Technology & Digital Applications Flashcards
7 cards from real Certified Public Accountant practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Technology & Digital Applications flashcards as text
A CPA performing IT audit procedures identifies that database administrators have both read and write access to the general ledger tables. This MOST likely represents a violation of which control principle?
Answer: Separation of duties
Granting DBAs unrestricted access to the general ledger violates separation of duties because they could alter financial records without independent oversight.
Which encryption standard is currently recommended by NIST for protecting highly sensitive financial data?
Answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the current NIST-recommended standard for protecting sensitive data and is considered computationally infeasible to brute-force.
When evaluating a SaaS vendor's controls, a CPA should FIRST request which document?
Answer: A SOC 1 Type II or SOC 2 Type II report
A Type II SOC report provides independent assurance over the design AND operating effectiveness of controls over a period of time, which is essential for evaluating a SaaS vendor.
A company's IT disaster recovery plan specifies a Recovery Time Objective (RTO) of 4 hours. What does this mean?
Answer: Systems must be restored and operational within 4 hours of a disruption
RTO is the maximum acceptable time for restoring a system or process after a disruption before the impact becomes unacceptable.
In the context of IT controls, 'change management' procedures PRIMARILY exist to ensure that:
Answer: System modifications are authorized, tested, and documented before implementation
Change management controls govern the process of modifying IT systems to prevent unauthorized changes, ensure testing, and maintain a complete audit trail of modifications.
A CPA uses continuous auditing techniques to monitor a client's transactions. Which technology is MOST commonly used to enable real-time transaction monitoring?
Answer: Embedded audit modules within the client's ERP system
Embedded audit modules (EAMs) are built directly into the client's application systems to capture and evaluate transactions as they occur, enabling continuous auditing.
Which of the following is a PRIMARY concern when a CPA relies on a client-provided data extract for audit analytics?
Answer: Completeness and integrity of the extracted data
If the client's extract is incomplete or manipulated, all subsequent analytics will produce flawed conclusions, making data completeness and integrity the paramount concern.