Exam 14: Auditing It Controls Part I: Sarbanes-Oxley and It Governance

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

Explain why certain duties that are deemed incompatible in a manual system may be combined in an automated environment? Give an example.

Free
(Essay)
4.7/5
(26)
Correct Answer:
Verified

In an automated environment it would be inefficient and contrary to the objectives of automation to separate such tasks as processing and recoding a transaction among several different application programs merely to emulate a manual control model.Further,the reason for separating tasks is to control against the negative behavior of humans; in an automated environment the computer performs the tasks,not humans.

What is a recovery operations center? What is its purpose?

Free
(Essay)
4.7/5
(38)
Correct Answer:
Verified

A recovery operations center (ROC)or hot site is a fully equipped backup data center that many companies share.In addition to hardware and backup facilities,ROC service providers offer a range of technical services to their clients,who pay an annual fee for access rights.In the event of a major disaster,a subscriber can occupy the premises and,within a few hours,resume processing critical applications.

Computer fraud can take many forms,including each of the following except

Free
(Multiple Choice)
4.7/5
(34)
Correct Answer:
Verified

D

The database administrator should be separated from systems development.

(True/False)
4.8/5
(40)

What is IT governance?

(Essay)
4.9/5
(39)

How do the tests of controls affect substantive tests?

(Essay)
4.8/5
(34)

Which organizational structure is most likely to result in good documentation procedures?

(Multiple Choice)
4.9/5
(38)

Briefly explain the core competency theory.

(Essay)
4.8/5
(41)

Internal control in a computerized environment can be divided into two broad categories.What are they? Explain each.

(Essay)
4.8/5
(37)

Which statement is not true?

(Multiple Choice)
4.8/5
(35)

Substantive testing techniques provide information about the accuracy and completeness of an application's processes.

(True/False)
4.9/5
(32)

Both the SEC and the PCAOB require management to use the COBIT framework for assessing internal control adequacy.

(True/False)
4.7/5
(44)

In a computer-based information system,which of the following duties needs to be separated?

(Multiple Choice)
4.8/5
(29)

What is program fraud?

(Essay)
4.9/5
(41)

A cold site backup approach is also known as

(Multiple Choice)
4.8/5
(30)

As a form of computer fraud,what is eavesdropping?

(Essay)
4.7/5
(36)

An advantage of a recovery operations center is that

(Multiple Choice)
4.8/5
(38)

Define fault tolerance.

(Essay)
4.9/5
(37)

Explain how IT outsourcing can lead to loss of strategic advantage.

(Essay)
4.9/5
(42)

Which of the following is not a requirement in management's report on the effectiveness of internal controls over financial reporting?

(Multiple Choice)
4.8/5
(37)
Showing 1 - 20 of 129
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)