Technology & Digital Applications Flashcards
7 cards from real Certified Public Accountant practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Technology & Digital Applications flashcards as text
Artificial intelligence tools used in audit workflows MOST require CPAs to exercise professional judgment in which area?
Answer: Evaluating and validating AI-generated outputs and conclusions
AI can produce plausible but incorrect outputs; CPAs must critically evaluate AI-generated findings rather than accepting them without independent professional judgment.
A 'bring your own device' (BYOD) policy at an audit client introduces which PRIMARY data security risk for the CPA?
Answer: Client data may reside on personal devices outside the firm's security controls
BYOD means sensitive financial data may be stored on personally owned devices that lack the firm's security configurations, encryption, and remote-wipe capabilities.
Under PCAOB standards, when an issuer's financial reporting relies heavily on IT systems, the auditor must evaluate IT controls because:
Answer: Effective IT controls are a prerequisite for the reliability of automated processing that feeds financial reports
If IT general and application controls are ineffective, the automated processing that populates financial statement amounts cannot be relied upon, requiring the auditor to expand substantive testing.
A 'phishing' attack successfully compromises an accounting manager's credentials. The MOST immediate financial reporting risk is:
Answer: Unauthorized journal entries or wire transfers initiated using stolen credentials
Compromised credentials give an attacker the same system access as the victim, enabling fraudulent journal entries, payment redirections, or data exfiltration with minimal detection.
Which of the following BEST describes 'data normalization' in the context of audit data analytics?
Answer: Restructuring data into a consistent format to eliminate redundancy and enable accurate analysis
Data normalization standardizes formats, removes duplicates, and structures data consistently so that analytical comparisons and aggregations produce accurate results.
A CPA reviewing cybersecurity risk for a public company client notes that the company has not patched a known OS vulnerability for 90 days. This is MOST relevant to which financial reporting risk?
Answer: Material weakness in internal control over financial reporting if the vulnerability could allow unauthorized data modification
An unpatched vulnerability that could allow unauthorized access to financial systems may constitute a significant deficiency or material weakness in ICFR, requiring disclosure.
What is the PRIMARY purpose of a 'rollback' capability in an enterprise accounting system?
Answer: To reverse erroneous or unauthorized transactions and restore the system to a prior valid state
Rollback functionality allows the system to undo incorrect or fraudulent changes and return to a known-good state, supporting both error correction and internal control objectives.