is the individual with accountability for ensuring a specific control is properly designed, operating effectively, and maintained over time.
An auditor is evaluating an organization's patch management process. Which finding represents the GREATEST risk?
Answer: No formal process exists for tracking and prioritizing security patches
The absence of a formal patch management process means critical vulnerabilities may go unaddressed indefinitely, creating significant exposure to cyberattacks.
When auditing data analytics capabilities within an organization, which attribute MOST indicates a mature analytics program?
Answer: Defined data governance policies with repeatable, automated analytics workflows
A mature analytics program is characterized by strong data governance, standardized methodologies, and automated workflows that enable consistent and reliable analysis.
What is the PRIMARY purpose of an IT audit trail (audit log)?
Answer: To provide a chronological record of system activities for accountability and forensic analysis
Audit trails create an immutable chronological record of system events that supports accountability, forensic investigations, and after-the-fact review of activities.
During a review of an IT project, the auditor notes that user acceptance testing (UAT) was skipped to meet the go-live deadline. What is the PRIMARY risk introduced by this decision?
Answer: The system may not meet business requirements and contain undetected errors
Skipping UAT removes the key validation step where business users confirm the system meets requirements, increasing the risk that defects and misalignments go live undetected.
Which of the following is an example of a preventive IT control?
Answer: Requiring multi-factor authentication before system login
Multi-factor authentication prevents unauthorized access from occurring, making it a preventive control rather than a detective or corrective control.