QUESTIONS FINAL EXAM BANK WITH
RATIONALES (2026 UPDATE)
This comprehensive exam repository is specifically designed to
align with the modern curriculum covering Accounting Information
Systems components, transaction cycles, and information
security. It provides realistic, multiple-choice practice questions
featuring italicized answers and bolded rationales to reinforce key
concepts like the COSO framework, segregation of duties, and
database normalization. Mastering these structured scenarios
ensures complete preparation for data analytics, IT governance,
and system-driven internal control assessments.
Internal Control Frameworks (COSO & COBIT)
1. Which COSO Internal Control component
establishes the foundation for an organization's
overall integrity and ethical values?
A) Risk Assessment
B) Control Activities
C) Control Environment
D) Information and Communication
Answer: C) Control Environment
Rationale: The Control Environment sets the
tone of an organization, influencing the
control consciousness of its people. It is the
foundation for all other components of
internal control, providing discipline and
structure.
,2. Under the COSO ERM framework, which of the
following describes an organization's core
philosophy regarding how much risk it is willing
to accept in pursuit of value?
A) Risk Tolerance
B) Risk Appetite
C) Risk Target
D) Risk Capacity
Answer: B) Risk Appetite
Rationale: Risk appetite is the broad amount
of risk an entity is willing to accept in pursuit
of its strategic objectives and mission. Risk
tolerance is the specific, measurable
boundary of acceptable variation around
those objectives.
3. A company implements a policy requiring two
independent approvals for any wire transfer
exceeding $50,000. Which type of COSO control
activity does this represent?
A) Preventive control
B) Detective control
C) Corrective control
D) Directive control
Answer: A) Preventive control
Rationale: Preventive controls are designed
, to deter errors or fraud before they occur.
Requiring dual signatures stops
unauthorized or incorrect large-scale cash
disbursements from happening in the first
place.
4. While COSO focuses broadly on enterprise risk
and internal control, COBIT is specifically
designed as a framework for:
A) Financial statement audits only
B) IT governance and management
C) Environmental sustainability metrics
D) Human resource management
Answer: B) IT governance and management
Rationale: COBIT (Control Objectives for
Information and Related Technology)
provides a comprehensive framework that
helps enterprises achieve their objectives for
the governance and management of
enterprise IT.
5. Which component of the COSO Internal Control
framework involves identifying, analyzing, and
managing risks that could prevent the
organization from achieving its objectives?
A) Monitoring Activities
B) Risk Assessment
, C) Control Activities
D) Governance and Culture
Answer: B) Risk Assessment
Rationale: Risk assessment is the process of
identifying and assessing risks from both
external and internal sources, forming the
basis for determining how the risks should
be mitigated or managed.
6. An internal auditor discovers that a company
has not updated its business continuity plan in
five years. This deficiency represents a failure
primarily in which COSO component?
A) Control Environment
B) Monitoring Activities
C) Risk Assessment
D) Information and Communication
Answer: B) Monitoring Activities
Rationale: Monitoring activities evaluate
whether internal controls are present and
functioning over time. Failing to review, test,
and update key policies like business
continuity plans highlights a breakdown in
ongoing monitoring.
7. According to COBIT principles, governance
differs from management because governance: